logo

Adobe warns of critical ColdFusion bug with PoC exploit code

ID: b487a59d-9fda-51f2-9e8a-f1e81aa5ad41

STIX ID: report--b487a59d-9fda-51f2-9e8a-f1e81aa5ad41

Feed Name: Bleeping Computer

Threat Score
65/100

Date Published: 2024-12-23

Date Updated: 2026-03-27

Author: Sergiu Gatlan

...
...

Adobe issued out-of-band security updates for a critical ColdFusion path traversal vulnerability (CVE-2024-53961) affecting ColdFusion 2021 and 2023 that can enable arbitrary file reads; a proof-of-concept exists and Adobe assigned the flaw Priority 1, urging administrators to apply emergency patches and lockdown guidance (within ~72 hours) and to review serial filter mitigations. The advisory notes past ColdFusion exploitation activity but does not confirm active exploitation of this specific CVE.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.