[Looking for Charlie's main web site?]

Announcing ColdFusion updates released Dec 9 2025 - p1 security update and more

An update for ColdFusion has been released, Dec 9 2025, for each of cf2025 (update 5), cf2023 (update 17) and cf2021 (update 23). This is in fact that FINAL update of CF2021, as it has reached its end of life as I blogged last month.

In brief, this update (for all 3 versions) ad.dresses several P1 (Priority 1, "Critical") security vulnerabilities, and also updates Tomcat, along with updating several CF packages, and makes some other changes (see below). Note that Adobe is also reporting currently that, "Adobe is not aware of any exploits in the wild for any of the issues addressed in these updates."

In this post, I share the details about the update (from Adobe and from others). I also share additional info you may want to consider before (or after) doing the update. 

Having installed the update for each of the releases on multiple machines, I can report that it went well expect for this:

Warning: on CF2023, after applying the update, I and others have experiences that the CF Admin is inaccessible and packages that were updates are unexpectedly uninstalled. I will offer a follow-up post on that, including how to solve the problem (until Adobe does), and how to ensure your own manual efforts to solve it are complete.

[....Continue Reading....]

Reminder that CF2021 is end-of-life as of Monday Nov 10 2025

This coming Monday, Nov 10 2025, marks the end of Adobe support of CF2021. After that date, Adobe is no longer obligated to offer updates for ColdFusion 2021 (not even security updates--and buying "extended support" DOES NOT CHANGE that!)

There's more to consider. For that, read on.

[....Continue Reading....]

Announcing Java updates of Oct 21, 2025 for 8, 11, 17, 21, and 25 - thoughts and resources

It's that time again: there are new Oracle JVM updates released today (Oct 21, 2025) for the current long-term support (LTS) releases of Oracle Java, 8, 11, 17, 21, and 25. (The previous short-term release, Java 24, is no longer updated.)

TLDR: The new updates are 1.8.0_471 (aka 8u471), 11.0.29, 17.0.17, 21.0.9, and 25.0.1, respectively. More on the updates below, including links to more info on each of them including what changed, bug fixes, and the security fixes each version contains. (I also offer a quick assessment of the updates with respect to my primary audience, users of CFML engines.)

[....Continue Reading....]

Announcing ColdFusion updates released Sep 9 2025 - p1 security update

An update for ColdFusion has been released, Sep 9 2025, for each of cf2025 (update 4), cf2023 (update 16) and cf2021 (update 22). In brief, it addresses a single P1 (Priority 1, "Critical") security vulnerabilities, along with an indicated update to the "feed" package (used by cffeed). Note that Adobe is also reporting currently that, "Adobe is not aware of any exploits in the wild for any of the issues addressed in these updates." More below.

As usual, there are a number of things you should consider before (or after) doing the update, with some discussed in Adobe's resources on the update (there are more than one), and some info that I share below based on my experience helping people apply this and past updates.

In this post, I share the details about the update (from Adobe and from others). I can report I have installed the update for each release on multiple machines and operating systems without any major incidents. As for challenges (common to recent releases) and lessons learned (about this update), read on.

[....Continue Reading....]

Announcing Java updates of Jul 15, 2025 for 8, 11, 17, 21, and 24 - thoughts and resources

It's that time again: there are new Oracle JVM updates released today (Jul 15, 2025) for the current long-term support (LTS) releases of Oracle Java, 8, 11, 17, and 21, as well as the new short-term release 24. (The previous short-term release, Java 23, is no longer updated.)

TLDR: The new updates are 1.8.0_461 (aka 8u461), 11.0.28, 17.0.16, 21.0.8, and 24.0.2, respectively. More on the updates below, including links to more info on each of them including what changed, bug fixes, and the security fixes each version contains. (I also offer a quick assessment of the updates with respect to my primary audience, users of CFML engines.)

[....Continue Reading....]

Announcing ColdFusion updates released July 8 2025 - p1 security update and more

An update for ColdFusion has been released, July 8 2025, for each of cf2025 (update 3), cf2023 (update 15) and cf2021 (update 21). In brief, it addresses a number of P1 (Priority 1, "Critical") security vulnerabilities and more, including bug fixes and some modest feature changes.

As usual, there are a number of things you should consider before (or after) doing the update, with some discussed in Adobe's resources on the update (more than one), and some that I share below based on my experience helping people apply this and past updates. Finally, the update corrects some issues introduced in the previous updates, released in May.

In this post, I share the details about the update (from Adobe and from others). I can report I have installed the update for each release on multiple machines and operating systems without any major incidents. As for challenges (common to recent releases) and lessons learned (about this update), read on.

[....Continue Reading....]

Presenting "Debugging & Error Handling in ColdFusion" today, online for CF DevWeek

Today begins the first of several live hour-long presentations over the next few days as part of Adobe ColdFusion Dev Week. I blogged more about the week-long event on the Adobe CF portal, including listing all the topics, times, and presenters (and those are offered on the Adobe devweek page linked to above, of course--though the UI is a bit of a challenge, with each day in a different tab you must select).

I want to announce in particular here that I'll be offering the first talk of the week: "Debugging and Error Handling in ColdFusion". Read on for more.

[....Continue Reading....]

Announcing ColdFusion updates released May 13 2025 - p1 security update (and more)

An update for ColdFusion has been released, May 13, 2025, for both cf2025 (update 2), cf2023 (update 14) and cf2021 (update 20). In brief, it addresses a P1 (Priority 1, "Critical") security vulnerability, as indicated in the associated ASPB (security bulletin) for the update.

The update also incorporates potentially breaking changes (with Adobe trading compatibility for security), while it also includes configurable options to undo those changes (if you prefer to trade away security for compatibility). Finally, the update corrects some issues introduced in the previous updates, released in April.

In this post, I share the details about the update (from Adobe and from others). I can report I have installed both updates on multiple machines and operating systems without incident. As for challenges or lessons learned, I may do a follow-up post as I/we all learn more.

For more details, read on.

[....Continue Reading....]

Presenting "Solving Common Problems with CF Updates" today, online

Have you had problems installing CF updates, whether the most recent or past ones?

I'll be presenting a talk on this topic, online today, at noon US Eastern, on the CFMeetup Youtube livestream (which will be recorded). Folks who are members of the Online ColdFusion Meetup will have already gotten email notification about this, including the meeting URL, but for those who are not members here are the details:

[....Continue Reading....]

Announcing Java updates of Apr 15, 2025 for 8, 11, 17, 21, and 24 - thoughts and resources

It's that time again: there are new JVM updates released today (Apr 15, 2025) for the current long-term support (LTS) releases of Oracle Java, 8, 11, 17, and 21, as well as the new short-term release 24. (The previous short-term release, Java 23, is no longer updated.)

TLDR: The new updates are 1.8.0_451 (aka 8u451), 11.0.27, 17.0.15, 21.0.7, and 24.0.1, respectively. Crazy that there are now 5 current Java releases, I do realize. More below, including links to more on each of them including what changed, bug fixes, and the security fixes each version contains, which are offered in Oracle resources I list below.

[....Continue Reading....]

More Entries

Copyright ©2025 Charlie Arehart
Carehart Logo
BlogCFC was created by Raymond Camden. This blog is running version 5.005.
(Want to validate the HTML in this page?)

Managed Hosting Services provided by
Managed Dedicated Hosting