Announcing ColdFusion updates of Sep 8 2026 - p1 security update
Rather than detail the updates as I have in the past, I will for now leave this at simply announcing the update and pointing you to Adobe's several resources with more on the updates. The first 3 are community resources where other folks may (over time) share feedback or observations about the update(s), which point to the last 2 (the update technotes) and more:
- Adobe CF Forum post on the update
- Adobe CF Portal post on the update
- Adobe post on CFML Slack Channel
- CF2025 update 13 tech note
- CF2023 update 24 tech note
Each of the resources link to still more info about the CF updates in general and about this most recent one in particular, including downloads for the update jar file and packages zip file (for those who may need those for command-line or offline updates) as well as the APSB offering security vuln details.
As has been the case in recent updates, note that the update technotes indicate some changes arising from the new security protections as well as available mitigation options.
We must balance the urgency of the update (for the security protections) against the potential changes in compatibility, along with the available mitigations (which would re-open a door that Adobe is closing in this update). Sadly, there's never enough detail in the information provided to assess that on this first day. Time will tell.
Experience so far...
FWIW I have not seen any discussions of update issues today in the community resources above.
If I learn of any significant ramifications of this update, I may offer comments below, or an update to this post, or potentially even a new post.
I can say that I have applied the update on both versions, on multiple machines and different OS's, without any trouble during the update. I've also confirmed that the downloadable zip of packages offers the updated packages indicated in each update technote (there have been recent occasions where the zip did NOT include the updated packages).
Getting help, from me or others
As always, if you have need of assistance in applying or dealing with the ramifications of the update, note first that you can use those community resources above to seek help publicly.
Or I am available for remote screenshare consulting. I can usually solve most update-related problems very quickly, since I help so many people with them in each update (whether publicly or directly). See carehart.org/consulting for more on my rates, approach, satisfaction guarantee, online calendar, and more.
For more content like this from Charlie Arehart:Need more help with problems?
- Signup to get his blog posts by email:
- Follow his blog RSS feed
- View the rest of his blog posts
- View his blog posts on the Adobe CF portal
- If you may prefer direct help, rather than digging around here/elsewhere or via comments, he can help via his online consulting services
- See that page for more on how he can help a) over the web, safely and securely, b) usually very quickly, c) teaching you along the way, and d) with satisfaction guaranteed





First, he's referring to https://tracker.adobe.com/#/view/CF-4233544, which was a bug introduced in the previous update, which had updated tomcat. After that, cf instances that were set to use cf's cluster and session replication feature wouldn't start. Adobe offered an updated catalina.jar there, which fixed the problem. Jeff's now asking if that change made it into this update.
I'll say there were no "bugs fixed" listed in the technote. And I don't make a habit of checking all outstanding bugs (that may have fixes offered via tracker) to see if they were rolled into an update. :-)
But it won't surprise me if they did NOT incorporate this change (the updated catalina.jar), because such security updates tend NOT to incorporate bug fixes. It seems they are pressed (by the Adobe PSIRT folks) to get the sec vulns fixed ASAP. As such, my sense is that they withhold bug fixes--even existing ones--to keep the impact of the update limited to those changes due to the security protections.
I've seen them wait more than one cycle of updates before rolling bug fixes (and perhaps feature changes and even sec fixes) into a later update.
That's frustrated folks who found this stance also meant that known tomcat vulns remained unresolved, because Adobe didn't roll that into some sec-only update.
I'm just an observer. I have no sway on their decision-making.
Last, note that it's possible that while the update didn't APPLY that updated catalina.jar, it also likely would not have touched it. So if you did apply the update, the changed file may remain.
If you or anyone gets to check, I'd love to hear. I don't want to promise I will get to check. Juggling a lot right now.
Hope that's helpful.
Second, I did not have that updated jar in place when I did my updates earlier this week, but I can say that I see the catalina.jar listed in the hotfix_filelist.log, within the hf-updates folder for the update. And I ALSO see the file in the \backup\runtime\lib folder within that hf-updates folder for the update.)
As such, I would expect that the updated file (put in place from tracker) WOULD have been replaced by the update. That said, it does mean one could easily recover it from that backup folder (or it can be obtained again from tracker, of course). One would then need to restart CF for that change to take effect.
And while I was looking at CF2025, I'd expect the same with CF2023 (though to be clear, Adobe offers a different catalina.jar in tracker for each CF version. Don't cross the streams!)
Finally, it is indeed lamentable that the tracker ticket lists the bug as "fixed". If you look closely, though, what it shows (for 2025) is that the "fixed in build" is 2025.0.12.331938. To be clear, the update technote for update 12 had indicated its version was 2025,0,12,331922 (which is BELOW that). We've not had an update that takes us to THAT version.
And while this week's update takes us to 2025,0,13,331960 (clearly "above" that), again we don't have it fixed.
More interesting, I am noticing now that the tracker ticket DOES list TWO different versions for CF2023's "fixed in build": 2023.0.25.330965, 2023.0.23.330946
So that suggests they plan for it to be implemented in an update 25 (of 2023). They just failed to list there that seemingly for CF2025 i would come in an update 14, yet to come.
HTH.
/Charlie, your friendly tea-leaves reader...
That's not saying all ran smoothly. The odd thing with this hotfix that I noticed is that with most of the upgrades to HF 24 on my instances, I had to reinstall the FEED package because it was uninstalled for some reason. I had to install the .21 version but there is a .25 version since that hotfix is now released. I also had to install the administrator through cfpm.bat randomly on some but not every instance. Strange happenings but I seem to be okay.
Of course, a month later update 25 came out. We'll see how things go for you and others dealing with that session replication issue, when you may apply that.
Finally, as for your issues with the feed package, I can say that I am not aware of any common problem (about that package specifically) that has been happening to folks.
There can be all kinds of reasons that one or more packages fail to get installed. I have discussed many times in past blog posts (about updates) how it's critical that folks watch the logs after an update--both the update log itself (which is where downloading of the package updates is tracked, at the bottom) and then in the coldfusion-out.log (in the lines tracking the startup of CF after that update).
It's during that first CF startup after the update that any package updates are attempted (first showing "uninstalling" for each package to be updated, and then showing "started" for each package installed--no message tracking "updating" or "updated").
To be clear, that package update mechanism ALWAYS starts by removing what it thinks it needs to update. The problem is that if there's any FAILURE to do that update (which WILL be logged there), it does NOT have a process to roll back, reinstall, etc. And so folks are left with some packages uninstalled.
The answer is always in the logs. And sometimes the root cause is something you can control. There are too many possibilities to list them all. But I can help those who feel it's a convoluted mess that they can't figure out.
I won't be surprised if it's it specific to the feed package but somehow happens to another, or none at all.
Good for people to be reminded to watch out, yep.