- Blogs
- Adobe ColdFusion 2021
- NOW LIVE! ColdFusion 2025, 2023, and 2021 December security updates
We are pleased to inform you that we’ve released security updates for ColdFusion 2025, 2023, and 2021 releases. For more information, see the respective tech notes:
- ColdFusion (2025 release) Update 5
- ColdFusion (2023 release) Update 17
- ColdFusion (2021 release) Update 23
The updates includes important security fixes that mitigate vulnerabilities related to arbitrary file system write, arbitrary file system read, arbitrary code execution, and security feature bypass. The updates also include:
- New JVM flags
- Changes to serialfilter
- CAR migration changes
- Tomcat upgrade
- Bug fixes and known issues
View the tech notes and security bulletin, APSB25-105, for more information.
Download the updates
Docker and CFFiddle
Docker and CFFiddle will be available shortly.
Important
End of core support for ColdFusion 2021 update release
Adobe ColdFusion (2021 release) Update 23 marks the end of core support for ColdFusion 2021 update releases.
Adobe ColdFusion (2021 release) Update 23 is the final update, as this version reached its end of core support on November 10, 2025. After this update, no further core updates will be provided for this version.
Note: Extended support options may still be available after core support ends. Please review Adobe’s End-of-Life (EOL) matrix for details on timelines and support plans. See the Adobe support matrix for more information.
We are pleased to inform you that we’ve released security updates for ColdFusion 2025, 2023, and 2021 releases. For more information, see the respective tech notes:
- ColdFusion (2025 release) Update 5
- ColdFusion (2023 release) Update 17
- ColdFusion (2021 release) Update 23
The updates includes important security fixes that mitigate vulnerabilities related to arbitrary file system write, arbitrary file system read, arbitrary code execution, and security feature bypass. The updates also include:
- New JVM flags
- Changes to serialfilter
- CAR migration changes
- Tomcat upgrade
- Bug fixes and known issues
View the tech notes and security bulletin, APSB25-105, for more information.
Download the updates
Docker and CFFiddle
Docker and CFFiddle will be available shortly.
Important
End of core support for ColdFusion 2021 update release
Adobe ColdFusion (2021 release) Update 23 marks the end of core support for ColdFusion 2021 update releases.
Adobe ColdFusion (2021 release) Update 23 is the final update, as this version reached its end of core support on November 10, 2025. After this update, no further core updates will be provided for this version.
Note: Extended support options may still be available after core support ends. Please review Adobe’s End-of-Life (EOL) matrix for details on timelines and support plans. See the Adobe support matrix for more information.
- Most Recent
- Most Relevant
Thanks Priyank. And readers may be interested to hear that I did a post with more about the update (as I try to do for each update, pointing to this one and other resources as well as offering lots more info to help folks applying the update).
Additionally, if anyone seeing this applied the update and then found that the CF Admin stopped working, I’ll note that it’s a problem that some folks (myself included) experienced with CF2023 when doing the update yesterday. Technically, it’s a problem that can happen with the other versions and other CF updates, where the issue is that administrator package and indeed all updated packages are unexpectedly uninstalled during the first startup but then not updated/reinstalled.
Some good news first is that there’s a solution for the problem if it happened/happens to you. Then second the problem didn’t happen in an update I did to CF2023 later/that night. So I attribute the problem to being some sort of caching issue (somewhere between my CF instance and the Adobe server sending the bundledependency.json file, which I found was lacking the updated package info).
Again, this problem has happened to others with previous CF updates, and it could happen in the future, perhaps especially to those who try to implement the update on the first day of its release. (It doesn’t ALWAYS happen–and indeed it did not happen when I updated cf2025 before that, and cf2021.)
Anyway, if you’re interested in hearing more about the issue (including how to diagnose and resolve it), see my post on that, which followed the one above. And try to keep it in mind if you apply a future update on the first day or two, and find that updated packages are unexpectedly uninstalled after doing the update. (This is not to discourage you doing the update the first day–just info to be aware of, and an explanation of what may happen and how to recover.)





