FAIL › dossier
ColdFusion
PRODUCT· dossier confidence 60%
ColdFusion is a legacy web development platform with a severe and recurring security track record. The platform suffers from frequent critical remote code execution vulnerabilities, particularly through deserialization and path traversal flaws, which are often exploited rapidly by attackers before patches are applied.
PROFILE
CategorysoftwareWhat they doColdFusion is a web application development platform and scripting language used for building dynamic websites and enterprise applications.Founded1998HQSan Jose, California
Websitehttps://coldfusion.adobe.com ↗
SECURITY POSTURE
ColdFusion has a historically poor security posture, characterized by repeated critical remote code execution (RCE) vulnerabilities, deserialization flaws, and improper access controls that frequently lead to exploitation within hours of disclosure.
Notable failures
- CVE-2023-29300 critical RCE
- CVE-2023-38203 critical RCE
- CVE-2026-48282 path traversal RCE exploited in 2 hours
- CVE-2018-15961 unrestricted file upload RCE
- CVE-2013-0625 authentication bypass
- CVE-2023-26360 RCE0day
Patterns: repeated unpatched deserialization RCEs; critical flaws exploited within hours of disclosure; path traversal leading to arbitrary code execution; authentication bypasses granting administrative access
FAILURE HISTORY · 22
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2024-01-08 | CVE-2023-38203 | critical | Adobe ColdFusion suffered a critical deserialization vulnerability allowing remote code execution, linked to ransomware attacks. |
| 2024-01-08 | CVE-2023-29300 | critical | Adobe ColdFusion suffered a critical deserialization vulnerability allowing remote code execution, linked to ransomware attacks. |
| 2022-03-07 | CVE-2013-0625 | high | An authentication bypass in Adobe ColdFusion allowed unauthorized administrative access, later linked to CVSS 10.0 command and eval injection flaws. |
| 2022-03-07 | CVE-2013-0631 | high | Adobe ColdFusion suffered from critical unpatched command injection and eval injection flaws enabling remote code execution and privilege escalation. |
| 2022-03-03 | CVE-2013-0632 | high | An authentication bypass in Adobe ColdFusion allowed unauthorized administrative access, later linked to CVSS 10.0 command and eval injection flaws. |
| 2021-11-03 | CVE-2018-4939 | high | Adobe ColdFusion suffered a deserialization of untrusted data vulnerability allowing remote code execution. |
| 2021-11-03 | CVE-2018-15961 | high | Adobe ColdFusion's unrestricted file upload flaw allowed remote code execution, enabling attackers to upload and execute malicious files on vulnerable systems. |
| 2023-08-21 | CVE-2023-26359 | high | Adobe ColdFusion's deserialization vulnerability (CVE-2023-26359) allows for code execution, and is currently being exploited in the wild. |
| 2023-03-15 | CVE-2023-26360 | high | Adobe ColdFusion RCE flaw exploited before patch |
| 2022-03-25 | CVE-2010-2861 | critical | Adobe ColdFusion's directory traversal vulnerability allowed attackers to read arbitrary files via the administrator console, and is currently being exploited in the wild, often linked to ransomware attacks. |
| 2026-07-07 | CVE-2026-48282 | high | Adobe ColdFusion allows arbitrary code execution via path traversal, enabling attackers to run commands as the current user. |
| 2025-02-24 | CVE-2017-3066 | high | Adobe ColdFusion's deserialization vulnerability (CVE-2017-3066) enabled arbitrary code execution, actively exploited in the wild, demonstrating a recurring security weakness in the platform. |
| 2024-12-16 | CVE-2024-20767 | high | Adobe ColdFusion's unpatched improper access control flaw (CVE-2024-20767) lets attackers modify restricted files via exposed admin panels. |
| 2022-03-07 | CVE-2013-0629 | high | Adobe ColdFusion suffered a directory traversal vulnerability allowing unauthorized access to restricted directories. |
| 2023-07-20 | CVE-2023-29298 | high | Adobe ColdFusion's improper access control vulnerability allows security feature bypass, actively exploited in the wild. |
| 2023-07-20 | CVE-2023-38205 | high | Adobe ColdFusion's improper access control vulnerability allows security feature bypass, actively exploited in the wild. |
| 2026-07-14 | CVE-2026-48320 | high | CVE-2026-48320: ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. |
| 2026-06-09 | CVE-2026-47932 | high | CVE-2026-47932: ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Limi |
| 2026-06-09 | CVE-2026-47931 | high | CVE-2026-47931: ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Inpu |
| 2026-06-09 | CVE-2026-47928 | critical | CVE-2026-47928: ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Inpu |
| 2026-06-09 | CVE-2026-47929 | high | CVE-2026-47929: ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Incorrect Aut |
| 2010-08-11 | CVE-2010-2861 | critical | CVE-2010-2861: Multiple directory traversal vulnerabilities in the administrator console in Ado |
DOSSIER SOURCES
- Fermi (FRMI) Company Profile & Description - Stock Analysis · stockanalysis.com
- Top ColdFusion Development Companies | RightFirms · www.rightfirms.co
- Oklo Inc. (OKLO) Company Profile & Description - Stock Analysis · stockanalysis.com
- Profile - CRDO - NASDAQ - Weiss Ratings · weissratings.com
- Adobe ColdFusion CVE-2026-48282: Exploited in 2 Hours · tech-insider.org
- NOW LIVE! ColdFusion 2025 and 2023 July 2026 security updates · coldfusion.adobe.com
- Adobe ColdFusion CVE-2026-48282: Exploited in 2 Hours · tech-insider.org
- ColdFusion in 2026: What Still Runs on It and Why That's Not the ... · www.convective.com
- Reading old WDDX files in 2026 - mycfml.com · www.mycfml.com
Open questions: Exact founding year of ColdFusion · Current ownership structure post-Adobe acquisition · Specific number of employees in the ColdFusion development team
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-17 04:14:04.183448+00:00