ColdFusion versions 2025.9, 2023.20 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed.
| Vendor | Product | Versions |
|---|---|---|
| adobe | coldfusion | 0 |
Updated severity to CRITICAL, marked exploit as not available, and noted that the vulnerability is actively exploited.
Initial creation