Announcing CF update released Jul 14 2023 - a second priority 1 security update in one week
For more on the update, and some additional thoughts, read on.
For more on the update, and some additional thoughts, read on.
Announcing major ColdFusion 2025 update of May 20 2026 - thoughts and resources
About the coming (massive) CF2025 "AI update", prerelease links and more
Announcing Java updates of Apr 21 2026 - thoughts and resources
Announcing ColdFusion updates of Apr 14 2026 - p1 security update - thoughts and resources
Announcing Java updates of Jan 20 2026 - thoughts and resources
Announcing major ColdFusion 2025 update of May 20 2026 - thoughts and resources
Charlie Arehart said:
Rejith: ah, ok. I had not yet noticed that new drop-down (on all pages of the new doc site
...
[more]
Announcing major ColdFusion 2025 update of May 20 2026 - thoughts and resources
Rejith said:
Hey Charlie, when you are in one of the documentation pages, next to the page heading, there is a bu
...
[more]
Announcing major ColdFusion 2025 update of May 20 2026 - thoughts and resources
Charlie Arehart said:
j404, I don't think this post is the place to have that debate. Still, I'll clarify for re
...
[more]
Announcing major ColdFusion 2025 update of May 20 2026 - thoughts and resources
Charlie Arehart said:
Rejith, the link you shared fails for me. Does it really work for you?
I ...
an
...
[more]
Announcing major ColdFusion 2025 update of May 20 2026 - thoughts and resources
j404 said:
too little to late adobe, boxlang is eating your lunch, for breakfast


I will note that while that post indicates that "There is currently no mitigation", that may not be the final/complete answer. Note how it refers to the _cfclient querystring, and notice that in my first post last week (on the Jul 11 CF update), I did point out how my March blog post on the previous CF update discussed ways to BLOCK ALL REQUESTS using that _cfclient querystring. I also elaborate there on what it's about, how one can determine if they may have any legit use of it (most do not), and much more. See https://www.carehart...
As I've said elsewhere, it's just not clear how many of the recently closed vulns DO work based on the _cfclient querystring. That post is about all we have to go on, as I've not seen any others. While those on cf2018 and above can apply these fixes to address what Adobe has found, it's just not clear (for now) what those on cf2016 can or should do, other than block requests with that querystring.