Adobe has issued important security updates addressing 30 vulnerabilities across multiple products, with particular focus on ColdFusion versions 2025, 2023, and 2021. Among these flaws, 11 are classified as Critical severity that could allow attackers to read arbitrary files or execute malicious code.
## Critical ColdFusion Vulnerabilities
The most severe vulnerabilities include:
– **CVE-2025-24446** (CVSS 9.1): Improper input validation allowing arbitrary file system read
– **CVE-2025-24447** (CVSS 9.1): Deserialization of untrusted data enabling arbitrary code execution
– **CVE-2025-30281** (CVSS 9.1): Improper access control leading to arbitrary file system read
– **CVE-2025-30282** (CVSS 9.1): Improper authentication vulnerability permitting arbitrary code execution
Additional critical flaws involve deserialization issues, command injection, authentication bypasses, and path traversal vulnerabilities with CVSS scores ranging from 7.5 to 8.7.
## Patched Versions
Adobe has resolved these vulnerabilities in:
– ColdFusion 2021 Update 19
– ColdFusion 2023 Update 13
– ColdFusion 2025 Update 1
## Other Adobe Products Affected
Security updates have also been released for several Creative Cloud applications to address out-of-bounds write and heap-based buffer overflow vulnerabilities that could lead to code execution:
– After Effects
– Media Encoder
– Bridge
– Premiere Pro
– Photoshop
– Animate
– FrameMaker
While Adobe reports no known exploits for these vulnerabilities in the wild, users are strongly encouraged to update their software immediately to protect against potential threats.
