CVE-2023-26359
Published on: Not Yet Published
Last Modified on: 03/28/2023 01:00:00 PM UTC
Certain versions of Coldfusion from Adobe contain the following vulnerability:
Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.
- CVE-2023-26359 has been assigned by
[email protected] to track the vulnerability - currently rated as CRITICAL severity.
- Affected Vendor/Software:
Adobe - ColdFusion version <= CF2018U15, CF2021U5
- Affected Vendor/Software:
Adobe - ColdFusion version <= None
- Affected Vendor/Software:
Adobe - ColdFusion version <= None
- Affected Vendor/Software:
Adobe - ColdFusion version <= None
CVSS3 Score: 9.8 - CRITICAL
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Adobe Security Bulletin | helpx.adobe.com text/html |
![]() |
Related QID Numbers
- 378080 Adobe ColdFusion Multiple Vulnerabilities (APSB23-25)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Adobe | Coldfusion | 2018 | - | All | All |
Application | Adobe | Coldfusion | 2018 | update1 | All | All |
Application | Adobe | Coldfusion | 2018 | update10 | All | All |
Application | Adobe | Coldfusion | 2018 | update11 | All | All |
Application | Adobe | Coldfusion | 2018 | update12 | All | All |
Application | Adobe | Coldfusion | 2018 | update13 | All | All |
Application | Adobe | Coldfusion | 2018 | update14 | All | All |
Application | Adobe | Coldfusion | 2018 | update15 | All | All |
Application | Adobe | Coldfusion | 2018 | update2 | All | All |
Application | Adobe | Coldfusion | 2018 | update3 | All | All |
Application | Adobe | Coldfusion | 2018 | update4 | All | All |
Application | Adobe | Coldfusion | 2018 | update5 | All | All |
Application | Adobe | Coldfusion | 2018 | update6 | All | All |
Application | Adobe | Coldfusion | 2018 | update7 | All | All |
Application | Adobe | Coldfusion | 2018 | update8 | All | All |
Application | Adobe | Coldfusion | 2018 | update9 | All | All |
Application | Adobe | Coldfusion | 2021 | - | All | All |
Application | Adobe | Coldfusion | 2021 | update1 | All | All |
Application | Adobe | Coldfusion | 2021 | update2 | All | All |
Application | Adobe | Coldfusion | 2021 | update3 | All | All |
Application | Adobe | Coldfusion | 2021 | update4 | All | All |
Application | Adobe | Coldfusion | 2021 | update5 | All | All |
- cpe:2.3:a:adobe:coldfusion:2018:-:*:*:*:*:*:*:
- cpe:2.3:a:adobe:coldfusion:2018:update1:*:*:*:*:*:*:
- cpe:2.3:a:adobe:coldfusion:2018:update10:*:*:*:*:*:*:
- cpe:2.3:a:adobe:coldfusion:2018:update11:*:*:*:*:*:*:
- cpe:2.3:a:adobe:coldfusion:2018:update12:*:*:*:*:*:*:
- cpe:2.3:a:adobe:coldfusion:2018:update13:*:*:*:*:*:*:
- cpe:2.3:a:adobe:coldfusion:2018:update14:*:*:*:*:*:*:
- cpe:2.3:a:adobe:coldfusion:2018:update15:*:*:*:*:*:*:
- cpe:2.3:a:adobe:coldfusion:2018:update2:*:*:*:*:*:*:
- cpe:2.3:a:adobe:coldfusion:2018:update3:*:*:*:*:*:*:
- cpe:2.3:a:adobe:coldfusion:2018:update4:*:*:*:*:*:*:
- cpe:2.3:a:adobe:coldfusion:2018:update5:*:*:*:*:*:*:
- cpe:2.3:a:adobe:coldfusion:2018:update6:*:*:*:*:*:*:
- cpe:2.3:a:adobe:coldfusion:2018:update7:*:*:*:*:*:*:
- cpe:2.3:a:adobe:coldfusion:2018:update8:*:*:*:*:*:*:
- cpe:2.3:a:adobe:coldfusion:2018:update9:*:*:*:*:*:*:
- cpe:2.3:a:adobe:coldfusion:2021:-:*:*:*:*:*:*:
- cpe:2.3:a:adobe:coldfusion:2021:update1:*:*:*:*:*:*:
- cpe:2.3:a:adobe:coldfusion:2021:update2:*:*:*:*:*:*:
- cpe:2.3:a:adobe:coldfusion:2021:update3:*:*:*:*:*:*:
- cpe:2.3:a:adobe:coldfusion:2021:update4:*:*:*:*:*:*:
- cpe:2.3:a:adobe:coldfusion:2021:update5:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
Múltiples vulnerabilidades afectan a Adobe ColdFusion - Vulnerabilidad CVE-2023-26359 - Vulnerabilidad CVE-2023-2… twitter.com/i/web/status/1… | 2023-03-17 20:41:51 |
![]() |
El 14 de marzo Adobe dió a conocer las siguientes vulnerabilidades: - CVE-2023-26359: CVSS score 9.8. - CVE-202… twitter.com/i/web/status/1… | 2023-03-21 15:20:35 |
![]() |
CVE-2023-26359 : Adobe ColdFusion versions 2018 Update 15 and earlier and 2021 Update 5 and earlier are affecte… twitter.com/i/web/status/1… | 2023-03-23 20:08:28 |
![]() |
MS-ISAC CYBERSECURITY ADVISORY - Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution - PATCH NOW | 2023-03-15 12:44:55 |
![]() |
CVE-2023-26359 | 2023-03-23 20:38:26 |