Winter is coming… and so is CVE-2023-26360: Critical Adobe ColdFusion Vulnerability Exploited in the Wild

Share This Post

The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability, CVE-2023-26360, that affects Adobe ColdFusion 2018 and 2021 versions to its catalog of security bugs that have been exploited in the wild. This flaw is due to an Improper Access Control weakness and can be remotely abused by unauthenticated attackers in low-complexity attacks that don’t require user interaction. Adobe has patched this vulnerability in ColdFusion 2018 Update 16 and ColdFusion 2021 Update 6, and it has been used as a zero-day vulnerability in limited attacks targeting Adobe ColdFusion. The administrators are advised to install security updates and apply security configuration settings outlined in the ColdFusion 2018 and ColdFusion 2021 lockdown guides. The CISA has given all US Federal Civilian Executive Branch Agencies (FCEB) agencies three weeks to secure their systems against potential attacks using CVE-2023-26360 exploits.

Links:

https://helpx.adobe.com/security/products/coldfusion/apsb23-25.html

https://www.bleepingcomputer.com/news/security/cisa-warns-of-adobe-coldfusion-bug-exploited-as-a-zero-day/

ColdFusion 2018 lockdown guide:

https://helpx.adobe.com/coldfusion/using/server-lockdown.html

ColdFusion 2021 lockdown guide:

https://www.adobe.com/content/dam/cc/us/en/products/coldfusion/pdfs/cf-starter-kits/coldfusion-2021-lockdown-guide-1.1.pdf



Reach out to our incident response team for help

More To Explore

Information Security News – 11/17/2025

Hackers Breach Texting Service Used by New York State, Sending Hundreds of Thousands of Scam Texts Article Link: https://www.nbcnews.com/tech/security/text-scam-phone-sms-hack-message-fake-transaction-call-new-york-rcna243349 Cisco ASA Firewalls Still Under Attack;

Information Security News – 11/10/2025

You’ll Never Guess What the Most Common Passwords Are. Oh, Wait, Yes You Will Article Link: https://www.theregister.com/2025/11/06/most_common_passwords/ The Louvre’s Video Security Password Was Reportedly ‘Louvre’

Do You Want to Shore Up Your Defenses?

We're opening our first round of threat hunting engagements to 100 organizations. Sign up or join the wait list here.