Adobe warns of critical ColdFusion bug with PoC exploit code
ID: b487a59d-9fda-51f2-9e8a-f1e81aa5ad41
STIX ID: report--b487a59d-9fda-51f2-9e8a-f1e81aa5ad41
Feed Name: Bleeping Computer
Adobe issued out-of-band security updates for a critical ColdFusion path traversal vulnerability (CVE-2024-53961) affecting ColdFusion 2021 and 2023 that can enable arbitrary file reads; a proof-of-concept exists and Adobe assigned the flaw Priority 1, urging administrators to apply emergency patches and lockdown guidance (within ~72 hours) and to review serial filter mitigations. The advisory notes past ColdFusion exploitation activity but does not confirm active exploitation of this specific CVE.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
