Adobe ColdFusion known exploited vulnerabilities, ranked
CISA lists 16 Adobe ColdFusion CVEs as exploited in the wild. 1 were added in the last 12 months and 3 are known to be used in ransomware. The table ranks all of them by EPSS, FIRST's estimate of the chance a CVE is exploited in the next 30 days, so the first rows are the ones to patch first.
Patch these first
- CVE-2023-29300: EPSS 99.99%, used in ransomware, added 2024-01-08
- CVE-2018-15961: EPSS 99.95%, added 2021-11-03
- CVE-2023-29298: EPSS 99.79%, added 2023-07-20
- CVE-2010-2861: EPSS 99.75%, used in ransomware, added 2022-03-25
- CVE-2023-38205: EPSS 99.74%, added 2023-07-20
All 16 Adobe ColdFusion CVEs in CISA KEV, by EPSS
| # | CVE | Flaw | EPSS | Ransomware | Added | Federal due |
|---|---|---|---|---|---|---|
| 1 | CVE-2023-29300 | ColdFusion Deserialization of Untrusted Data | 99.99% | Yes | 2024-01-08 | 2024-01-29 |
| 2 | CVE-2018-15961 | ColdFusion Unrestricted File Upload | 99.95% | – | 2021-11-03 | 2022-05-03 |
| 3 | CVE-2023-29298 | ColdFusion Improper Access Control | 99.79% | – | 2023-07-20 | 2023-08-10 |
| 4 | CVE-2010-2861 | ColdFusion Directory Traversal | 99.75% | Yes | 2022-03-25 | 2022-04-15 |
| 5 | CVE-2023-38205 | ColdFusion Improper Access Control | 99.74% | – | 2023-07-20 | 2023-08-10 |
| 6 | CVE-2024-20767 | ColdFusion Improper Access Control | 98.5% | – | 2024-12-16 | 2025-01-06 |
| 7 | CVE-2023-26360 | ColdFusion Deserialization of Untrusted Data | 97.3% | – | 2023-03-15 | 2023-04-05 |
| 8 | CVE-2023-38203 | ColdFusion Deserialization of Untrusted Data | 97.1% | Yes | 2024-01-08 | 2024-01-29 |
| 9 | CVE-2013-0625 | ColdFusion Authentication Bypass | 93.8% | – | 2022-03-07 | 2022-09-07 |
| 10 | CVE-2013-0632 | ColdFusion Authentication Bypass | 93.6% | – | 2022-03-03 | 2022-03-24 |
| 11 | CVE-2017-3066 | ColdFusion Deserialization | 90.6% | – | 2025-02-24 | 2025-03-17 |
| 12 | CVE-2013-0631 | ColdFusion Information Disclosure | 66.4% | – | 2022-03-07 | 2022-09-07 |
| 13 | CVE-2013-0629 | ColdFusion Directory Traversal | 65.8% | – | 2022-03-07 | 2022-09-07 |
| 14 | CVE-2018-4939 | ColdFusion Deserialization of Untrusted Data | 61.7% | – | 2021-11-03 | 2022-05-03 |
| 15 | CVE-2026-48282 | ColdFusion Path Traversal | 42.4% | – | 2026-07-07 | 2026-07-10 |
| 16 | CVE-2023-26359 | ColdFusion Deserialization of Untrusted Data | 17.0% | – | 2023-08-21 | 2023-09-11 |
EPSS changes daily; a CVE with a low EPSS that is in KEV is still exploited somewhere. Federal due dates bind US federal civilian agencies; everyone else can use them as a priority hint.
Sources: CISA KEV, FIRST EPSS.
More: all Adobe KEV CVEs · other Adobe products: Acrobat and Reader · Flash Player · Reader and Acrobat · free KEV badge for Adobe · all vendors