EXPOSURES › CVE-2023-29300
CVE-2023-29300
CRITICAL ⌖ ON CISA KEV · EXPLOITEDAdobe ColdFusion suffered a critical deserialization vulnerability allowing remote code execution, linked to ransomware attacks.
The vulnerability in Adobe ColdFusion allowed attackers to execute arbitrary code through deserialization of untrusted data, directly enabling ransomware deployment. DIB organizations must ensure all ColdFusion instances are patched immediately, as this flaw was actively exploited in the wild and represents a severe compliance risk under CMMC/NIST 800-171 for unpatched critical vulnerabilities.
Shame score — A critical, actively exploited vulnerability linked to ransomware that Adobe failed to patch promptly, demonstrating severe negligence and avoidable exposure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution.
| PRODUCT | STATUS |
|---|---|
| Adobe Acrobat Sign for Government Adobe |
Authorized |
| Adobe Analytics Adobe |
Authorized |
| Adobe Campaign Adobe |
Authorized |
| Adobe Connect Managed Services (ACMS-GC) Adobe |
Authorized |
| Adobe Creative Cloud for Enterprise Adobe |
Authorized |
| Adobe Document Cloud (PDF Services & Adobe Sign) Adobe |
Authorized |
| Adobe Experience Manager Managed Services (AEMMS-GC) Adobe |
Authorized |
| Adobe Learning Manager Adobe |
Authorized |