CISA KEV · catalog date Jan 8, 2024 · first observed Jul 19, 2026
Evidence dossier
CVE-2023-38203
Analysis CVE-2023-29300 Bypass: Adobe ColdFusion Pre-Auth RCE
Exploited in the wild (CISA KEV since Jan 8, 2024). adobe reports CVSS 3.1 9.8. EPSS estimates 96.5% exploit likelihood as of Aug 8, 2026.
As of Aug 27, 2026
Normalized restatement
Adobe ColdFusion versions 2018u17 (and earlier), 2021u7 (and earlier) and 2023u1 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.
- State
- PUBLISHED
- Published
- Jul 20, 2023
- Updated
- Oct 21, 2025
- Evidence coverage
- 99%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCAadobeOriginal evidence ↗
Record text: Analysis CVE-2023-29300 Bypass: Adobe ColdFusion Pre-Auth RCE
Inspect raw assertion
- Field
container- Value
- Analysis CVE-2023-29300 Bypass: Adobe ColdFusion Pre-Auth RCE
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 96.53% probability · 99.88th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.965340000000; percentile 0.998770000000
FIRST EPSS · score date Aug 8, 2026 · 99.9th percentile · first observed Aug 8, 2026
adobe · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
Analysis CVE-2023-29300 Bypass: Adobe ColdFusion Pre-Auth RCE
Inspect raw assertion
- Field
container- Value
- Analysis CVE-2023-29300 Bypass: Adobe ColdFusion Pre-Auth RCE
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
96.53% probability · 99.88th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.965340000000; percentile 0.998770000000
Applicability
Cited product scope
Grouped from 1 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
2 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "0", "versionType": "semver", "lessThanOrEqual": "cf2023U1"}]product-40c507acd7e9f9a6fe8bc1b45cc600068bd553a29d1397a3d2e038f0deeda04dLinked exactInspect raw assertions
cpe:2.3:a:adobe:coldfusion:2018:update4:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 12
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
58d32489-627b-4e49-9329-8a3b8f8e4903
cpe:2.3:a:adobe:coldfusion:2021:update7:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 25
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f9d645a2-e02d-4e82-a2bd-0a7de5b8fbcc
cpe:2.3:a:adobe:coldfusion:2018:update8:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 16
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
82208628-f32a-4380-9b0f-dc8507e7701d
cpe:2.3:a:adobe:coldfusion:2018:update17:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
907f11b7-56c6-49f1-bc7b-e86b35346fd3
cpe:2.3:a:adobe:coldfusion:2021:update1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 19
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
afd05e3a-10f9-4c75-9710-ba46b66ff6e6
cpe:2.3:a:adobe:coldfusion:2018:update13:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c26bf72c-e991-4170-b68b-09b20b6c0679
cpe:2.3:a:adobe:coldfusion:2018:update10:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8ddd85df-69a0-476f-8365-cd67c75cf0ce
cpe:2.3:a:adobe:coldfusion:2018:update6:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 14
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9f9336cc-e38f-4bcb-83cd-805ec7fef806
cpe:2.3:a:adobe:coldfusion:2021:update2:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 20
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d57c8681-ac68-47df-a61e-b5c4b4a47663
cpe:2.3:a:adobe:coldfusion:2018:update14:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
25b4b4f2-318f-4046-ade5-e9dd64f83fd9
cpe:2.3:a:adobe:coldfusion:2018:update5:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 13
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6d5860e1-d293-48fe-9796-058b78b2d571
cpe:2.3:a:adobe:coldfusion:2021:update4:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 22
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7773db68-414a-4ba9-960f-52471a784379
cpe:2.3:a:adobe:coldfusion:2018:update1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
edb126bf-e09d-4e58-a39f-1190407d1cab
cpe:2.3:a:adobe:coldfusion:2018:update2:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
59649177-81ee-43c3-bfa5-e56e65b486df
cpe:2.3:a:adobe:coldfusion:2018:update15:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
831e8d69-62e9-4778-8cc5-d6d45cf5ab6f
cpe:2.3:a:adobe:coldfusion:2021:update5:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 23
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b38b9e86-bcd5-4bca-8fb7-ec55905184e6
cpe:2.3:a:adobe:coldfusion:2018:update7:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 15
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
97964507-047a-4cc8-8d2b-0ea0c7f9bd50
cpe:2.3:a:adobe:coldfusion:2018:update16:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2f549bb3-25ab-4c83-b608-3717eadaab35
cpe:2.3:a:adobe:coldfusion:2018:update11:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
23f63675-7817-4af0-a7db-5e35edabf04e
cpe:2.3:a:adobe:coldfusion:2018:update3:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 11
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
453b96ed-738a-4642-b461-c5216cf45ca3
cpe:2.3:a:adobe:coldfusion:2021:update3:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 21
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
75608383-b727-48d6-8ffa-d552a338a562
cpe:2.3:a:adobe:coldfusion:2023:update1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 27
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0aa3d302-cfee-4dfd-ab92-f53c87721bff
cpe:2.3:a:adobe:coldfusion:2018:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3b54b2b0-b1e1-4b4e-a529-d0bd3b5deef3
cpe:2.3:a:adobe:coldfusion:2018:update12:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3e3bf53e-2c0d-4f79-8b62-4c2a50cb5f52
cpe:2.3:a:adobe:coldfusion:2021:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 18
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7a94b406-c011-4673-8c2b-0dd94d46cc4c
cpe:2.3:a:adobe:coldfusion:2021:update6:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 24
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5e7bab80-8455-4570-a2a2-8f40469ee9cc
cpe:2.3:a:adobe:coldfusion:2023:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 26
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b02a37fe-5d31-4892-a3e6-156a8fe62d28
cpe:2.3:a:adobe:coldfusion:2018:update9:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 17
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1563ce5e-a4f7-40a4-a050-bb96e332d8dd
Affected-product evidence
Accepted scope and product mapping
1 canonical links · 1 source-reported links
vendor-70d8e9d1eb9ce5b2e6b4c9351aebc88bced6ea77611cbc8d5cdbe8115b6faed8 · product-40c507acd7e9f9a6fe8bc1b45cc600068bd553a29d1397a3d2e038f0deeda04d
- Source class
- Nvd cpe vulnerable target
- Assertions
- 28
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0a357402-1807-4b4c-9caf-7b027be905db0bb03995-a236-4700-8db1-90bbfc2dbce60d3e06ae-2bc2-4e61-a32f-63d5084429b10edd034a-bea1-44ce-84ce-c524bc42c6a41e031ebb-5c98-4c48-be4f-b51b4d93d0c42005ce97-453e-407b-8972-810bcff1d5a22d8e075d-9d3d-40c3-9f69-c2a5f4648b803ed50b1e-8f6f-47af-b604-092be5d2e2f847df27b3-ec08-4af6-8ca3-0907f0035fb64a843a18-43cf-421c-b933-e13022fd37ac579075c0-a02b-4d7b-b999-deefbbae3596642d0a52-6915-47a4-83e0-6f092941b9868a40b954-19a9-4201-8b92-8f487c1633b694ab0662-7027-493e-bfdb-99a6c4a6868f98da822f-da67-4ba6-82da-8f3aa359673c9c417aeb-1f37-4a54-8399-75e6a29a55819cd08859-6845-40e8-9b7e-3aff3036aa209cee2e74-f0fa-4380-83bc-e7c3f8a637bb9f364e4f-6cd3-46b0-8faa-9e26f5c3ee83a4410002-f3c1-4bc5-9e78-bf567831e77ba74df311-c7c4-4ee9-b60b-8fcefd3b8ee4c64cc42b-4298-467c-932e-24afa5b59332e1ed79a9-3a60-4dc7-be4f-3da56f2d60b3e45556e1-5e6b-4d0e-9509-1cb06779eb24e730ddaa-9959-4dbd-903d-2bead1c1cf7becd32be9-95ff-4149-a119-b1cb60ab66c3f23faadc-300a-44c6-a65e-5c78effbacc0f7564e19-6596-478d-acd6-bd3158ee00d8Canonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
d4a150e8-8aed-45b4-bc89-c70c1b427ff9Assessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDirect CVE/CNA normalized decisions
adobe
CVSS 3.1 · Primary · Original assertion · rank 1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Validation
- Valid match
- Recomputed
- 9.8
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.