⚠ Actively exploited
Added to CISA KEV on 2023-03-15. Federal agencies required to patch by 2023-04-05. Required action: Apply updates per vendor instructions..

CVE-2023-26360Improper Access Control in Adobe Coldfusion

Severity
9.8CRITICALNVD
CNA8.6VulnCheck8.6
EPSS
94.3%
top 0.05%
CISA KEV
KEV
Added 2023-03-15
Due 2023-04-05
Exploit
Exploited in wild
Active exploitation observed
Affected products
Timeline
KEV addedMar 15
PublishedMar 23
KEV dueApr 5
Latest updateJan 12
CISA Required Action: Apply updates per vendor instructions.

Description

Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

CVEListV5adobe/coldfusionunspecifiedCF2018U15+2
NVDadobe/coldfusion2018, 2021+1

Patches

🔴Vulnerability Details

3
GHSA
GHSA-p86r-cr5m-73hp: Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Access Control vulnerability that c2023-03-23
CVEList
Adobe ColdFusion Improper Access Control Arbitrary code execution2023-03-23
VulnCheck
Adobe ColdFusion Deserialization of Untrusted Data Vulnerability2023

💥Exploits & PoCs

2
Exploit-DB
Adobe ColdFusion versions 2018_15 (and earlier) and 2021_5 and earlier - Arbitrary File Read2024-03-11
Nuclei
Adobe ColdFusion - Local File Read

🔍Detection Rules

5
Suricata
ET WEB_SPECIFIC_APPS Adobe Coldfusion Local File Inclusion Attempt (CVE-2023-26360, CVE-2023-26359) M12023-12-06
Suricata
ET WEB_SPECIFIC_APPS Adobe Coldfusion Local File Inclusion Attempt (CVE-2023-26360, CVE-2023-26359) M22023-12-06
Suricata
ET EXPLOIT Adobe ColdFusion Deserialization of Untrusted Data (CVE-2023-26360) M12023-12-05
Suricata
ET EXPLOIT Adobe ColdFusion Deserialization of Untrusted Data (CVE-2023-26360) M22023-12-05
Suricata
ET EXPLOIT Adobe ColdFusion Deserialization of Untrusted Data (CVE-2023-26360) M32023-12-05

📋Vendor Advisories

1
CISA
Adobe ColdFusion Deserialization of Untrusted Data Vulnerability2023-03-15

🕵️Threat Intelligence

4
Wiz
Crying Out Cloud - January Newsletter | Wiz2024-01-01
Bleepingcomputer
Hackers breach US govt agencies using Adobe ColdFusion exploit2023-12-05
Sentinelone
CVE-2023-26360: A Critical Vulnerability in Adobe ColdFusion2023-05-25
Sentinelone
CVE-2023-26360: A Critical Vulnerability in Adobe ColdFusion2023-05-25

💬Community

2
HackerOne
Unauthenticated File Read Adobe ColdFusion2026-01-12
HackerOne
Unauthenticated File Read Adobe ColdFusion2023-12-21
CVE-2023-26360 — Improper Access Control in Adobe | cvebase