Adobe ColdFusion
cpe:2.3:a:adobe:coldfusion:*:*:*:*:*:*:*
- <= 2025.6
- <= 2023.18
A denial-of-service vulnerability has been identified in Adobe ColdFusion versions 2023.18, 2025.6 and earlier. This vulnerability allows a high-privileged attacker to exhaust system resources, causing a slowdown in application performance. The issue arises from uncontrolled resource consumption, and exploitation does not require user interaction.
Exploitation of this vulnerability can lead to application denial-of-service, causing a significant reduction in application speed and performance.
Users are advised to update to ColdFusion 2025 Update 7 or ColdFusion 2023 Update 19. For more information, refer to the Adobe ColdFusion downloads page or the respective ColdFusion 2025 and 2023 Lockdown Guides.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.