# Adobe ColdFusion flaw enables security bypass

Published: 2025-12-10 · Severity: medium
Canonical: https://vorant.io/reports/f91cf79b-9f1a-53c8-8de7-c8e1d3d92b50/adobe-coldfusion-flaw-enables-security-bypass

> IPA Japan warns of an Adobe ColdFusion input validation flaw (CVE-2025-61809) that could let attackers bypass security features.

The Information-technology Promotion Agency (IPA) Japan issued an advisory regarding CVE-2025-61809, an input validation vulnerability in Adobe ColdFusion, an application server product. If exploited, the flaw could allow an attacker to bypass security features implemented within the product.

## Mentioned in this report

- Vulnerabilities: CVE-2025-61809

Source reporting: https://www.ipa.go.jp/security/security-alert/2025/alert20251211.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/f91cf79b-9f1a-53c8-8de7-c8e1d3d92b50/adobe-coldfusion-flaw-enables-security-bypass.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
