We are pleased to inform you that we’ve released security updates for ColdFusion 2025, 2023, and 2021 releases. For more information, see the respective tech notes:

These updates resolve several critical and important vulnerabilities that could lead to arbitrary file system read, arbitrary code execution, and security feature bypass. View the security bulletin, APSB25-15, for more information.

Download the updates

What’s new in the updates

  • New JVM flags
  • Refreshed add-on installers
  • IP filtering for cfhtmltopdf
  • Central Configuration Server changes
  • cfencode removal for the 2023 and 2021 updates

Others

  • Bug fixes
  • Known issues

Docker and cffiddle

  • Will be updated shortly. We’ll update the post.

Please download and apply the updates and provide your feedback.

All Comments
Sort by:  Most Recent