← Back to browse · API

CVE-2023-26359

Severity
CRITICAL
CVSS
9.8
EPSS
0.17937
Risk score
70.48
CISA KEV
Yes
PoC
No
Published
2023-03-23
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2023-30180, GHSA-P4MQ-MQPJ-7XCJ
Products
Adobe:ColdFusion, Adobe:ColdFusion unspecified ≤CF2018U15, CF2021U5, Adobe:ColdFusion unspecified ≤None
Sources
cisa.gov CVE-2023-26359
euvd EUVD-2023-30180

Description

Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.

References