Adobe has released security updates to address a critical vulnerability in the ColdFusion product (versions 2021, 2016, and 2018) that could lead to arbitrary code execution. The issue, tracked as CVE-2021-21087 is caused by improper input validation. The vulnerability was reported by Josh Lane, the company confirmed that it is now aware of attacks in the wild exploiting the vulnerability. The software giant recommends customers apply the security configuration settings as outlined on the Coldfusion Security page as well as review the respective Lockdown guides.”]
Source: https://securityaffairs.co/wordpress/115864/security/adobe-coldfusion-flaw.html

