CISA KEV · catalog date Feb 24, 2025 · first observed Jul 19, 2026
Evidence dossier
CVE-2017-3066
Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization vulnerability in the Apache…
Exploited in the wild (CISA KEV since Feb 24, 2025). NVD reports CVSS 3.1 9.8. EPSS estimates 90.6% exploit likelihood as of Aug 26, 2026.
As of Aug 27, 2026
Normalized restatement
Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization vulnerability in the Apache BlazeDS library. Successful exploitation could lead to arbitrary code execution.
- State
- PUBLISHED
- Published
- Apr 27, 2017
- Updated
- Oct 21, 2025
- Evidence coverage
- 99%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCAadobeOriginal evidence ↗
Record text: Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization vulnerability in the Apache BlazeDS library. Successful exploitation could lead to arbitrary code execution.
Inspect raw assertion
- Field
container- Value
- Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization vulnerability in the Apache BlazeDS library. Successful exploitation could lead to arbitrary code execution.
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Adobe ColdFusion Deserialization Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Adobe ColdFusion Deserialization Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 90.6% probability · 99.79th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.905970000000; percentile 0.997930000000
FIRST EPSS · score date Aug 26, 2026 · 99.8th percentile · first observed Aug 26, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
Outside this view’s verified evidenceReason detail begins outside this selected snapshot; the state remains source-bound.
Source comparison
Who said what
Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization vulnerability in the Apache BlazeDS library. Successful exploitation could lead to arbitrary code execution.
Inspect raw assertion
- Field
container- Value
- Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization vulnerability in the Apache BlazeDS library. Successful exploitation could lead to arbitrary code execution.
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
Adobe ColdFusion Deserialization Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Adobe ColdFusion Deserialization Vulnerability
90.6% probability · 99.79th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.905970000000; percentile 0.997930000000
Applicability
Cited product scope
Grouped from 1 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
2 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "Adobe ColdFusion ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier"}]product-40c507acd7e9f9a6fe8bc1b45cc600068bd553a29d1397a3d2e038f0deeda04dLinked exactInspect raw assertions
cpe:2.3:a:adobe:coldfusion:10.0:update11:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
fdac841b-3fe8-46f6-84b4-650d939225f5
cpe:2.3:a:adobe:coldfusion:11.0:update5:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 30
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
96c50cd1-ce75-4d70-ad65-2db6027d806a
cpe:2.3:a:adobe:coldfusion:10.0:update9:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 22
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
61bc9d5b-1208-4613-bd23-fea9c404a503
cpe:2.3:a:adobe:coldfusion:2016:update3:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 38
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e6ec92f3-1ef8-4820-9cd8-ecea03d27a7b
cpe:2.3:a:adobe:coldfusion:10.0:update12:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ac034beb-0adb-4340-8afb-30ef67e72815
cpe:2.3:a:adobe:coldfusion:10.0:update16:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0bb6df8f-4ca1-448e-8e48-7c2165ec3ae3
cpe:2.3:a:adobe:coldfusion:11.0:update8:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 33
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
31f22450-f26c-4797-9292-66ca444c0d2c
cpe:2.3:a:adobe:coldfusion:10.0:update14:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f56cfa71-3d5e-4a0b-ba4c-9756d0727f8e
cpe:2.3:a:adobe:coldfusion:10.0:update19:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 11
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9b048a36-1e2f-4d0c-af07-b3d255f170ce
cpe:2.3:a:adobe:coldfusion:10.0:update13:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c8f1abab-c4ff-45fd-8c64-23e79f40c043
cpe:2.3:a:adobe:coldfusion:11.0:update7:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 32
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
827cb550-5078-4fd5-8b1f-616c06912ad9
cpe:2.3:a:adobe:coldfusion:2016:update1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 36
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9f3d7c8e-6695-44df-ac9a-1ae09c46c529
cpe:2.3:a:adobe:coldfusion:10.0:update1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1c4d259e-56b1-4d53-80a9-52d0687779c4
cpe:2.3:a:adobe:coldfusion:11.0:update11:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 26
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
afe18fea-271a-42fe-8c24-19731deb5444
cpe:2.3:a:adobe:coldfusion:11.0:update6:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 31
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ae1b1190-4699-4fb0-ad46-df0233b5ba90
cpe:2.3:a:adobe:coldfusion:2016:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 35
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b262f442-ff7f-4cc0-a9c5-ffd0edb08e38
cpe:2.3:a:adobe:coldfusion:2016:update2:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 37
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
12bae66c-a745-4661-b5bb-7fc2c169cc82
cpe:2.3:a:adobe:coldfusion:10.0:update5:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 18
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
705e7f38-9407-4148-835e-5ab994c05f30
cpe:2.3:a:adobe:coldfusion:10.0:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
bb4e08f7-c133-4083-906a-335b9880ba04
cpe:2.3:a:adobe:coldfusion:10.0:update21:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 14
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2bd246be-c263-46c5-bf2c-e7c4b5c7dd95
cpe:2.3:a:adobe:coldfusion:10.0:update22:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 15
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
75f104af-2a38-447b-ab59-09b8f769e787
cpe:2.3:a:adobe:coldfusion:11.0:update1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 24
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7d4bd25e-6856-40ec-98a8-acb540992487
cpe:2.3:a:adobe:coldfusion:10.0:update7:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 20
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
71302041-9bb6-406e-9e77-99ad1594c5c2
cpe:2.3:a:adobe:coldfusion:10.0:update6:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 19
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
dd7a193c-6ce4-4b80-9897-934bc915627f
cpe:2.3:a:adobe:coldfusion:10.0:update17:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
304f3518-82f3-4566-a44d-3fa8d1feebca
cpe:2.3:a:adobe:coldfusion:10.0:update15:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4db7821d-f4a7-4772-a25b-d925c90478ce
cpe:2.3:a:adobe:coldfusion:11.0:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 23
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e217ce63-07dc-4a88-8877-181f33a21c20
cpe:2.3:a:adobe:coldfusion:10.0:update8:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 21
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
34472770-ffce-4088-8658-fa0a552beaa6
cpe:2.3:a:adobe:coldfusion:10.0:update20:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 13
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
79885d33-9360-41d5-9b37-4dc45bdd2439
cpe:2.3:a:adobe:coldfusion:10.0:update2:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 12
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
09f8f645-dd28-4159-877e-40b4c8cda4cc
cpe:2.3:a:adobe:coldfusion:11.0:update3:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 28
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
57bbbe71-bbe0-4129-b997-3f9af54bfbd8
cpe:2.3:a:adobe:coldfusion:11.0:update10:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 25
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2f0907e8-7bc4-4f5a-894c-b7c5f6baaeae
cpe:2.3:a:adobe:coldfusion:10.0:update4:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 17
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f54ff25a-ef5b-4de0-802c-c9b00a963c21
cpe:2.3:a:adobe:coldfusion:11.0:update9:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 34
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
72450205-b4f4-4b44-9991-f4876d829bbd
cpe:2.3:a:adobe:coldfusion:11.0:update2:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 27
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
82f81cf8-1482-4731-ad34-677b8d6b930b
cpe:2.3:a:adobe:coldfusion:10.0:update10:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
191e8cc6-8ad5-40de-8b5d-1a8bcaee855d
cpe:2.3:a:adobe:coldfusion:10.0:update3:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 16
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1b83d6cf-4c45-4b7a-9afc-9961e1fe0686
cpe:2.3:a:adobe:coldfusion:10.0:update18:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b6f8c00c-60ca-4a53-92df-fb2bf09cf9e3
cpe:2.3:a:adobe:coldfusion:11.0:update4:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 29
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8e514d95-9287-4a43-9a44-bd6f8edc5da8
Affected-product evidence
Accepted scope and product mapping
0 canonical links · 0 source-reported links
Applicability remains source-scoped; safety and exposure remain unassessed.
Assessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAV:N/AC:L/Au:N/C:C/I:C/A:CCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HEvidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Affected-product evidence remains source-scoped; canonical linkage is required before applicability scoring.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.