logo

Active Exploitation of Newly Patched ColdFusion Vulnerability (CVE-2018-15961)

ID: 500064ed-43ca-502a-b946-19fdd46b9f63

STIX ID: report--500064ed-43ca-502a-b946-19fdd46b9f63

Feed Name: Volexity Blog

Threat Score
80/100

Date Published: 2018-11-08

Date Updated: 2026-05-01

...
...

Volexity observed a suspected Chinese APT actively exploiting Adobe ColdFusion vulnerability CVE-2018-15961 (unauthenticated file upload via CKEditor) to upload a JSP China Chopper webshell and execute commands on unpatched Internet-facing ColdFusion servers. The advisory describes how attackers bypassed file-type restrictions and path controls, documents multiple compromised sites (including defacements and attempted uploads), provides Suricata/Snort detection signatures, and recommends immediate patching, log review, and administrative access restrictions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.