Skip to main content
Inspiring
April 28, 2023
Question

Is there any hope in a new STIG to support newest ColdFusion

  • April 28, 2023
  • 3 replies
  • 965 views

While its vulnerabilities are still mostly relevant towards newer versions of ColdFusion, DISA has now sunset the Adobe ColdFusion 11 STIG as it has not seen an update since 26 Jul 2021. Is there any hope at all for Adobe to work through the vendor STIG process for the newest iterations of the software? 

Reference: https://public.cyber.mil/stigs/downloads/
Reference: https://public.cyber.mil/stigs/vendor-process/

    3 replies

    Inspiring
    August 13, 2024

    I have heard (unofficially) that Adobe is currently working on updating ColdFusion STIG and are targeting Q4 2024 for release.  No info on which version this will cover, but presumably 2021 and/or 2023.

    Inspiring
    May 13, 2025

    This is still unofficial, however my organization received this from our Adobe support contact earlier this year: "We are awaiting review comments from DISA on our final [STIG] submission.  Once 2023 is closed, we can look to get one started for 2025.  Since there are not too many changes in 2025, that should be straightforward in my opinion."

     

    So it sounds like they're targeting CF 2023 for the next STIG publication.  Last update was early-April - team still waiting on DISA review.  Hope that helps!

    Participating Frequently
    May 1, 2023

    Adobe has a history of responding to security vulnerabilities in their products and releasing updates to address them. It's possible that they will work through the vendor STIG process for their newest iterations of ColdFusion, but this would depend on their internal priorities and resources.

    In the meantime, organizations using ColdFusion should continue to follow best practices for securing their systems, including keeping up with security updates and patches, monitoring for potential security threats, and implementing appropriate access controls and other security measures.

    BKBK
    Community Expert
    Community Expert
    April 30, 2023

    You are asking about Adobe working through the vendor STIG process for the newest iterations of which ColdFusion version?  

    Charlie Arehart
    Community Expert
    Community Expert
    April 30, 2023

    Indeed, and I will add that I'd brought this to Adobe's attention directly the other day, and asked them to please offer some answer here. 

    /Charlie (troubleshooter, carehart. org)