Unscheduled patch for Adobe ColdFusion fixes RCE vulnerability
Adobe has released an emergency update to address a critical vulnerability affecting ColdFusion versions 2021 (including 2021.0.0.323925), 2016 and 2018.
The problem received the ID CVE-2021-21087 and is related to Improper Input Validation. Exploitation of this issue could lead to remote arbitrary code execution.
Source: xakep.ru
24 March 2021