Umbra Wiki cve cve/CVE-2023-26359
Back to wiki

CVE-2023-26359 — Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

provenance: imported · CVE: CVE-2023-26359

CVE-2023-26359: Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Adobe
Product ColdFusion
Date added 2023-08-21
Due date 2023-09-11
Ransomware campaign use Unknown

Description

Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could result in code execution in the context of the current user.

Required action (CISA)

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Notes

https://helpx.adobe.com/security/products/coldfusion/apsb23-25.html; https://nvd.nist.gov/vuln/detail/CVE-2023-26359

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2023-26359
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog