Adobe has released security updates to fix various vulnerabilities , including several bugs in ColdFusion versions 2025, 2023 , and 2021 .
See also: Microsoft released Patch Tuesday April 2025

Of the 30 vulnerabilities identified and fixed, 11 are considered critical. Below we will briefly review these vulnerabilities:
- CVE-2025-24446 (CVSS score: 9.1/10): This is a vulnerability that could lead to arbitrary file system read.
- CVE-2025-24447 (CVSS Score: 9.1/10): Vulnerability that could lead to arbitrary code execution.
- CVE-2025-30281 (CVSS score: 9.1/10): Vulnerability that could lead to arbitrary file system read.
- CVE-2025-30282 (CVSS Score: 9.1/10): Vulnerability that could lead to arbitrary code execution.
- CVE-2025-30284 (CVSS Score: 8.0/10): Vulnerability that could lead to arbitrary code execution.
- CVE-2025-30285 (CVSS Score: 8.0/10): Vulnerability that could lead to arbitrary code execution.
- CVE-2025-30286 (CVSS score: 8.0/10): Vulnerability that could lead to arbitrary code execution.
- CVE-2025-30287 (CVSS score: 8.1/10): Vulnerability that could lead to arbitrary code execution.
- CVE-2025-30288 (CVSS score: 7.8/10): Vulnerability that could lead to feature bypass .
- CVE-2025-30289 (CVSS score: 7.5/10): Vulnerability that could lead to arbitrary code execution.
- CVE-2025-30290 (CVSS score: 8.710): Vulnerability that could lead to security feature bypass.
Adobe fixed the above (and other) vulnerabilities in the following versions:
- ColdFusion 2021 Update 19
- ColdFusion 2023 Update 13
- ColdFusion 2025 Update 1
See also: WhatsApp vulnerability puts Windows systems at risk
The company has also fixed out-of-bounds write and heap-based buffer overflow vulnerabilities in other products: After Effects (CVE-2025-27182, CVE-2025-27183), Media Encoder (CVE-2025-27194, CVE-2025-27195), Bridge (CVE-2025-27193), Premiere Pro (CVE-2025-27196), Photoshop (CVE-2025-27198), Animate (CVE-2025-27199) and FrameMaker (CVE-2025-30304, CVE-2025-30297, CVE-2025-30295). These vulnerabilities could also lead to code execution.

Protection
Although there is no evidence of active exploitation of the above vulnerabilities, it is essential to apply security updates. Regularly updating Adobe ColdFusion security is critical. Failure to install these updates may leave the system vulnerable to attacks and security breaches.
See also: Vulnerability in Nissan Leaf allows full control of the car
Additionally, experts recommend implementing network segmentation, using a firewall or WAF, and enforcing signed software execution policies.
You also need to properly configure your ColdFusion server. This includes disabling unnecessary services and features.
Finally, it is important to implement strict security policies and regularly monitor logs for signs of unwanted activity.
Source: thehackernews.com
