NOW LIVE — the April 2026 security updates for ColdFusion 2025 and ColdFusion 2023 have been released. This update addresses multiple security issues and includes important mitigations we recommend you apply as soon as possible.

What’s included

The April 2026 release contains:

  • Tomcat upgrades. See the respective tech notes for more details.
  • Security fixes for multiple vulnerabilities (including remote code execution and privilege escalation vectors).
  • Patches to harden request handling, deserialization paths, and template parsing logic.
  • Updates to packages.

Why you should install this update

These fixes close high‑ and critical‑severity vulnerabilities that could be used by attackers to execute code, elevate privileges, or access sensitive data. Applying the update reduces risk to your production and development environments.

Download the updates

See the tech notes

Feedback and support

As always, if you encounter issues after updating or need assistance planning your rollout, contact support or reply to this post with details. Your feedback helps us prioritize follow‑up fixes and clarifications.

All Comments
Sort by:  Most Recent