Yes. Adobe confirmed on March 14, 2023, that attackers had exploited CVE-2023-26360 against ColdFusion servers in what it described as “very limited attacks.” Later security reporting documented additional exploitation, but no reliable public count of compromised servers was established.
What happened—and what “very limited” means
Adobe’s security bulletin APSB23-25, published March 14, 2023, and updated March 28, said CVE-2023-26360 had been exploited in the wild. Adobe did not disclose how many systems were affected or provide additional details about the compromises. SecurityWeek’s March 14 report likewise noted the lack of further compromise details.
The “very limited” wording describes Adobe’s initial disclosure, not proof that exploitation stayed rare. FortiGuard recorded CISA’s addition of CVE-2023-26360 to its Known Exploited Vulnerabilities catalog on March 15, 2023, and reported continued targeted attacks. Rapid7 later observed multiple exploitation instances and said that activity may indicate exploitation was broader than Adobe’s initial description. These reports establish exploitation, but not a verified total of compromised servers or an attacker identity.
Which ColdFusion versions were affected?
| ColdFusion release | Affected level listed by Adobe | Adobe update for the 2023 bulletin |
|---|---|---|
| ColdFusion 2018 | Update 15 and earlier | Update 16 |
| ColdFusion 2021 | Update 5 and earlier | Update 6 |
| ColdFusion 2016 and 11 | Reported as affected | Out of support; no current security updates |
The update numbers above are the fixes identified in APSB23-25 in 2023. They do not establish whether a release line remains supported or whether these updates meet current security requirements in 2026; check Adobe’s current support and security information before planning a deployment.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problems#1 Best Overall
What vulnerabilities did APSB23-25 fix?
CVE-2023-26360 was one of three vulnerabilities addressed in the bulletin. Adobe assigned it a CVSS score of 8.6. CISA reporting described it as remotely exploitable without authentication, with low attack complexity and no user interaction required.
| CVE | Issue and reported impact | Adobe CVSS score |
|---|---|---|
| CVE-2023-26359 | Deserialization of untrusted data; arbitrary code execution | 9.8 |
| CVE-2023-26360 | Improper access control; arbitrary code execution | 8.6 |
| CVE-2023-26361 | Path traversal; memory leak | 4.9 |
FortiGuard recorded CVE-2023-26359’s addition to CISA’s KEV catalog on August 21, 2023. The 9.8 score belongs to that separate deserialization flaw, not to CVE-2023-26360.
Quick Recap
What administrators should do
- Identify the deployed ColdFusion release and update level. Check every production and internet-facing instance, including systems that may be managed by a hosting provider or another team.
- Install the applicable ColdFusion security update. For the release levels covered by APSB23-25, Adobe specified ColdFusion 2018 Update 16 or ColdFusion 2021 Update 6, as applicable. Use Adobe’s current guidance to determine the supported update path for your installed release.
- Update the corresponding JDK or JRE. Adobe warned that applying the ColdFusion update without its corresponding JDK/JRE update would not secure the server. Confirm that the Java runtime paired with the installation is updated as Adobe specifies; the bulletin’s update levels alone do not identify a universal Java version for every deployment.
- Apply ColdFusion security configuration and lockdown guidance. Patching is not a substitute for Adobe’s security configuration settings and the lockdown guide applicable to the installed release.
- Review exposed systems for signs of compromise. Prioritize internet-facing servers and investigate suspicious access or changes using your organization’s incident-response procedures. Treat an updated server and an investigated server as separate outcomes: patching closes the vulnerability but does not establish whether it was exploited before remediation.
- Plan a supported-release migration if necessary. ColdFusion 2016 and 11 were reported as affected but are out of support and do not receive current security updates; an old installation cannot be brought up to date with the 2018 or 2021 update numbers.
Sources
- Adobe Security Bulletin APSB23-25, published March 14, 2023, updated March 28, 2023.
- SecurityWeek, reporting on Adobe’s disclosure, March 14, 2023.
- FortiGuard, reporting on CISA KEV additions and targeted activity, including the March 15, 2023 entry for CVE-2023-26360 and August 21, 2023 entry for CVE-2023-26359.
- Rapid7, reporting multiple observed instances of CVE-2023-26360 exploitation.
- CISA vulnerability reporting for the remote-exploitation characteristics of CVE-2023-26360.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

