LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-26359: Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

RBRecent Breaches Vulnerability Intelligence·Aug 21, 2023
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Sep 11, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-26359 to its Known Exploited Vulnerabilities catalog on Aug 21, 2023, with a federal patch deadline of Sep 11, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could result in code execution in the context of the current user.

CVE-2023-26359 is a deserialization of untrusted data vulnerability in Adobe ColdFusion. It can allow an attacker to achieve code execution in the context of the current user. For IT and security teams, this matters because ColdFusion often underpins business applications that process external or semi-trusted input; successful abuse can lead to full compromise of the application host and lateral movement into connected systems.

Public detail is limited to the CISA summary and the CWE classification. Confirm exact affected builds, fixed versions, and any configuration prerequisites against the official Adobe advisory before taking action.

How it works

The weakness is CWE-502: Deserialization of Untrusted Data. ColdFusion, like many application platforms, can reconstruct objects from serialized data streams. When that data is attacker-controlled and is not properly validated or restricted, the reconstruction process can be coerced into executing unintended code or instantiating dangerous objects.

An attacker who can supply crafted serialized input to a vulnerable ColdFusion endpoint or service may trigger code execution under the privileges of the ColdFusion process or the user account it runs as. No public exploit mechanics or payload details are provided in the available facts; treat any observed anomalous deserialization activity as potentially malicious and investigate against the vendor advisory.

Am I affected? How to find it in your systems

Adobe ColdFusion is typically deployed as a standalone application server or as part of web-facing or internal business applications that generate dynamic content, process forms, or integrate with databases and other services. It may run on Windows or Linux hosts, often behind a web server or reverse proxy.

How to remediate

Patch first. Apply the vendor-supplied update or mitigation instructions published by Adobe for this CVE. CISA’s required action is to apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

If you can't patch immediately

Until the vendor update can be applied, reduce the attack surface with compensating controls.

These measures lower risk but do not eliminate it; schedule the official patch as soon as operationally feasible.

If your data may have been exposed

Actively exploited vulnerabilities of this class can lead to breaches in which application data, credentials, or adjacent systems are compromised. Known ransomware use is not documented for this CVE. If you suspect exploitation, isolate affected hosts, preserve logs and memory images, and begin forensic review. As a quick personal check, individuals can run a free exposure scan of their email addresses against known breach data sets to see whether their credentials appear in public dumps, then force password resets and enable multi-factor authentication where relevant.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedAdobe · ColdFusion
WeaknessCWE-502
Added to CISA KEVAug 21, 2023
Federal patch deadlineSep 11, 2023
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities