Skip to main content
Community Manager
September 8, 2026
Blog

NOW LIVE: ColdFusion 2025 and 2023 September 2026 Security Updates

  • September 8, 2026
  • 4 replies
  • 272 views

NOW LIVE — the September 2026 security updates for ColdFusion 2025 and ColdFusion 2023 have been released. The updates resolve critical, important, and moderate vulnerabilities that could lead to arbitrary code execution, arbitrary file system read, privilege escalation, security feature bypass, and memory exposure.

What’s included

The September 2026 release contains:

  • SQL table and stored-procedure identifier validation
  • New SQL validation opt-out flags
  • XSLT collection() and uri-collection() blocked
  • New XSLT compatibility flag
  • AJAX widget HTML input sanitization guidance
  • Configurable deserialization limits
  • Package updates

Download the updates

See the tech notes

Feedback and support

As always, if you encounter issues after updating or need assistance planning your rollout, contact support or reply to this post with details. Your feedback helps us prioritize follow‑up fixes and clarifications.

Thanks,

Team ColdFusion

    4 replies

    Participant
    September 10, 2026

    I'm getting an error after applying CF2023 Update 24. Existing code that worked before Update 24 now breaks. The following code:

    <cfprocparam type = "in" CFSQLType = "CF_SQL_INTEGER" dbvarname = ":theID" value = "#theID#">

    gets the following error:

    The value ":theID" contains invalid characters. Only letters, digits, and the characters _ $ # @ are allowed in a SQL identifier such as a stored procedure name or bind variable name (a dotted procedure name may also contain "."). The value was rejected to prevent SQL injection through the identifier. 

    Anybody else getting errors when using cfprocparam with an Oracle database? The technote shows a cfprocparam example for SQL Server but not Oracle.

    Participant
    September 10, 2026

    I also get this. JVM arguments now in use on non-prod to mitigate this but we have too make many removing them from code practical.

    DevScreen
    Inspiring
    September 9, 2026

    When using CFChart with an external style file, CF can no longer find it after applying the latest patch.  The error returned is:  Could not locate the style file ../includes/css/currency.piegraph.

     

    Current version:  2023,0,24,330957
    Previous version (which still works):  11,0,19,314546
    Server:  Windows Server 2019.

     

    Code:

    <cfchart style="..\includes\css\currency.piegraph" chartwidth="500">

    </cfchart>

     

    I have tried using relative path, absolute path, and also ExpandPath() and made sure the file exists but CF doesn’t like it.  We have other servers not yet updated but they can locate the file just fine.  Please suggest a fix. I created a “bug report” so I am not sure if that will create a post of it’s own.

     

    DevScreen
    Inspiring
    September 9, 2026

    I had posted a bug report which got created as it’s own thread. Apologies for the double post.