EXPOSURES › CVE-2023-26359
CVE-2023-26359
HIGH ⌖ ON CISA KEV · EXPLOITEDAdobe ColdFusion's deserialization vulnerability (CVE-2023-26359) allows for code execution, and is currently being exploited in the wild.
A deserialization flaw in Adobe ColdFusion enables attackers to execute arbitrary code, potentially compromising systems running the platform. DIB organizations using ColdFusion face significant compliance risks under NIST 800-171 and CMMC, and should immediately patch affected versions and review system logs for signs of compromise. Legacy systems like ColdFusion require heightened scrutiny and mitigation strategies.
Shame score — Adobe's recurring security issues with ColdFusion, coupled with active exploitation, demonstrate a pattern of negligence and inadequate security practices.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could result in code execution in the context of the current user.
| PRODUCT | STATUS |
|---|---|
| Adobe Acrobat Sign for Government Adobe |
Authorized |
| Adobe Analytics Adobe |
Authorized |
| Adobe Campaign Adobe |
Authorized |
| Adobe Connect Managed Services (ACMS-GC) Adobe |
Authorized |
| Adobe Creative Cloud for Enterprise Adobe |
Authorized |
| Adobe Document Cloud (PDF Services & Adobe Sign) Adobe |
Authorized |
| Adobe Experience Manager Managed Services (AEMMS-GC) Adobe |
Authorized |
| Adobe Learning Manager Adobe |
Authorized |