CVE-2024-20767Active Exploitation(adobe / coldfusion)

MEDIUMCVSS 7.4 · HIGHCISA KEV

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Prioritize remediation for adobe coldfusion systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could leverage this vulnerability to access or modify restricted files. Exploitation of this issue does not require user interaction. Exploitation of this issue requires the admin panel be exposed to the internet.

5.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-01-06. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-284

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • coldfusion

Threat summary

  • Active exploitation appears in 4 classified signals
  • Public PoC is present in monitored signal
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 4 signals
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 7 signals
  • General: 3 classified signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-05-03); latest day: 1
  • 8 total mentions across 4 days

Affected systems

Vendors
Products
coldfusion

2 versions affected across 1 product

Deep dive

Activity timeline8 mentions / 4d
01234Mentions · 2026-03-30: 2Mentions · 2026-03-31: 1Mentions · 2026-05-03: 4Mentions · 2026-06-01: 1PoC Mentioned / Linked · 2026-05-03: 1Active Exploitation · 2026-05-03: 3Active Exploitation · 2026-06-01: 1Technical Details · 2026-03-30: 2Technical Details · 2026-03-31: 1Technical Details · 2026-05-03: 3Technical Details · 2026-06-01: 103-3003-3105-0306-01
Signal classification3 categories
Active Exploitation
450.0%
General
337.5%
Disclosure
112.5%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-302
Disclosure1General1
2026-03-311
General1
2026-05-034
Active Exploitation3General1
2026-06-011
Active Exploitation1
Full discourse8 posts
  • GoCocoaAI@GoCocoaAI
    Active Exploitation

    The window closed BLUF: The time between vulnerability disclosure and active exploitation is now measured in days, not sprints. Traditional patch cycles were not built for this. 1. Two days is not a cycle The disclosure-to-KEV gap on CVE-2024-1709 (ConnectWise ScreenConnect, CVSS 10. 0, EPSS 99. 96th percentile) was two days. CVE-2024-27198 (JetBrains TeamCity, CVSS 9. 8) was three days. CVE-2024-3094 (XZ Utils supply chain, CVSS 10. 0) was four days. These are not edge cases — they are the new center of the distribution for anything touching remote access, CI/CD pipelines, or widely-deployed enterprise software. Ransomware affiliation is confirmed on three of the four. EPSS flagged near-certain exploitation before CISA added any of them to KEV. The model is now faster than the catalog. 2. The quiet failure mode CVE-2024-20767 (Adobe ColdFusion, CVSS 7. 4, EPSS 99. 90th percentile) took nine months to land in KEV. That is a different failure — medium severity on paper, easy to defer, exploited anyway. Both the fast entries and the slow ones resolve in the same place: unpatched when it mattered. The BleepingComputer piece is circling a structural point the data confirms: scan-triage-ticket-schedule-patch was designed for a world where the exploitation curve ran weeks. That world is gone. Operator take: If CVE-2024-1709 is in your stack, the questions that matter are already overdue — where is it exposed, who owns the patch, what compensating control is live, and what telemetry would prove nobody touched it during the window. The quiet work now is cheaper than the loud paperwork later.

    Post summary

    The article underscores the rapid transition from disclosure to exploitation for several high‑severity CVEs, citing EPSS predictions and ransomware activity, and stresses the need for immediate patching in the face of such swift attacks.

    1000038
    15 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    https://research.lyrie.ai/research/active-exploit-cve-2024-20767-coldfusion #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The link points to research indicating that CVE-2024-20767 in ColdFusion is being actively exploited, but no details about exploitation tools, patches, or technical specifics are provided.

    0001032
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    Why it matters Improper access control on an administrative interface is a straight line to sensitive data and configuration when reachable from the internet NVD CVE-2024-20767. CISA’s KEV inclusion means active exploitation exists, so opportunistic scanning and rapid…

    Post summary

    CISA’s KEV inclusion confirms the CVE‑2024‑20767 vulnerability—improper access control on a remotely reachable admin interface—is actively exploited in the wild.

    1000036
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    NVD tracks CVE‑2024‑20767 with CWE‑284 (Improper Access Control), reinforcing that the core failure is insufficient enforcement of authorization on sensitive resources NVD CVE-2024-20767. The MITRE CVE record mirrors the assignment and coordinates references for consumers…

    Post summary

    The text merely references NVD and MITRE records for CVE‑2024‑20767, noting its CWE classification and authorization flaw, without providing PoC, exploit, patch, or exploitation reports.

    1000034
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CVE-2024-20767: Improper access control in Adobe ColdFusion lets attackers access/modify restricted files via an internet-exposed admin panel. Confirmed KEV.

    Post summary

    Adobe ColdFusion's CVE-2024-20767 involves improper access control that permits attackers to read/modify restricted files via an exposed admin panel, and the vulnerability is confirmed as being actively exploited.

    1000034
    152 followersView on X
  • Patrick Roland@DeusLogica
    General

    🔴 EPSS 94.0% | Almost certainly exploitation | medium confidence CVE-2024-20767 (EPSS 94.00%) ColdFusion versions 2023.6, 2021.12 and earlier affected by Improper Access Control vulnerability that could result in arbitrary file system read. Highest risk of all CVEs by exploitation likelihood Source: http://FIRST.org EPSS | Reliability: B Link: https://nvd.nist.gov/vuln/detail/CVE-2024-20767 #EPSS #threatintel #CVE #cybersecurity

    Post summary

    The post supplies basic technical details about CVE‑2024‑20767, citing a high EPSS exploitation likelihood and a file‑read vulnerability in ColdFusion, but offers no PoC, exploit code, patch information, or evidence of active exploitation.

    1000045
    311 followersView on X
  • Patrick Roland@DeusLogica
    Disclosure

    Timestamp: 2026-03-30T11:11:47.241088 Type: HIGH_EPSS Severity: CRITICAL Confidence: MEDIUM Source Reliability: B Title: CVE-2024-20767 (EPSS 94.00%) ## Draft Post 🔴 EPSS 94.0% | Almost certainly exploitation | medium confidence CVE-2024-20767 (EPSS 94.00%) ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system re Highest risk of all CVEs by exploitation likelihood Source: http://FIRST.org EPSS | Reliability: B Link: https://nvd.nist.gov/vuln/detail/CVE-2024-20767 #EPSS #threatintel #CVE #cybersecurity ## CTI Metadata - Confidence Level: MEDIUM - Source Reliability: B - Calibrated Language: medium confidence

    Post summary

    Announcement of a ColdFusion Improper Access Control vulnerability (CVE‑2024‑20767) with high EPSS, noting potential exploitation but providing no PoC, exploit tool, or patch details.

    1000052
    307 followersView on X
  • Patrick Roland@DeusLogica
    General

    Timestamp: 2026-03-30T11:11:47.241088 Type: HIGH_EPSS Severity: CRITICAL Confidence: MEDIUM Source Reliability: B Title: CVE-2024-20767 (EPSS 94.00%) ## Draft Post 🔴 EPSS 94.0% | Almost certainly exploitation | medium confidence CVE-2024-20767 (EPSS 94.00%) ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system re Highest risk of all CVEs by exploitation likelihood Source: http://FIRST.org EPSS | Reliability: B Link: https://nvd.nist.gov/vuln/detail/CVE-2024-20767 #EPSS #threatintel #CVE #cybersecurity ## CTI Metadata - Confidence Level: MEDIUM - Source Reliability: B - Calibrated Language: medium confidence

    Post summary

    The post highlights a high EPSS score for CVE-2024-20767 and outlines the vulnerability type, yet it provides no proof of exploitation, PoC, or patch information, and does not confirm active exploitation.

    0000051
    307 followersView on X
CPE platform detail20 entries

20 of 20 entries

PartVendorProductVersionTarget SWTarget HW
Appadobecoldfusion2021--
Appadobecoldfusion2021--
Appadobecoldfusion2021--
Appadobecoldfusion2021--
Appadobecoldfusion2021--
Appadobecoldfusion2021--
Appadobecoldfusion2021--
Appadobecoldfusion2021--
Appadobecoldfusion2021--
Appadobecoldfusion2021--
Appadobecoldfusion2021--
Appadobecoldfusion2021--
Appadobecoldfusion2021--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--

Explore more