Announcing ColdFusion updates of Sep 8 2026 - p1 security update
Solving a new problem as of CF2023 update 25 that can cause CF to not start
Announcing ColdFusion updates of Sep 23 2026 - for CF2023 only
Announcing ColdFusion updates of Sep 8 2026 - p1 security update
Announcing ColdFusion updates of Aug 11 2026 - p1 security update - thoughts and resources
Announcing Java updates of Jul 21 2026 - thoughts and resources
Solving a new problem as of CF2023 update 25 that can cause CF to not start
Charlie Arehart said:
Glad to hear that it helped, Franc. I'll say again (as i do in the post) that this is
...
[more]
Solving a new problem as of CF2023 update 25 that can cause CF to not start
Franc Amour said:
Hey Charlie,
I ended up installing CFU25 the day it came out, and ran into this -
...
[more]
Solving a new problem as of CF2023 update 25 that can cause CF to not start
Charlie Arehart said:
Salvatore, glad to hear that the fix got you past your first hump. As for your second, I've not
...
[more]
Solving a new problem as of CF2023 update 25 that can cause CF to not start
Salvatore said:
Hi Charlie, thanks for this post. Your short-PATH workaround does fix the initial Java instrumentati
...
[more]
Announcing ColdFusion updates of Sep 23 2026 - for CF2023 only
Charlie Arehart said:
OK, I've finally figured out what's amiss (about that issue where CF won't start
...
[more]


First, he's referring to https://tracker.adobe.com/#/view/CF-4233544, which was a bug introduced in the previous update, which had updated tomcat. After that, cf instances that were set to use cf's cluster and session replication feature wouldn't start. Adobe offered an updated catalina.jar there, which fixed the problem. Jeff's now asking if that change made it into this update.
I'll say there were no "bugs fixed" listed in the technote. And I don't make a habit of checking all outstanding bugs (that may have fixes offered via tracker) to see if they were rolled into an update. :-)
But it won't surprise me if they did NOT incorporate this change (the updated catalina.jar), because such security updates tend NOT to incorporate bug fixes. It seems they are pressed (by the Adobe PSIRT folks) to get the sec vulns fixed ASAP. As such, my sense is that they withhold bug fixes--even existing ones--to keep the impact of the update limited to those changes due to the security protections.
I've seen them wait more than one cycle of updates before rolling bug fixes (and perhaps feature changes and even sec fixes) into a later update.
That's frustrated folks who found this stance also meant that known tomcat vulns remained unresolved, because Adobe didn't roll that into some sec-only update.
I'm just an observer. I have no sway on their decision-making.
Last, note that it's possible that while the update didn't APPLY that updated catalina.jar, it also likely would not have touched it. So if you did apply the update, the changed file may remain.
If you or anyone gets to check, I'd love to hear. I don't want to promise I will get to check. Juggling a lot right now.
Hope that's helpful.
Second, I did not have that updated jar in place when I did my updates earlier this week, but I can say that I see the catalina.jar listed in the hotfix_filelist.log, within the hf-updates folder for the update. And I ALSO see the file in the \backup\runtime\lib folder within that hf-updates folder for the update.)
As such, I would expect that the updated file (put in place from tracker) WOULD have been replaced by the update. That said, it does mean one could easily recover it from that backup folder (or it can be obtained again from tracker, of course). One would then need to restart CF for that change to take effect.
And while I was looking at CF2025, I'd expect the same with CF2023 (though to be clear, Adobe offers a different catalina.jar in tracker for each CF version. Don't cross the streams!)
Finally, it is indeed lamentable that the tracker ticket lists the bug as "fixed". If you look closely, though, what it shows (for 2025) is that the "fixed in build" is 2025.0.12.331938. To be clear, the update technote for update 12 had indicated its version was 2025,0,12,331922 (which is BELOW that). We've not had an update that takes us to THAT version.
And while this week's update takes us to 2025,0,13,331960 (clearly "above" that), again we don't have it fixed.
More interesting, I am noticing now that the tracker ticket DOES list TWO different versions for CF2023's "fixed in build": 2023.0.25.330965, 2023.0.23.330946
So that suggests they plan for it to be implemented in an update 25 (of 2023). They just failed to list there that seemingly for CF2025 i would come in an update 14, yet to come.
HTH.
/Charlie, your friendly tea-leaves reader...