Latest ColdFusion Security Updates - July 2025

Updated , First Published by Pete Freitag

This page is updated with the latest ColdFusion Security Updates and Hotfixes published by Adobe.

Latest ColdFusion Security Update


July 2025 - ColdFusion 2025 Update 3, ColdFusion 2023 Update 15, ColdFusion 2021 Update 21

Release Date: July 8, 2025

Adobe Product Security Bulletin APSB25-69 fixes several critical vulnerabilities.

Vulnerabilities Fixed

This priority 1 security hotfix resolved 5 critical vulnerabilities, 7 important vulnerabilities, and 1 one moderate vulnerability.

Links & Resources

Notes / Issues


Previous ColdFusion Security Updates

May 2025 - ColdFusion 2025 Update 2, ColdFusion 2023 Update 14, ColdFusion 2021 Update 20

Release Date: May 13, 2025

Adobe Product Security Bulletin APSB25-52 fixes several critical vulnerabilities.

Vulnerabilities Fixed

This priority 1 security hotfix resolved 7 critical vulnerabilities, and 1 important vulnerability.

Links & Resources

Notes / Issues

April 2025 - ColdFusion 2025 Update 1, ColdFusion 2023 Update 13, ColdFusion 2021 Update 19

Release Date: April 8, 2025

Adobe Product Security Bulletin APSB25-15 fixes several critical vulnerabilities.

Vulnerabilities Fixed

This priority 1 security hotfix resolved 11 critical vulnerabilities, and 4 important vulnerabilities.

Links & Resources

Notes / Issues

No updates to the connectors in this release. The administrator, and ajax packages were updated as part of this release.

One notable change in this update is the addition of IP restrictions for the jetty (ColdFusion Add On Services) server which is used for Solr and cfhtmltopdf. Typically you only access this server over localhost, details for configuring the IPs can be found here.

December 2024 - ColdFusion 2023 Update 12, ColdFusion 2021 Update 18

Release Date: December 23, 2024

Adobe Product Security Bulletin APSB24-107 fixes one critical vulnerability.

Vulnerabilities Fixed

Links & Resources

Notes / Issues

No updates to the connectors in this release. The pmtagent package was updated as part of this release.

October 2024 - ColdFusion 2023 Update 11, ColdFusion 2021 Update 17

Release Date: October 15, 2024

This update was not a security hotfix update, although it did update some third party libraries with vulnerabilities (such as netty).

Links & Resources

September 2024 - ColdFusion 2023 Security Update 10, ColdFusion 2021 Security Update 16

Release Date: September 10, 2024

Adobe Product Security Bulletin APSB24-71 fixes one critical vulnerability.

Vulnerabilities Fixed

Links & Resources

Notes / Issues

No updates to connector or packages in this release. Fixed bug CF-4223435 caused by previous update.


August 2024 - ColdFusion 2023 Update 9, ColdFusion 2021 Update 15

Release Date: August 20, 2024

This ColdFusion update primarily updated the version of Tomcat from 9.0.85 to 9.0.93.

Links & Resources

Notes / Issues

No connector or package updates in this release.

Bug CF-4223435 removed packages previously installed during the update process (see link above). Fixed CF2023 update 10, CF2021 Update 16.

The Fixinator Code Security Scanner for ColdFusion & CFML is an easy to use security tool that every CF developer can use. It can also easily integrate into CI for automatic scanning on every commit.