• News/
  • https://www.bleepingcomputer.com/news/security/hackers-breach-us-govt-agencies-using-adobe-coldfusion-exploit/

Hackers breach US govt agencies using Adobe ColdFusion exploit

BleepingComputer
·
Bill Toulas
·
Published Dec 5, 2023
·
Updated

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning about hackers actively exploiting a critical vulnerability in Adobe ColdFusion identified as CVE-2023-26360 to gain initial access to government servers. The security issue allows executing arbitrary code on servers running  Adobe ColdFusion 2018 Update 15 and older, and 2021 Update 5 and earlier. It was exploited as a zero day before Adobe fixed it in mid-March by releasing ColdFusion 2018 Update 16 and 2021 Update 6. At the time, CISA published a notice about threat actors exploiting the flaw and urged federal organizations and state services to apply the available security updates. In an alert today, America's Cyber Defense Agency warns that CVE-2023-26360 is still leveraged in attacks, showcasing incidents from June that impacted two federal agency systems. “In both incidents, Microsoft Defender for Endpoint (MDE) alerted of the potential exploitation of an Adobe ColdFusion vulnerability on public-facing web servers in the agency’s pre-production environment” - CISA The agency notes that "both servers were running outdated versions of software which are vulnerable to various CVEs.” CISA says that the threat actors leveraged the vulnerability to drop malware using HTTP POST commands to the directory path associated with ColdFusion. The first incident was recorded on June 26 and relied on the critical vulnerability to breach a server running Adobe ColdFusion v2016.0.0.3. The attackers conducted pro...

Read full article

Affected Software

2 affected components
Adobe ColdFusion=2018 Update 15
Adobe ColdFusion=2021 Update 5

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a breach of U.S. government agencies by hackers exploiting a critical vulnerability in Adobe ColdFusion.

2

What security implications are discussed?

The article highlights the risk posed by the exploitation of CVE-2023-26360, which allows hackers to gain initial access to government servers.

3

What products or software are affected?

The affected software includes Adobe ColdFusion versions 2018 Update 15 and 2021 Update 5.

4

Who issued the warning regarding the ColdFusion exploit?

The warning was issued by the U.S. Cybersecurity and Infrastructure Security Agency (CISA).

5

What specific vulnerability is being exploited by hackers?

The vulnerability being exploited is identified as CVE-2023-26360.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203