๐Ÿ” CVE Alert

CVE-2023-26360

HIGH 8.6 โš ๏ธ CISA KEV

Adobe ColdFusion Improper Access Control Arbitrary code execution

CVSS Score
8.6
EPSS Score
0.0%
EPSS Percentile
0th

Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.

CWE CWE-284
Vendor adobe
Product coldfusion
Ecosystems
Industries
TechnologyMedia
Published Mar 23, 2023
Last Updated Oct 21, 2025
โš ๏ธ Actively Exploited โ€” Act Now

Get instant alerts for adobe coldfusion

This vulnerability is actively exploited in the wild. Set up free real-time alerts so you're first to know about threats like CVE-2023-26360.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

Adobe / ColdFusion
unspecified โ‰ค CF2018U15 unspecified โ‰ค CF2021U5 unspecified โ‰ค None

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
helpx.adobe.com: https://helpx.adobe.com/security/products/coldfusion/apsb23-25.html packetstormsecurity.com: http://packetstormsecurity.com/files/172079/Adobe-ColdFusion-Unauthenticated-Remote-Code-Execution.html cisa.gov: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-26360