EXPOSURES › CVE-2023-26360
CVE-2023-26360
HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
⚡ RCE
◐ ZERO-DAY
⌖ EXPLOITED IN THE WILD
SHAME 72/100
rceexploited-in-wildunpatched
Adobe ColdFusion RCE flaw exploited before patch
Adobe ColdFusion allowed remote code execution through deserialization, with an unpatched vulnerability actively exploited in the wild.
Shame score — Critical RCE flaw exploited before patch availability.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
PLAYERS IMPLICATED
DESCRIPTION
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for remote code execution.
AFFECTED FEDRAMP PRODUCTS · 8
| PRODUCT | STATUS |
|---|---|
| Adobe Acrobat Sign for Government Adobe |
Authorized |
| Adobe Analytics Adobe |
Authorized |
| Adobe Campaign Adobe |
Authorized |
| Adobe Connect Managed Services (ACMS-GC) Adobe |
Authorized |
| Adobe Creative Cloud for Enterprise Adobe |
Authorized |
| Adobe Document Cloud (PDF Services & Adobe Sign) Adobe |
Authorized |
| Adobe Experience Manager Managed Services (AEMMS-GC) Adobe |
Authorized |
| Adobe Learning Manager Adobe |
Authorized |