
Adobe Releases Security Updates to Fix Critical Vulnerabilities in ColdFusion
CybersecurityVulnerabilitiesSoftwareUpdatesExploits
Adobe has published security updates to address a set of security flaws, including several critical vulnerabilities in the 2025, 2023, and 2021 versions of ColdFusion. Out of the 30 identified flaws, 11 are classified as critical. One of these vulnerabilities, CVE-2025-24446 (CVSS score: 9.1), is an incorrect input validation flaw that could lead to arbitrary file reading and code execution. The critical vulnerabilities could allow arbitrary code execution and arbitrary file reading.