Adobe ColdFusion Vulnerability: Critical Bug (CVE-2024-53961) with PoC Exploit Code Discovered
ID: 05137c63-7f31-55b9-9587-9d6e254fde99
STIX ID: report--05137c63-7f31-55b9-9587-9d6e254fde99
Feed Name: The Cyber Express
Threat Score
Adobe disclosed a critical path traversal vulnerability (CVE-2024-53961) affecting ColdFusion 2023 (≤Update 11) and 2021 (≤Update 17) that permits unauthorized arbitrary file reads; Adobe rated it Priority 1 with a CVSS base score of 7.4, confirmed proof-of-concept exploit code is circulating, and released out-of-band patches (2023: Update 12, 2021: Update 18) on December 23, 2024, urging immediate updates to mitigate risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
