Adobe released security updates for Adobe ColdFusion to fix CVE-2024-53961, a critical vulnerability that allows a remote unauthenticated attacker to read arbitrary files from affected servers. The flaw impacts ColdFusion 2023 versions earlier than Update 12 and ColdFusion 2021 versions earlier than Update 18, creating a path for attackers to access sensitive information stored on vulnerable systems.
Security advisories warned that the exposed data could be used to support follow-on attacks and potentially lead to broader system compromise. A public proof-of-concept exploit is already available, raising the risk of exploitation attempts against unpatched internet-facing servers. Adobe advised organizations to upgrade immediately to ColdFusion 2023 Update 12 or ColdFusion 2021 Update 18 and to apply the vendor’s recommended configuration guidance.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
CSIRT.SK reported that a proof-of-concept exploit for CVE-2024-53961 was already publicly available, increasing the likelihood of exploitation attempts against vulnerable Adobe ColdFusion servers. The notice also highlighted the risk of arbitrary file reads exposing sensitive data for follow-on attacks.
Adobe released security updates to fix CVE-2024-53961, a critical arbitrary file-read vulnerability affecting ColdFusion 2023 before Update 12 and ColdFusion 2021 before Update 18. Adobe advised customers to upgrade to ColdFusion 2023 Update 12 or ColdFusion 2021 Update 18 and follow the vendor's configuration guidance.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.