peter bassill · operator
$ cve CVE-2018-4939 JSON

CVE-2018-4939 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 61.7% (pctl 99)

Patch first

On CISA KEV — known exploited in the wild, due 2022-05-03.

Description

Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Deserialization of Untrusted Data vulnerability. Successful exploitation could lead to arbitrary code execution.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS61.67% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-502
On CISA KEVyes — remediate by 2022-05-03
Public exploitnone known
Published2018-05-19
Last modified2026-06-17

CISA KEV

NameAdobe ColdFusion Deserialization of Untrusted Data Vulnerability
Added2021-11-03
Due2022-05-03
Vendor / productAdobe / ColdFusion
Ransomware usenone reported

Affected (1)

VendorProduct
adobecoldfusion

References

→ the Explorer  ·  watch your stack  ·  NVD