Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Application Security

Adobe Patches Critical ColdFusion Security Flaw

Adobe has released an urgent patch for a potentially dangerous security vulnerability in Adobe ColdFusion, the platform used for building and deploying mobile and web apps.

Adobe has released an urgent patch for a potentially dangerous security vulnerability in Adobe ColdFusion, the platform used for building and deploying mobile and web apps.

“These updates resolve a critical vulnerability that could lead to arbitrary code execution,” Adobe said in an advisory issued on Monday. 

The security updates are available for ColdFusion versions 2021 (including version 2021.0.0.323925), 2016 and 2018.

Adobe said it has not observed signs of in-the-wild exploitation targeting the new CVE-2021-20187 vulnerability.  

According to Adobe’s advisory, the vulnerability is described as “improper input validation” that could lead to arbitrary remote code execution.

The company recommends that users update the ColdFusion JDK/JRE to the latest version of the LTS releases for 1.8 and JDK 11.  “Applying the ColdFusion update without a corresponding JDK update will NOT secure the server,” Adobe warned.

The company also published security configuration settings and lockdown guides for ColdFusion deployments.

Related: Adobe Patches Critical Flaws in AEM, FrameMaker, InDesign

Advertisement. Scroll to continue reading.

Related: Adobe Patches 11 Critical Vulnerabilities in Acrobat and Reader

Written By

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this event as we dive into threat hunting tools and frameworks, and explore value of threat intelligence data in the defender’s security stack.

Register

Learn how integrating BAS and Automated Penetration Testing empowers security teams to quickly identify and validate threats, enabling prompt response and remediation.

Register

People on the Move

Wendi Whitmore has taken the role of Chief Security Intelligence Officer at Palo Alto Networks.

Phil Venables, former CISO of Google Cloud, has joined Ballistic Ventures as a Venture Partner.

David Currie, former CISO of Nubank and Klarna, has been appointed CEO of Vaultree.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.