Skip to main content
Community Manager
April 14, 2026
StickyBlog

NOW LIVE! ColdFusion 2025 and 2023 — April 2026 Security Updates

  • April 14, 2026
  • 3 replies
  • 274 views

NOW LIVE — the April 2026 security updates for ColdFusion 2025 and ColdFusion 2023 have been released. This update addresses multiple security issues and includes important mitigations we recommend you apply as soon as possible.

What’s included

The April 2026 release contains:

  • Tomcat upgrades. See the respective tech notes for more details.
  • Security fixes for multiple vulnerabilities (including remote code execution and privilege escalation vectors).
  • Patches to harden request handling, deserialization paths, and template parsing logic.
  • Updates to packages.

Why you should install this update

These fixes close high‑ and critical‑severity vulnerabilities that could be used by attackers to execute code, elevate privileges, or access sensitive data. Applying the update reduces risk to your production and development environments.

Download the updates

See the tech notes

 

Docker and CFFiddle

Feedback and support

As always, if you encounter issues after updating or need assistance planning your rollout, contact support or reply to this post with details. Your feedback helps us prioritize follow‑up fixes and clarifications.

Thanks,

Team ColdFusion

 

    3 replies

    Adobe Employee
    April 24, 2026

    Could you please verify now? The ticket is visible on Tracker.

    Participating Frequently
    April 20, 2026

    Will there be updates to the ColdFusion 2023 docker containers for update 19?

    I seem to still be pulling update 18 and the docker hub says it hasn’t changed in 3 months.

    Thanks

    Community Manager
    April 21, 2026

    Yes, ​@EvanSinceCF31 
    both Docker and CFFiddle are updated.
    i’ve also updated the announcement.

    Participating Frequently
    April 21, 2026

    Thanks for the help Saurav

     

    Does it take a while to get posted or am I looking in the wrong place?

    adobecoldfusion/coldfusion2023 - Docker Image

     

    I see tags 2023.0.10 through 2023.0.18 but no 2023.0.19.  

    For tag latest it says “Last pushed 3 months by suchsing”

     

    Paolo Olocco
    Participating Frequently
    April 15, 2026

    Sorry, but this ticket https://tracker.adobe.com/#/view/CF-4229926 was resolved?

    because it is not mentioned..

    Paolo Olocco
    Participating Frequently
    April 22, 2026

    the ticket disappeared…

    and no one is answering me on this issue

    Community Manager
    April 24, 2026