HomeUpdatesAdobe patches 11 vulnerabilities in ColdFusion

Adobe patches 11 vulnerabilities in ColdFusion

Adobe has released security updates to fix various vulnerabilities , including several bugs in ColdFusion versions 2025, 2023 , and 2021 .

See also: Microsoft released Patch Tuesday April 2025

Adobe ColdFusion vulnerabilities

Of the 30 vulnerabilities identified and fixed, 11 are considered critical. Below we will briefly review these vulnerabilities:

  • CVE-2025-24446 (CVSS score: 9.1/10): This is a vulnerability that could lead to arbitrary file system read.
  • CVE-2025-24447 (CVSS Score: 9.1/10): Vulnerability that could lead to arbitrary code execution.
  • CVE-2025-30281 (CVSS score: 9.1/10): Vulnerability that could lead to arbitrary file system read.
  • CVE-2025-30282 (CVSS Score: 9.1/10): Vulnerability that could lead to arbitrary code execution.
  • CVE-2025-30284 (CVSS Score: 8.0/10): Vulnerability that could lead to arbitrary code execution.
  • CVE-2025-30285 (CVSS Score: 8.0/10): Vulnerability that could lead to arbitrary code execution.
  • CVE-2025-30286 (CVSS score: 8.0/10): Vulnerability that could lead to arbitrary code execution.
  • CVE-2025-30287 (CVSS score: 8.1/10): Vulnerability that could lead to arbitrary code execution.
  • CVE-2025-30288 (CVSS score: 7.8/10): Vulnerability that could lead to feature bypass .
  • CVE-2025-30289 (CVSS score: 7.5/10): Vulnerability that could lead to arbitrary code execution.

Adobe fixed the above (and other) vulnerabilities in the following versions:

  • ColdFusion 2021 Update 19
  • ColdFusion 2023 Update 13
  • ColdFusion 2025 Update 1

See also: WhatsApp vulnerability puts Windows systems at risk

The company has also fixed out-of-bounds write and heap-based buffer overflow vulnerabilities in other products: After Effects (CVE-2025-27182, CVE-2025-27183), Media Encoder (CVE-2025-27194, CVE-2025-27195), Bridge (CVE-2025-27193), Premiere Pro (CVE-2025-27196), Photoshop (CVE-2025-27198), Animate (CVE-2025-27199) and FrameMaker (CVE-2025-30304, CVE-2025-30297, CVE-2025-30295). These vulnerabilities could also lead to code execution.

Adobe patches 11 vulnerabilities in ColdFusion

Protection

Although there is no evidence of active exploitation of the above vulnerabilities, it is essential to apply security updates. Regularly updating Adobe ColdFusion security is critical. Failure to install these updates may leave the system vulnerable to attacks and security breaches.

See also: Vulnerability in Nissan Leaf allows full control of the car

Additionally, experts recommend implementing network segmentation, using a firewall or WAF, and enforcing signed software execution policies.

You also need to properly configure your ColdFusion server. This includes disabling unnecessary services and features.

Finally, it is important to implement strict security policies and regularly monitor logs for signs of unwanted activity.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS