Rapid7: threat actors have exploited zero-day RCE flaws in Adobe ColdFusion and Citrix NetScaler; Citrix patched its flaw but Adobe issued an incomplete fix
The exploited code-execution flaws are the kind coveted by ransomware and nation-state hackers. — Organizations big and small …
Ars Technica Dan Goodin
Related Coverage
- Active Exploitation of Multiple Adobe ColdFusion Vulnerabilities Rapid7 · Caitlin Condon
- Citrix warns of actively exploited zero-day in ADC and Gateway Security Affairs · Pierluigi Paganini
- Critical Zero-Day Vulnerability in Citrix NetScaler ADC and NetScaler Gateway Rapid7 · Caitlin Condon
- Citrix discloses critical NetScaler Gateway vulnerability ITPro · Ross Kelly
- Zero-Day Attacks Exploited Critical Vulnerability in Citrix ADC and Gateway The Hacker News
- New Vulnerabilities Found in Adobe ColdFusion Infosecurity · Kevin Poireault
- Exploitation of New Citrix Zero-Day Likely to Increase, Organizations Warned SecurityWeek · Eduard Kovacs
- Citrix zero-day vulnerability under attack iTnews · Richard Chirgwin
- Adobe ColdFusion Vulnerabilities Exploited in the Attacks in Dropping Webshell (CVE-2023-29298, CVE-2023-29300, and CVE-2023-38203) Qualys ThreatPROTECT · Diksha Ojha
- Patch Adobe ColdFusion zero-days, CISA urges security teams SC Media · Steve Zurier
- Vulnerabilities in Adobe ColdFusion and Citrix NetScaler are under active exploitation Ars OpenForum
Discussion
-
Citrix.com
Citrix.com
on x
Citrix ADC and Citrix Gateway Security Bulletin for CVE-2023-3519, CVE-2023-3466, CVE-2023-3467
-
@pdiscoveryio
@pdiscoveryio
on x
📚 Dive into our new blog analyzing the Adobe ColdFusion Pre-Auth Remote Code Execution vulnerability (CVE-2023-29300). Visit 👉 https://blog.projectdiscovery.io/ ... Also, check out our @pdnuclei template for effective vulnerability detection. #AdobeColdFusion #Cybersecurity #CVEa…
-
@rapid7
@rapid7
on x
⚠ Rapid7 managed services teams have observed exploitation of Adobe ColdFusion in multiple customer environments. Customers should update to the latest version of ColdFusion released July 14, 2023. Read more in our blog ⤵ https://www.rapid7.com/...
-
@raj_samani
Raj Samani
on x
We have observed exploitation of Adobe ColdFusion in multiple customer environments. The attacks our team has responded to thus far appear to be chaining CVE-2023-29298. Further details included mitigation guidance here: https://www.rapid7.com/... #infosec #cybersecurity [image]
-
@keithdsouza
Keith
on x
Lol who still uses coldfusion, the last I had used it was in maybe 1999 or 2000
-
@securityweek
@securityweek
on x
At least two new Adobe ColdFusion vulnerabilities have been exploited in the wild, including one that has not been completely patched by the software giant - https://www.securityweek.com/ ...
-
@stephenfewer
Stephen Fewer
on x
Adobe has patched an access control bypass (CVE-2023-29298) affecting ColdFusion 2023, 2021 and 2018 that we reported last April, found when researching some other CF vulns. Full details on the @rapid7 blog: https://www.rapid7.com/...