[Looking for Charlie's main web site? or all posts?]

Announcing ColdFusion updates of Sep 8 2026 - p1 security update

Adobe has released another set of updates today, Sept 8 2026, for CF2025 (update 13) and CF2023 (update 24). As with other recent updates, these "resolve critical, important, and moderate vulnerabilities that could lead to arbitrary code execution, arbitrary file system read, privilege escalation, security feature bypass, and memory exposure."

[....Continue Reading....]

Comments
Is the workaround for CF-4233544 included in this hotfix or will it have to be re-applied? I did not see anything in the tech notes about it.
# Posted By Jeff Horne | 9/10/26 11:13 AM
Jeff, I am not aware, but you (or others or I) can find out pretty easily. Let me elaborate (responding on a phone).

First, he's referring to https://tracker.adobe.com/#/view/CF-4233544, which was a bug introduced in the previous update, which had updated tomcat. After that, cf instances that were set to use cf's cluster and session replication feature wouldn't start. Adobe offered an updated catalina.jar there, which fixed the problem. Jeff's now asking if that change made it into this update.

I'll say there were no "bugs fixed" listed in the technote. And I don't make a habit of checking all outstanding bugs (that may have fixes offered via tracker) to see if they were rolled into an update. :-)

But it won't surprise me if they did NOT incorporate this change (the updated catalina.jar), because such security updates tend NOT to incorporate bug fixes. It seems they are pressed (by the Adobe PSIRT folks) to get the sec vulns fixed ASAP. As such, my sense is that they withhold bug fixes--even existing ones--to keep the impact of the update limited to those changes due to the security protections.

I've seen them wait more than one cycle of updates before rolling bug fixes (and perhaps feature changes and even sec fixes) into a later update.

That's frustrated folks who found this stance also meant that known tomcat vulns remained unresolved, because Adobe didn't roll that into some sec-only update.

I'm just an observer. I have no sway on their decision-making.

Last, note that it's possible that while the update didn't APPLY that updated catalina.jar, it also likely would not have touched it. So if you did apply the update, the changed file may remain.

If you or anyone gets to check, I'd love to hear. I don't want to promise I will get to check. Juggling a lot right now.

Hope that's helpful.
Thank you Charlie. I will be sure to post here once I have a finding.
# Posted By Jeff Horne | 9/10/26 1:17 PM
I'll note that I have since done some checking, and I can confirm first that the catalina.jar in that tracker fix is NOT the one placed into CF by that update. They're the same "version" (such as 10.1.57 for CF2025), but internally there are a couple of java classes (in \org\apache\catalina\startup within the jar) that are NOT in the version of the file placed there by the update.

Second, I did not have that updated jar in place when I did my updates earlier this week, but I can say that I see the catalina.jar listed in the hotfix_filelist.log, within the hf-updates folder for the update. And I ALSO see the file in the \backup\runtime\lib folder within that hf-updates folder for the update.)

As such, I would expect that the updated file (put in place from tracker) WOULD have been replaced by the update. That said, it does mean one could easily recover it from that backup folder (or it can be obtained again from tracker, of course). One would then need to restart CF for that change to take effect.

And while I was looking at CF2025, I'd expect the same with CF2023 (though to be clear, Adobe offers a different catalina.jar in tracker for each CF version. Don't cross the streams!)

Finally, it is indeed lamentable that the tracker ticket lists the bug as "fixed". If you look closely, though, what it shows (for 2025) is that the "fixed in build" is 2025.0.12.331938. To be clear, the update technote for update 12 had indicated its version was 2025,0,12,331922 (which is BELOW that). We've not had an update that takes us to THAT version.

And while this week's update takes us to 2025,0,13,331960 (clearly "above" that), again we don't have it fixed.

More interesting, I am noticing now that the tracker ticket DOES list TWO different versions for CF2023's "fixed in build": 2023.0.25.330965, 2023.0.23.330946

So that suggests they plan for it to be implemented in an update 25 (of 2023). They just failed to list there that seemingly for CF2025 i would come in an update 14, yet to come.

HTH.

/Charlie, your friendly tea-leaves reader...
Thanks for the update Charlie...although I needed to have a few more cups with tea leaves in them to follow your latest post. :)
# Posted By BrianM | 9/11/26 10:30 AM
I'll assume you mean my last comment here. Admittedly it should make more sense to those already dealing with the problem Jeff raised. Hope to hear for him or others dealing with it, based on what I'd shared.
Copyright ©2026 Charlie Arehart
Carehart Logo
BlogCFC was created by Raymond Camden. This blog is running version 5.005.
(Want to validate the HTML in this page?)

Managed Hosting Services provided by
xByte cloud Hosting