EXPOSURES › CVE-2010-2861
CVE-2010-2861
CRITICAL ⌖ ON CISA KEV · EXPLOITEDAdobe ColdFusion's directory traversal vulnerability allowed attackers to read arbitrary files via the administrator console, and is currently being exploited in the wild, often linked to ransomware attacks.
A directory traversal vulnerability in Adobe ColdFusion's administrator console enabled unauthorized file access, posing a significant risk to DIB organizations using the platform. This exposes sensitive data and increases the likelihood of ransomware infection, potentially impacting CMMC compliance. Organizations should immediately patch ColdFusion and review access controls.
Shame score — The vulnerability's exploitation in the wild and association with ransomware demonstrates a serious and avoidable security lapse in a widely-used platform.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A directory traversal vulnerability exists in the administrator console in Adobe ColdFusion which allows remote attackers to read arbitrary files.
| PRODUCT | STATUS |
|---|---|
| Adobe Acrobat Sign for Government Adobe |
Authorized |
| Adobe Analytics Adobe |
Authorized |
| Adobe Campaign Adobe |
Authorized |
| Adobe Connect Managed Services (ACMS-GC) Adobe |
Authorized |
| Adobe Creative Cloud for Enterprise Adobe |
Authorized |
| Adobe Document Cloud (PDF Services & Adobe Sign) Adobe |
Authorized |
| Adobe Experience Manager Managed Services (AEMMS-GC) Adobe |
Authorized |
| Adobe Learning Manager Adobe |
Authorized |