CVE-2018-15961: critical vulnerability in Adobe ColdFusion
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Apply updates per vendor instructions.
Adobe ColdFusion allows attackers to upload files without proper restrictions, potentially leading to malicious code execution on the server. This is a critical flaw because it can give attackers complete control over the affected system.
An unrestricted file upload vulnerability (CWE-434) in Adobe ColdFusion enables attackers to bypass upload validation controls and execute arbitrary code on the server. Exploitation requires network access to the upload functionality; successful code execution compromises the entire application and underlying system integrity.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.