CVE-2025-30281: Adobe ColdFusion
Critical severity, CVSS 9.1. EPSS: 23.6% chance of exploitation in the next 30 days.
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution. A high-privileged attacker could leverage this vulnerability to access or modify sensitive data without proper authorization. Exploitation of this issue does not require user interaction, and scope is changed.
Affected products
- Adobe ColdFusion: version 2021 only; version 2023 only; version 2025 only
Published 2025-04-08. Last modified 2026-06-17.