Attackers exploited Adobe ColdFusion vulnerabilities that can allow arbitrary code execution without user interaction. Adobe confirmed limited exploitation of CVE-2023-26360 in March 2023, and FortiGuard Labs subsequently reported blocking several hundred attempts targeting the flaw. FortiGuard identified both CVE-2023-26360 and CVE-2023-26359 as deserialization vulnerabilities and reported that CISA added both to its Known Exploited Vulnerabilities catalog. A separate SecureLayer7 analysis reported CVE-2023-26360 exploitation against U.S. Federal Civilian Executive Branch agencies and, citing Threatrecon, attributed exploitation to the Chinese government-sponsored group SectorB01.
CVE-2023-26360 affects ColdFusion 2018 and 2021, enabling unauthenticated attackers to read arbitrary files and execute code. SecureLayer7 traced the issue to unsafe handling of attacker-controlled JSON metadata, allowing arbitrary file paths to reach ColdFusion’s template-loading and compilation mechanisms. Its demonstrated execution chain placed a ColdFusion execution tag in a log file, then caused the server to process that file. Patch analysis identified a new allowNonCFCDeserialization control intended to restrict the unsafe behavior. Organizations should prioritize Adobe’s security updates and investigate signs of compromise on exposed servers; FortiGuard reported that IPS protection for CVE-2023-26359 remained under investigation at the time of its alert.

See which actors are running it and whether you're in range.
10 events from the most recent confirmed update back to the earliest known activity.
CISA added the ColdFusion deserialization vulnerability CVE-2023-26359 to its Known Exploited Vulnerabilities catalog.
FortiGuard added an intrusion prevention signature to detect exploitation attempts targeting CVE-2023-26360.
CISA added the exploited ColdFusion vulnerability CVE-2023-26360 to its Known Exploited Vulnerabilities catalog.
FortiGuard Labs published a Threat Signal report concerning the ColdFusion vulnerability CVE-2023-26360.
Adobe released security advisory APSB23-25 and confirmed that CVE-2023-26360 had been exploited in very limited attacks against ColdFusion. The reported vulnerabilities could allow arbitrary code execution without user interaction.
Adobe published March 2023 security updates for ColdFusion 2018 and 2021 addressing the reported vulnerabilities.
A researcher reproduced arbitrary file reads and remote code execution by manipulating JSON metadata and causing ColdFusion to compile attacker-influenced log content. Patch analysis identified a new allowNonCFCDeserialization control intended to restrict the vulnerable behavior.
SecureLayer7 cited Threatrecon as attributing exploitation to SectorB01, described as a Chinese government-sponsored advanced persistent threat group.
SecureLayer7 reported that threat actors exploited CVE-2023-26360 to gain initial access to U.S. Federal Civilian Executive Branch agencies, citing CISA advisory AA23-339A.
FortiGuard Labs reported continued targeted attacks against CVE-2023-26360, with its IPS devices blocking several hundred exploitation attempts during the month preceding its report.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.