Skip to content
COOEY

FAIL › dossier

ColdFusion

PRODUCT

· dossier confidence 60%

ColdFusion is a legacy web development platform with a severe and recurring security track record. The platform suffers from frequent critical remote code execution vulnerabilities, particularly through deserialization and path traversal flaws, which are often exploited rapidly by attackers before patches are applied.

PROFILE
CategorysoftwareWhat they doColdFusion is a web application development platform and scripting language used for building dynamic websites and enterprise applications.Founded1998HQSan Jose, California Websitehttps://coldfusion.adobe.com ↗
SECURITY POSTURE

ColdFusion has a historically poor security posture, characterized by repeated critical remote code execution (RCE) vulnerabilities, deserialization flaws, and improper access controls that frequently lead to exploitation within hours of disclosure.

Notable failures
  • CVE-2023-29300 critical RCE
  • CVE-2023-38203 critical RCE
  • CVE-2026-48282 path traversal RCE exploited in 2 hours
  • CVE-2018-15961 unrestricted file upload RCE
  • CVE-2013-0625 authentication bypass
  • CVE-2023-26360 RCE0day
Patterns: repeated unpatched deserialization RCEs; critical flaws exploited within hours of disclosure; path traversal leading to arbitrary code execution; authentication bypasses granting administrative access
FAILURE HISTORY · 22
DATEEVENTSEVSUMMARY
2024-01-08 CVE-2023-38203 critical Adobe ColdFusion suffered a critical deserialization vulnerability allowing remote code execution, linked to ransomware attacks.
2024-01-08 CVE-2023-29300 critical Adobe ColdFusion suffered a critical deserialization vulnerability allowing remote code execution, linked to ransomware attacks.
2022-03-07 CVE-2013-0625 high An authentication bypass in Adobe ColdFusion allowed unauthorized administrative access, later linked to CVSS 10.0 command and eval injection flaws.
2022-03-07 CVE-2013-0631 high Adobe ColdFusion suffered from critical unpatched command injection and eval injection flaws enabling remote code execution and privilege escalation.
2022-03-03 CVE-2013-0632 high An authentication bypass in Adobe ColdFusion allowed unauthorized administrative access, later linked to CVSS 10.0 command and eval injection flaws.
2021-11-03 CVE-2018-4939 high Adobe ColdFusion suffered a deserialization of untrusted data vulnerability allowing remote code execution.
2021-11-03 CVE-2018-15961 high Adobe ColdFusion's unrestricted file upload flaw allowed remote code execution, enabling attackers to upload and execute malicious files on vulnerable systems.
2023-08-21 CVE-2023-26359 high Adobe ColdFusion's deserialization vulnerability (CVE-2023-26359) allows for code execution, and is currently being exploited in the wild.
2023-03-15 CVE-2023-26360 high Adobe ColdFusion RCE flaw exploited before patch
2022-03-25 CVE-2010-2861 critical Adobe ColdFusion's directory traversal vulnerability allowed attackers to read arbitrary files via the administrator console, and is currently being exploited in the wild, often linked to ransomware attacks.
2026-07-07 CVE-2026-48282 high Adobe ColdFusion allows arbitrary code execution via path traversal, enabling attackers to run commands as the current user.
2025-02-24 CVE-2017-3066 high Adobe ColdFusion's deserialization vulnerability (CVE-2017-3066) enabled arbitrary code execution, actively exploited in the wild, demonstrating a recurring security weakness in the platform.
2024-12-16 CVE-2024-20767 high Adobe ColdFusion's unpatched improper access control flaw (CVE-2024-20767) lets attackers modify restricted files via exposed admin panels.
2022-03-07 CVE-2013-0629 high Adobe ColdFusion suffered a directory traversal vulnerability allowing unauthorized access to restricted directories.
2023-07-20 CVE-2023-29298 high Adobe ColdFusion's improper access control vulnerability allows security feature bypass, actively exploited in the wild.
2023-07-20 CVE-2023-38205 high Adobe ColdFusion's improper access control vulnerability allows security feature bypass, actively exploited in the wild.
2026-07-14 CVE-2026-48320 high CVE-2026-48320: ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability.
2026-06-09 CVE-2026-47932 high CVE-2026-47932: ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Limi
2026-06-09 CVE-2026-47931 high CVE-2026-47931: ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Inpu
2026-06-09 CVE-2026-47928 critical CVE-2026-47928: ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Inpu
2026-06-09 CVE-2026-47929 high CVE-2026-47929: ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Incorrect Aut
2010-08-11 CVE-2010-2861 critical CVE-2010-2861: Multiple directory traversal vulnerabilities in the administrator console in Ado
Open questions: Exact founding year of ColdFusion · Current ownership structure post-Adobe acquisition · Specific number of employees in the ColdFusion development team
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-17 04:14:04.183448+00:00