CISA KEV · catalog date Aug 21, 2023 · first observed Jul 19, 2026
Evidence dossier
CVE-2023-26359
Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code execution
Exploited in the wild (CISA KEV since Aug 21, 2023). adobe reports CVSS 3.1 9.8. EPSS estimates 17.0% exploit likelihood as of Aug 27, 2026.
As of Aug 27, 2026
Normalized restatement
Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.
- State
- PUBLISHED
- Published
- Mar 23, 2023
- Updated
- Oct 21, 2025
- Evidence coverage
- 99%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCAadobeOriginal evidence ↗
Record text: Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code execution
Inspect raw assertion
- Field
container- Value
- Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code execution
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 16.99% probability · 96.84th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.169880000000; percentile 0.968350000000
FIRST EPSS · score date Aug 27, 2026 · 96.8th percentile · first observed Aug 27, 2026
adobe · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code execution
Inspect raw assertion
- Field
container- Value
- Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code execution
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
16.99% probability · 96.84th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.169880000000; percentile 0.968350000000
Applicability
Cited product scope
Grouped from 1 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
2 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "unspecified", "versionType": "custom", "lessThanOrEqual": "CF2018U15, CF2021U5"}, {"status": "affected", "version": "unspecified", "versionType": "custom", "lessThanOrEqual": "None"}]product-40c507acd7e9f9a6fe8bc1b45cc600068bd553a29d1397a3d2e038f0deeda04dLinked exactInspect raw assertions
cpe:2.3:a:adobe:coldfusion:2021:update2:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 18
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d57c8681-ac68-47df-a61e-b5c4b4a47663
cpe:2.3:a:adobe:coldfusion:2018:update4:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
58d32489-627b-4e49-9329-8a3b8f8e4903
cpe:2.3:a:adobe:coldfusion:2018:update6:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 12
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9f9336cc-e38f-4bcb-83cd-805ec7fef806
cpe:2.3:a:adobe:coldfusion:2018:update7:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 13
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
97964507-047a-4cc8-8d2b-0ea0c7f9bd50
cpe:2.3:a:adobe:coldfusion:2018:update2:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
59649177-81ee-43c3-bfa5-e56e65b486df
cpe:2.3:a:adobe:coldfusion:2021:update4:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 20
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7773db68-414a-4ba9-960f-52471a784379
cpe:2.3:a:adobe:coldfusion:2021:update1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 17
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
afd05e3a-10f9-4c75-9710-ba46b66ff6e6
cpe:2.3:a:adobe:coldfusion:2018:update12:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3e3bf53e-2c0d-4f79-8b62-4c2a50cb5f52
cpe:2.3:a:adobe:coldfusion:2021:update5:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 21
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b38b9e86-bcd5-4bca-8fb7-ec55905184e6
cpe:2.3:a:adobe:coldfusion:2018:update10:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8ddd85df-69a0-476f-8365-cd67c75cf0ce
cpe:2.3:a:adobe:coldfusion:2018:update13:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c26bf72c-e991-4170-b68b-09b20b6c0679
cpe:2.3:a:adobe:coldfusion:2018:update8:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 14
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
82208628-f32a-4380-9b0f-dc8507e7701d
cpe:2.3:a:adobe:coldfusion:2018:update15:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
831e8d69-62e9-4778-8cc5-d6d45cf5ab6f
cpe:2.3:a:adobe:coldfusion:2021:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 16
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7a94b406-c011-4673-8c2b-0dd94d46cc4c
cpe:2.3:a:adobe:coldfusion:2018:update3:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
453b96ed-738a-4642-b461-c5216cf45ca3
cpe:2.3:a:adobe:coldfusion:2021:update3:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 19
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
75608383-b727-48d6-8ffa-d552a338a562
cpe:2.3:a:adobe:coldfusion:2018:update9:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 15
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1563ce5e-a4f7-40a4-a050-bb96e332d8dd
cpe:2.3:a:adobe:coldfusion:2018:update11:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
23f63675-7817-4af0-a7db-5e35edabf04e
cpe:2.3:a:adobe:coldfusion:2018:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3b54b2b0-b1e1-4b4e-a529-d0bd3b5deef3
cpe:2.3:a:adobe:coldfusion:2018:update5:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 11
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6d5860e1-d293-48fe-9796-058b78b2d571
cpe:2.3:a:adobe:coldfusion:2018:update1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
edb126bf-e09d-4e58-a39f-1190407d1cab
cpe:2.3:a:adobe:coldfusion:2018:update14:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
25b4b4f2-318f-4046-ade5-e9dd64f83fd9
Affected-product evidence
Accepted scope and product mapping
1 canonical links · 1 source-reported links
vendor-70d8e9d1eb9ce5b2e6b4c9351aebc88bced6ea77611cbc8d5cdbe8115b6faed8 · product-40c507acd7e9f9a6fe8bc1b45cc600068bd553a29d1397a3d2e038f0deeda04d
- Source class
- Nvd cpe vulnerable target
- Assertions
- 22
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0c08730a-025b-4b40-b3b2-db28a94b56cc29e5327b-6624-4bfd-b9ac-54ac5f4bbabc56895ef2-3d5c-4363-9923-a749b2ff7c0858f29241-6e13-43c6-bc6a-d37229b370305c05cca9-a8c2-46f6-b009-2e4e62ec6de99ce88d8d-9d66-427a-a2e5-c2ec71b0fe2c9d6a76ad-1ff9-4e87-abe6-d5cc9e3324369d6cb5e1-45a7-4c13-a7c3-30f5bebf5b86a7cd4ba0-89f3-44f0-8e5a-04d64c5121b1a9b511aa-7b35-4d11-8af3-7b4d12cc06b7b51483d1-995a-4548-a763-642827007c0db77dc24e-88d0-41f1-91dc-3a6d45f146c2c10bd8eb-2b4c-4eb7-9b02-b8106bdd39abc3f8cff3-8b0b-4fa0-a3c4-e2462e517719c6325265-eeb5-45c6-9b41-dbb594b85bb1d2684bf6-aeb1-4f4a-acc4-ad62416f026dd68b4e8b-e04d-4ff4-a195-6ca02bd4e353da130bb0-c1cb-44ee-bd1a-d83a84b84a6ce18557a1-c98c-4ecc-8750-da85a73aaa92e6d32d6e-616e-4135-855f-a49b32dfab42ef6f2547-bc91-47d1-a00f-4658f036b57af77d47ca-514c-4467-a639-a4b33c0faf0fCanonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
c8f92efa-8497-4692-9710-145dc7b72e15Assessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDirect CVE/CNA normalized decisions
adobe
CVSS 3.1 · Primary · Original assertion · rank 1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Validation
- Valid match
- Recomputed
- 9.8
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.