
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-64898 is an Insufficiently Protected Credentials vulnerability (CWE-522) in Adobe ColdFusion that could result in limited unauthorized write access. Affected versions include ColdFusion 2021 (through Update 22), 2023 (through Update 16), and 2025 (through Update 4). The vulnerability was disclosed on December 9, 2025, as part of Adobe's APSB25-105 security bulletin. It carries a CVSS v3.1 base score of 5.3 (Medium) per NIST NVD, and 4.3 (Medium) per Adobe's own assessment (Adobe Advisory).
The vulnerability is classified as CWE-522 (Insufficiently Protected Credentials), meaning credentials within Adobe ColdFusion are improperly stored or transmitted, allowing an attacker to leverage them for unauthorized access. The attack vector is network-based, requires no privileges, and no user interaction is needed, making it remotely exploitable without authentication. Successful exploitation results in limited unauthorized write access to the application. No public technical write-ups or proof-of-concept code have been identified at this time (Adobe Advisory).
Exploitation of this vulnerability allows an attacker to gain unauthorized write access to the ColdFusion application by leveraging improperly stored or transmitted credentials. The primary impact is on integrity — an attacker could modify application data — while confidentiality and availability are not directly affected according to the CVSS scoring. The scope is limited to the affected ColdFusion instance, though compromised credentials could potentially be reused for lateral movement within the environment (Adobe Advisory).
Adobe has released patches addressing this vulnerability as part of the December 2025 security update (APSB25-105). Users should update to ColdFusion 2021 Update 23 or later, ColdFusion 2023 Update 17 or later, or ColdFusion 2025 Update 5 or later. Additionally, organizations should review and harden credential storage mechanisms, implement additional authentication controls, and monitor for unauthorized access attempts. Conducting a security audit of credential management practices is also recommended (Adobe Advisory).
The CIS issued an advisory noting multiple vulnerabilities in Adobe products patched in December 2025 that could allow for arbitrary code execution, grouping CVE-2025-64898 among the broader set of ColdFusion issues addressed (CIS Advisory). Sophos covered the December 2025 Patch Tuesday in a blog post highlighting the volume of Adobe fixes released (Sophos Blog). General community reaction has been muted given the moderate severity and lack of public exploitation evidence.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."