VORANT. Threat Intelligence Sign in Get the full feed

Adobe ColdFusion input validation flaw bypasses security

high vulnerability

Adobe ColdFusion contains an input validation vulnerability (CVE-2025-61809) that allows attackers to bypass security features; patches are available.

Japan's Information-technology Promotion Agency (IPA) has issued an advisory for a newly disclosed input validation vulnerability in Adobe ColdFusion application server. The flaw, tracked as CVE-2025-61809, enables attackers to bypass security mechanisms when successfully exploited.

Adobe has released patched versions to address the vulnerability. The IPA warns that exploitation could expand and urges administrators to apply the vendor-provided security updates immediately following Adobe's published remediation procedures.

Organizations running Adobe ColdFusion should prioritize patching to prevent potential security bypasses that could undermine application-level controls.

Mentioned in this report

Vulnerabilities CVE-2025-61809

Source reporting: https://www.ipa.go.jp/security/security-alert/2025/alert20251211.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free