logo

Adobe ColdFusion Vulnerability: Critical Bug (CVE-2024-53961) with PoC Exploit Code Discovered

ID: 05137c63-7f31-55b9-9587-9d6e254fde99

STIX ID: report--05137c63-7f31-55b9-9587-9d6e254fde99

Feed Name: The Cyber Express

Threat Score
75/100

Date Published: 2024-12-24

Date Updated: 2026-04-23

Author: Ashish Khaitan

...
...

Adobe disclosed a critical path traversal vulnerability (CVE-2024-53961) affecting ColdFusion 2023 (≤Update 11) and 2021 (≤Update 17) that permits unauthorized arbitrary file reads; Adobe rated it Priority 1 with a CVSS base score of 7.4, confirmed proof-of-concept exploit code is circulating, and released out-of-band patches (2023: Update 12, 2021: Update 18) on December 23, 2024, urging immediate updates to mitigate risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.