criticalKEV
CVE-2023-26360
ColdFusion improper access control / deserialization - unauthenticated arbitrary file read and RCE
- Severity
- critical
- Affected product
- Adobe ColdFusion
- Affected versions
- Adobe ColdFusion all versions before the fix
- Detection basis
- Appliance fingerprint
- Shipped rule
- Adobe ColdFusion: ColdFusion improper access control / deserialization - unauthenticated arbitrary file read and RCE
- CISA KEV
- Listed as a known exploited vulnerability
- Added to NewScan
- 2026-08-02
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
APPLIANCE FINGERPRINT
NewScan fingerprints the Adobe ColdFusion appliance and reports this CVE when the detected version falls inside the affected range below.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →Review the measured benchmark, then use the verified remediation process.