Announcing CF update released Jul 14 2023 - a second priority 1 security update in one week
For more on the update, and some additional thoughts, read on.
For more on the update, and some additional thoughts, read on.
One explanation and solution for when applying CF updates uninstalls new packages unexpectedly
Announcing ColdFusion updates released Dec 9 2025 - p1 security update and more
Reminder that CF2021 is end-of-life as of Monday Nov 10 2025
Announcing Java updates of Oct 21, 2025 for 8, 11, 17, 21, and 25 - thoughts and resources
Announcing ColdFusion updates released Sep 9 2025 - p1 security update
Announcing ColdFusion updates released Dec 9 2025 - p1 security update and more
Charlie Arehart said:
Tim, that's incorrect.
...
CAN use that JVM arg with CF2025 and it IS honore
...
[more]
Announcing ColdFusion updates released Dec 9 2025 - p1 security update and more
Tim Fitzpatrick said:
Adobe replied that it's expected in this release, and is part of their ongoing scoping changes.
...
[more]
Announcing ColdFusion updates released Dec 9 2025 - p1 security update and more
Tim Fitzpatrick said:
Thanks for the info about the scoping change for variables named FILE!
ColdFusion 2025 released, Feb 25 2025 - resources and my initial thoughts
Charlie Arehart said:
Craig, you seem to have concluded (and want to warn people) that a cf license can only be
...
[more]
ColdFusion 2025 released, Feb 25 2025 - resources and my initial thoughts
Craig Baker said:
I let the free trial lapse into Developer mode while I took care of some other issues, and was subse
...
[more]


I will note that while that post indicates that "There is currently no mitigation", that may not be the final/complete answer. Note how it refers to the _cfclient querystring, and notice that in my first post last week (on the Jul 11 CF update), I did point out how my March blog post on the previous CF update discussed ways to BLOCK ALL REQUESTS using that _cfclient querystring. I also elaborate there on what it's about, how one can determine if they may have any legit use of it (most do not), and much more. See https://www.carehart...
As I've said elsewhere, it's just not clear how many of the recently closed vulns DO work based on the _cfclient querystring. That post is about all we have to go on, as I've not seen any others. While those on cf2018 and above can apply these fixes to address what Adobe has found, it's just not clear (for now) what those on cf2016 can or should do, other than block requests with that querystring.