---
id: CVE-2025-61809
title: >-
  ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an
  Improper Input Validation vulnerability that could result in a Security
  feature bypass
summary: >-
  ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an
  Improper Input Validation vulnerability that could result in a Security
  feature bypass. An attacker could leverage this vulnerability to bypass
  security measures…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-20
vendor: adobe
product: coldfusion
affected:
  - coldfusion = 2021
  - coldfusion = 2023
  - coldfusion = 2025
published: '2025-12-10'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T23:10:00.463'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-61809'
references:
  - url: 'https://helpx.adobe.com/security/products/coldfusion/apsb25-105.html'
    label: psirt@adobe.com
tags:
  - nvd
epss: 0.00661
epssPercentile: 0.49514
ingestedAt: '2026-09-25T23:21:16.908Z'
---

## Overview

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access. Exploitation of this issue does not require user interaction and scope is unchanged.

## Affected

- `coldfusion = 2021`
- `coldfusion = 2023`
- `coldfusion = 2025`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
