Adobe ColdFusion flaw enables security bypass
IPA Japan warns of an Adobe ColdFusion input validation flaw (CVE-2025-61809) that could let attackers bypass security features.
The Information-technology Promotion Agency (IPA) Japan issued an advisory regarding CVE-2025-61809, an input validation vulnerability in Adobe ColdFusion, an application server product. If exploited, the flaw could allow an attacker to bypass security features implemented within the product.
Mentioned in this report
Vulnerabilities
CVE-2025-61809
Source reporting: https://www.ipa.go.jp/security/security-alert/2025/alert20251211.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free