
Announcing ColdFusion updates released Sep 10 2024: P3 security update
Though the news is a couple of days old, I want to share with my readers that an update for ColdFusion has been released Tuesday, Sep 10, for both cf2023 (update 10) and cf2021 (update 16).

Announcing ColdFusion updates released Sep 10 2024: P3 security update
Though the news is a couple of days old, I want to share with my readers that an update for ColdFusion has been released Tuesday, Sep 10, for both cf2023 (update 10) and cf2021 (update 16).

Announcing ColdFusion updates released Sep 10 2024: P3 security update
Though the news is a couple of days old, I want to share with my readers that an update for ColdFusion has been released Tuesday, Sep 10, for both cf2023 (update 10) and cf2021 (update 16).

Announcing ColdFusion updates released Sep 10 2024: P3 security update
Though the news is a couple of days old, I want to share with my readers that an update for ColdFusion has been released Tuesday, Sep 10, for both cf2023 (update 10) and cf2021 (update 16).

Latest ColdFusion Security Updates - October 2024
I am going to attempt to keep this page updated with the latest ColdFusion Security Updates and Hotfixes published by Adobe.
From: Pete Freitag's Homepage

Latest ColdFusion Security Updates - April 2025
Links & Resources APSB25-15 - Adobe Product Security Bulletin CF2025 Update 11 - Adobe KB article for ColdFusion 2025 Update 1 CF2023 Update 13 - Adobe KB article for ColdFusion 2023 Update 13 CF2021 Update 19 - Adobe KB article for ColdFusion 2021 Update 19 Forum Thread - Adobe ColdFusi...
From: Pete Freitag's Homepage

Latest ColdFusion Security Updates - May 2025
Links & Resources APSB25-15 - Adobe Product Security Bulletin CF2025 Update 2 - Adobe KB article for ColdFusion 2025 Update 2 CF2023 Update 14 - Adobe KB article for ColdFusion 2023 Update 14 CF2021 Update 20 - Adobe KB article for ColdFusion 2021 Update 20 Forum Thread - Adobe ColdFusio...
From: Pete Freitag's Homepage

Follow-up on CF 2021 update 15: understanding, solving packages unexpectedly removed
If you've recently applied CF2021 update 15 or are planning to, you need to be aware of a known issue which can cause unexpected removal of some CF packages (modules) which occurs upon the CF restart after installing the update: specifically it's the document, htmltopdf, pdf, presentation, print, an...

Follow-up on CF 2021 update 15: understanding, solving packages unexpectedly removed
If you've recently applied CF2021 update 15 or are planning to, you need to be aware of a known issue which can cause unexpected removal of some CF packages (modules) which occurs upon the CF restart after installing the update: specifically it's the document, htmltopdf, pdf, presentation, print, an...

Follow-up on CF 2021 update 15: understanding, solving packages unexpectedly removed
If you've recently applied CF2021 update 15 or are planning to, you need to be aware of a known issue which can cause unexpected removal of some CF packages (modules) which occurs upon the CF restart after installing the update: specifically it's the document, htmltopdf, pdf, presentation, print, an...

Announcing ColdFusion updates released Aug 20 2024: offers Tomcat upgrade
An update for ColdFusion has been released today for both cf2023 as update 9 and and cf2021 as update 15.

Announcing ColdFusion updates released Aug 20 2024: offers Tomcat upgrade
An update for ColdFusion has been released today for both cf2023 as update 9 and and cf2021 as update 15.

Announcing ColdFusion updates released Aug 20 2024: offers Tomcat upgrade
An update for ColdFusion has been released today for both cf2023 as update 9 and and cf2021 as update 15.
BSidesLV 2024 Slides - Modern ColdFusion Exploitation and Attack Surface Reduction
Thank you to BSidesLV for the opportunity to speak this year. The slides from my talk, Modern ColdFusion Exploitation and Attack Surface Reduction, are now online below. They're pretty similar to my Summercon slides, with a few updates.
BSidesLV 2024 Slides - Modern ColdFusion Exploitation and Attack Surface Reduction
Thank you to BSidesLV for the opportunity to speak this year. The slides from my talk, Modern ColdFusion Exploitation and Attack Surface Reduction, are now online below. They're pretty similar to my Summercon slides, with a few updates.
BSidesLV 2024 Slides - Modern ColdFusion Exploitation and Attack Surface Reduction
Thank you to BSidesLV for the opportunity to speak this year. The slides from my talk, Modern ColdFusion Exploitation and Attack Surface Reduction, are now online below. They're pretty similar to my Summercon slides, with a few updates.
On ColdFusion Administrator Access Control Bypass Techniques
IntroductionAccess Control is frequently boring but important.
On ColdFusion Administrator Access Control Bypass Techniques
IntroductionAccess Control is frequently boring but important.
On ColdFusion Administrator Access Control Bypass Techniques
IntroductionAccess Control is frequently boring but important.

Follow-up on June 2024 CF update: more on change of default algorithm from CFMX_COMPAT
If you're considering or have already implemented the latest CF updates from June 2024 (CF2023 update 8 and CF2021 update 14), you might have struggled a bit to understand completely what Adobe was getting at in the update technotes, as they can sometimes be rather terse in covering some points (wor...

Follow-up on June 2024 CF update: more on change of default algorithm from CFMX_COMPAT
If you're considering or have already implemented the latest CF updates from June 2024 (CF2023 update 8 and CF2021 update 14), you might have struggled a bit to understand completely what Adobe was getting at in the update technotes, as they can sometimes be rather terse in covering some points (wor...

Follow-up on June 2024 CF update: more on change of default algorithm from CFMX_COMPAT
If you're considering or have already implemented the latest CF updates from June 2024 (CF2023 update 8 and CF2021 update 14), you might have struggled a bit to understand completely what Adobe was getting at in the update technotes, as they can sometimes be rather terse in covering some points (wor...
Summercon 2024 Slides - Modern ColdFusion Exploitation and Attack Surface Reduction
Last Friday it was an absolute honor to talk about ColdFusion security at Summercon.