CISA KEV · catalog date Jan 8, 2024 · first observed Jul 19, 2026
Evidence dossier
CVE-2023-29300
Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code execution
Exploited in the wild (CISA KEV since Jan 8, 2024). adobe reports CVSS 3.1 9.8. EPSS estimates 100.0% exploit likelihood as of Aug 7, 2026.
As of Aug 27, 2026
Normalized restatement
Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.
- State
- PUBLISHED
- Published
- Jul 12, 2023
- Updated
- Oct 21, 2025
- Evidence coverage
- 99%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCAadobeOriginal evidence ↗
Record text: Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code execution
Inspect raw assertion
- Field
container- Value
- Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code execution
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 99.99% probability · 99.99th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.999890000000; percentile 0.999850000000
FIRST EPSS · score date Aug 7, 2026 · 100th percentile · first observed Aug 7, 2026
adobe · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code execution
Inspect raw assertion
- Field
container- Value
- Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code execution
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
99.99% probability · 99.99th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.999890000000; percentile 0.999850000000
Applicability
Cited product scope
Grouped from 1 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
2 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "0", "versionType": "semver", "lessThanOrEqual": "2023.0.0.330468"}]product-40c507acd7e9f9a6fe8bc1b45cc600068bd553a29d1397a3d2e038f0deeda04dLinked exactInspect raw assertions
cpe:2.3:a:adobe:coldfusion:2021:update3:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 20
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
75608383-b727-48d6-8ffa-d552a338a562
cpe:2.3:a:adobe:coldfusion:2018:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3b54b2b0-b1e1-4b4e-a529-d0bd3b5deef3
cpe:2.3:a:adobe:coldfusion:2018:update16:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2f549bb3-25ab-4c83-b608-3717eadaab35
cpe:2.3:a:adobe:coldfusion:2018:update12:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3e3bf53e-2c0d-4f79-8b62-4c2a50cb5f52
cpe:2.3:a:adobe:coldfusion:2018:update9:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 16
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1563ce5e-a4f7-40a4-a050-bb96e332d8dd
cpe:2.3:a:adobe:coldfusion:2018:update6:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 13
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9f9336cc-e38f-4bcb-83cd-805ec7fef806
cpe:2.3:a:adobe:coldfusion:2021:update1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 18
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
afd05e3a-10f9-4c75-9710-ba46b66ff6e6
cpe:2.3:a:adobe:coldfusion:2021:update5:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 22
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b38b9e86-bcd5-4bca-8fb7-ec55905184e6
cpe:2.3:a:adobe:coldfusion:2021:update2:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 19
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d57c8681-ac68-47df-a61e-b5c4b4a47663
cpe:2.3:a:adobe:coldfusion:2018:update2:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
59649177-81ee-43c3-bfa5-e56e65b486df
cpe:2.3:a:adobe:coldfusion:2018:update15:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
831e8d69-62e9-4778-8cc5-d6d45cf5ab6f
cpe:2.3:a:adobe:coldfusion:2018:update14:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
25b4b4f2-318f-4046-ade5-e9dd64f83fd9
cpe:2.3:a:adobe:coldfusion:2018:update8:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 15
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
82208628-f32a-4380-9b0f-dc8507e7701d
cpe:2.3:a:adobe:coldfusion:2018:update11:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
23f63675-7817-4af0-a7db-5e35edabf04e
cpe:2.3:a:adobe:coldfusion:2018:update13:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c26bf72c-e991-4170-b68b-09b20b6c0679
cpe:2.3:a:adobe:coldfusion:2018:update1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
edb126bf-e09d-4e58-a39f-1190407d1cab
cpe:2.3:a:adobe:coldfusion:2021:update6:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 23
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5e7bab80-8455-4570-a2a2-8f40469ee9cc
cpe:2.3:a:adobe:coldfusion:2018:update4:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 11
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
58d32489-627b-4e49-9329-8a3b8f8e4903
cpe:2.3:a:adobe:coldfusion:2018:update5:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 12
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6d5860e1-d293-48fe-9796-058b78b2d571
cpe:2.3:a:adobe:coldfusion:2018:update7:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 14
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
97964507-047a-4cc8-8d2b-0ea0c7f9bd50
cpe:2.3:a:adobe:coldfusion:2023:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 24
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b02a37fe-5d31-4892-a3e6-156a8fe62d28
cpe:2.3:a:adobe:coldfusion:2021:update4:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 21
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7773db68-414a-4ba9-960f-52471a784379
cpe:2.3:a:adobe:coldfusion:2018:update10:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8ddd85df-69a0-476f-8365-cd67c75cf0ce
cpe:2.3:a:adobe:coldfusion:2021:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 17
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7a94b406-c011-4673-8c2b-0dd94d46cc4c
cpe:2.3:a:adobe:coldfusion:2018:update3:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
453b96ed-738a-4642-b461-c5216cf45ca3
Affected-product evidence
Accepted scope and product mapping
1 canonical links · 1 source-reported links
vendor-70d8e9d1eb9ce5b2e6b4c9351aebc88bced6ea77611cbc8d5cdbe8115b6faed8 · product-40c507acd7e9f9a6fe8bc1b45cc600068bd553a29d1397a3d2e038f0deeda04d
- Source class
- Nvd cpe vulnerable target
- Assertions
- 25
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
016335fc-087c-4d2e-8a43-6ba1f5df640922ed5329-5228-4d21-ac01-fa6ebf106fe9257cdc50-6ec0-415a-ab6c-924f94ed634d3b7a248d-3051-4434-b38c-2115ae87e9e83f933c9a-fd10-4c38-a426-c7103722dcf0460b7a1c-afe7-4bd1-b5ee-e18ec8924371481856f8-f520-47bf-ae4e-acec51b3417d4cf90cac-f2f0-4be1-b8b5-90261a763f595c5e6693-e4fc-478f-9d79-489151ef855d5e87b063-57c9-459a-8ea0-d6442a9e1e0a64ee8182-9bc1-4c57-bc4a-3f7cd34eaea17c5a8304-257f-4443-958a-2015104bf86c84c4972f-4438-495c-875c-bbe92c026eec8a082af7-5456-4092-abf0-80c3ef08226b8b41dc22-1171-40c9-865c-b5510cc57f419038618e-7a6a-4c60-b4dc-96313d2f656f91bd5457-3028-4002-a7d9-8b321684fe899723e26b-bc4e-4358-8e65-c3983cfad24897371861-920d-40c5-87d4-5adef4c163fcab45135f-26e1-46d8-b785-04c753d7646cc13d9e49-25c6-4324-8131-ef9b7bc100ecca4a0113-3489-4094-8063-a378538486e0e923a220-7917-4a5a-8751-e64445b12b26f5bbdd73-da97-4bf3-9205-1b5a1f9e5978ff65c9df-3a62-46cb-9236-2892b9f76716Canonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
f34a12a9-1d58-4817-b23a-a3aa6b7e4551Assessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDirect CVE/CNA normalized decisions
adobe
CVSS 3.1 · Primary · Original assertion · rank 1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Validation
- Valid match
- Recomputed
- 9.8
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.