Particle.news

Adobe ColdFusion Path-Traversal Flaw Is Being Exploited in the Wild

Unpatched ColdFusion servers face a remote code execution risk that makes immediate patching essential to prevent full compromise.

Overview

  • Threat researchers at KEVIntel say they observed attacks exploiting the flaw within two hours of public disclosure, based on activity in their global honeypot network.
  • The bug is a path traversal vulnerability that allows unauthenticated remote arbitrary code execution on ColdFusion versions 2025.9, 2023.20, and earlier.
  • Adobe has issued security updates and urged administrators to install them as soon as possible, recommending action within 72 hours, but the company also said it is not aware of active exploits for the patched issues.
  • The Canadian Centre for Cyber Security warned that open-source reporting indicates exploitation is happening and KEVIntel reported initial attack traffic from IP 103.207.14[.]220 attributed to an actor in India.
  • Internet scans from Shadowserver show roughly 800 ColdFusion instances exposed online, leaving a large attack surface and meaning unpatched sites risk data theft, server takeover, and wider network compromise.