[Looking for Charlie's main web site? or all posts?]

Announcing ColdFusion updates of Sep 8 2026 - p1 security update

Adobe has released another set of updates today, Sept 8 2026, for CF2025 (update 13) and CF2023 (update 24). As with other recent updates, these "resolve critical, important, and moderate vulnerabilities that could lead to arbitrary code execution, arbitrary file system read, privilege escalation, security feature bypass, and memory exposure."

Rather than detail the updates as I have in the past, I will for now leave this at simply announcing the update and pointing you to Adobe's several resources with more on the updates. The first 3 are community resources where other folks may (over time) share feedback or observations about the update(s), which point to the last 2 (the update technotes) and more:

Each of the resources link to still more info about the CF updates in general and about this most recent one in particular, including downloads for the update jar file and packages zip file (for those who may need those for command-line or offline updates) as well as the APSB offering security vuln details.

As has been the case in recent updates, note that the update technotes indicate some changes arising from the new security protections as well as available mitigation options.

We must balance the urgency of the update (for the security protections) against the potential changes in compatibility, along with the available mitigations (which would re-open a door that Adobe is closing in this update). Sadly, there's never enough detail in the information provided to assess that on this first day. Time will tell.

Experience so far...

FWIW I have not seen any discussions of update issues today in the community resources above.

If I learn of any significant ramifications of this update, I may offer comments below, or an update to this post, or potentially even a new post.

I can say that I have applied the update on both versions, on multiple machines and different OS's, without any trouble during the update. I've also confirmed that the downloadable zip of packages offers the updated packages indicated in each update technote (there have been recent occasions where the zip did NOT include the updated packages).

Getting help, from me or others

As always, if you have need of assistance in applying or dealing with the ramifications of the update, note first that you can use those community resources above to seek help publicly.

Or I am available for remote screenshare consulting. I can usually solve most update-related problems very quickly, since I help so many people with them in each update (whether publicly or directly). See carehart.org/consulting for more on my rates, approach, satisfaction guarantee, online calendar, and more.


For more content like this from Charlie Arehart: Need more help with problems?
  • If you may prefer direct help, rather than digging around here/elsewhere or via comments, he can help via his online consulting services
  • See that page for more on how he can help a) over the web, safely and securely, b) usually very quickly, c) teaching you along the way, and d) with satisfaction guaranteed
Comments
Is the workaround for CF-4233544 included in this hotfix or will it have to be re-applied? I did not see anything in the tech notes about it.
# Posted By Jeff Horne | 9/10/26 11:13 AM
Jeff, I am not aware, but you (or others or I) can find out pretty easily. Let me elaborate (responding on a phone).

First, he's referring to https://tracker.adobe.com/#/view/CF-4233544, which was a bug introduced in the previous update, which had updated tomcat. After that, cf instances that were set to use cf's cluster and session replication feature wouldn't start. Adobe offered an updated catalina.jar there, which fixed the problem. Jeff's now asking if that change made it into this update.

I'll say there were no "bugs fixed" listed in the technote. And I don't make a habit of checking all outstanding bugs (that may have fixes offered via tracker) to see if they were rolled into an update. :-)

But it won't surprise me if they did NOT incorporate this change (the updated catalina.jar), because such security updates tend NOT to incorporate bug fixes. It seems they are pressed (by the Adobe PSIRT folks) to get the sec vulns fixed ASAP. As such, my sense is that they withhold bug fixes--even existing ones--to keep the impact of the update limited to those changes due to the security protections.

I've seen them wait more than one cycle of updates before rolling bug fixes (and perhaps feature changes and even sec fixes) into a later update.

That's frustrated folks who found this stance also meant that known tomcat vulns remained unresolved, because Adobe didn't roll that into some sec-only update.

I'm just an observer. I have no sway on their decision-making.

Last, note that it's possible that while the update didn't APPLY that updated catalina.jar, it also likely would not have touched it. So if you did apply the update, the changed file may remain.

If you or anyone gets to check, I'd love to hear. I don't want to promise I will get to check. Juggling a lot right now.

Hope that's helpful.
Thank you Charlie. I will be sure to post here once I have a finding.
# Posted By Jeff Horne | 9/10/26 1:17 PM
I'll note that I have since done some checking, and I can confirm first that the catalina.jar in that tracker fix is NOT the one placed into CF by that update. They're the same "version" (such as 10.1.57 for CF2025), but internally there are a couple of java classes (in \org\apache\catalina\startup within the jar) that are NOT in the version of the file placed there by the update.

Second, I did not have that updated jar in place when I did my updates earlier this week, but I can say that I see the catalina.jar listed in the hotfix_filelist.log, within the hf-updates folder for the update. And I ALSO see the file in the \backup\runtime\lib folder within that hf-updates folder for the update.)

As such, I would expect that the updated file (put in place from tracker) WOULD have been replaced by the update. That said, it does mean one could easily recover it from that backup folder (or it can be obtained again from tracker, of course). One would then need to restart CF for that change to take effect.

And while I was looking at CF2025, I'd expect the same with CF2023 (though to be clear, Adobe offers a different catalina.jar in tracker for each CF version. Don't cross the streams!)

Finally, it is indeed lamentable that the tracker ticket lists the bug as "fixed". If you look closely, though, what it shows (for 2025) is that the "fixed in build" is 2025.0.12.331938. To be clear, the update technote for update 12 had indicated its version was 2025,0,12,331922 (which is BELOW that). We've not had an update that takes us to THAT version.

And while this week's update takes us to 2025,0,13,331960 (clearly "above" that), again we don't have it fixed.

More interesting, I am noticing now that the tracker ticket DOES list TWO different versions for CF2023's "fixed in build": 2023.0.25.330965, 2023.0.23.330946

So that suggests they plan for it to be implemented in an update 25 (of 2023). They just failed to list there that seemingly for CF2025 i would come in an update 14, yet to come.

HTH.

/Charlie, your friendly tea-leaves reader...
Thanks for the update Charlie...although I needed to have a few more cups with tea leaves in them to follow your latest post. :)
# Posted By BrianM | 9/11/26 10:30 AM
I'll assume you mean my last comment here. Admittedly it should make more sense to those already dealing with the problem Jeff raised. Hope to hear for him or others dealing with it, based on what I'd shared.
Hi Charlie. I was out all last week and have not yet worked with this hotfix yet. Hope to very soon.
# Posted By Jeff Horne | 9/24/26 9:30 AM
Getting back to this thread which I should have done a week or two ago. I installed CF 2023 Hotfix 24 in the clustered instances and they seem to run without issue. Everything started up after the install as one would expect and I did not have to apply the catalina.jar from the tracker fix.

That's not saying all ran smoothly. The odd thing with this hotfix that I noticed is that with most of the upgrades to HF 24 on my instances, I had to reinstall the FEED package because it was uninstalled for some reason. I had to install the .21 version but there is a .25 version since that hotfix is now released. I also had to install the administrator through cfpm.bat randomly on some but not every instance. Strange happenings but I seem to be okay.
# Posted By Jeff Horne | 10/7/26 2:05 PM
Jeff, first glad to hear you're confirming that you did not need to add that special hotfix (catalina.jar, for those dealing with CF clustering and session replication), at least as of your testing with this update 24 (the topic of this post).

Of course, a month later update 25 came out. We'll see how things go for you and others dealing with that session replication issue, when you may apply that.

Finally, as for your issues with the feed package, I can say that I am not aware of any common problem (about that package specifically) that has been happening to folks.

There can be all kinds of reasons that one or more packages fail to get installed. I have discussed many times in past blog posts (about updates) how it's critical that folks watch the logs after an update--both the update log itself (which is where downloading of the package updates is tracked, at the bottom) and then in the coldfusion-out.log (in the lines tracking the startup of CF after that update).

It's during that first CF startup after the update that any package updates are attempted (first showing "uninstalling" for each package to be updated, and then showing "started" for each package installed--no message tracking "updating" or "updated").

To be clear, that package update mechanism ALWAYS starts by removing what it thinks it needs to update. The problem is that if there's any FAILURE to do that update (which WILL be logged there), it does NOT have a process to roll back, reinstall, etc. And so folks are left with some packages uninstalled.

The answer is always in the logs. And sometimes the root cause is something you can control. There are too many possibilities to list them all. But I can help those who feel it's a convoluted mess that they can't figure out.
I checked the update log and it only mentions the Feed package for HF 25 being downloaded along with all the other HF 25 packages. Then in coldfusion-out log, I see an entry from when I did the HF 24 upgrade saying "Uninstalling the package feed" along with many others. Then at the time of the post upgrade startup, "feed package will not be deployed as it is not installed". Finally, after the re-install of FEED, I see "Package feed started..." It's not a big deal now because I am checking for it with each upgrade in each instance. I have not tried to install HF 25 in any of them yet but there is a updated version of FEED with HF 25 so I expect that to go smoothly. Like I said, it was a strange happening that I was not expecting, it did impact site behavior that used it before troubleshooting and finding the issue. My reason for posting it here was to give anyone else who is still working for the frequent hotfix releases and runs into it as well.
# Posted By Jeff Horne | 10/8/26 11:16 AM
Right. That's why checking the logs after each update is highly recommended. As for why it failed, there should be additional details elsewhere, perhaps the cfpm-audit.log (written to even during simply cf starting up), or the exception or coldfusion-error.log.

I won't be surprised if it's it specific to the feed package but somehow happens to another, or none at all.

Good for people to be reminded to watch out, yep.
Copyright ©2026 Charlie Arehart
Carehart Logo
BlogCFC was created by Raymond Camden. This blog is running version 5.005.
(Want to validate the HTML in this page?)

Managed Hosting Services provided by
xByte cloud Hosting