The official community for ColdFusion.
Recently active
NOW LIVE — the June 2026 security updates for ColdFusion 2025 and ColdFusion 2023 have been released. This update includes important security fixes that mitigate vulnerabilities related to arbitrary code execution, arbitrary file write, information disclosure, stored cross-site scripting, and security feature bypass. What’s includedThe June 2026 release contains:Tomcat upgrades. See the respective tech notes for more details. Security fixes for multiple vulnerabilities (including remote code execution and privilege escalation vectors). Patches to harden request handling, deserialization paths, and template parsing logic. Updates to packages.Why you should install this updateThese fixes close high‑ and critical‑severity vulnerabilities that could be used by attackers to execute code, elevate privileges, or access sensitive data. Applying the update reduces risk to your production and development environments.Download the updatesColdFusion 2025 updates ColdFusion 2023 updatesSee the tech
NOW LIVE — the April 2026 security updates for ColdFusion 2025 and ColdFusion 2023 have been released. This update addresses multiple security issues and includes important mitigations we recommend you apply as soon as possible.What’s includedThe April 2026 release contains:Tomcat upgrades. See the respective tech notes for more details. Security fixes for multiple vulnerabilities (including remote code execution and privilege escalation vectors). Patches to harden request handling, deserialization paths, and template parsing logic. Updates to packages.Why you should install this updateThese fixes close high‑ and critical‑severity vulnerabilities that could be used by attackers to execute code, elevate privileges, or access sensitive data. Applying the update reduces risk to your production and development environments.Download the updatesColdFusion 2025 updates ColdFusion 2023 updatesSee the tech notesColdFusion (2025 release) Update 7 ColdFusion (2023 release) Update 19 Docker and CF
We are pleased to announce the availability of ColdFusion Builder Extension for Visual Studio Code. Needless to say, we are as excited as you are to release this plugin. Now you'll be able to edit and validate code, manage files, projects, and servers, debug, and scan for security vulnerabilities, directly on Visual Studio Code. What's in it for me A lot, actually. The all-new Adobe ColdFusion Builder extension for VS Code helps developers to edit and validate code, manage files and projects, and debug and scan for security vulnerabilities. Why do I need this extension? Integrate the Adobe ColdFusion Builder Extension on your VS Code to: Automate repetitive tasks and navigate code for a smoother and faster process. Enjoy built-in support for IntelliSense code completion, better semantic code understanding, and code refactoring. Identify security vulnerabilities and maintain the integrity of your code. Manage your work with extensions, remote project support, inte
Does anyone know what is the best way to run coldfusion2023/config/cfsetup/cfsetup.sh unattended without being prompted for a password (su <runtime_user>)? If I modify the script and remove “su” it runs fine but not sure about security implications.We are running on Ubuntu 24, with stand alone CF2023 servers. Looking to updated/add datasources programmatically using the gitlab pipeline and cfsetup.sh
We’re excited to announce the availability of Adobe ColdFusion (2023 Release) Update 25, a significant update focused on platform modernization, developer productivity, improved compatibility, and important bug fixes across the server, Administrator, packages, and integrations.The update also includes extensive OEM library upgrades, Query-of-Queries enhancements, metadata handling improvements, spread operator fixes, and updates to several ColdFusion packages.Download the update View the tech note Release highlightsOEM upgradesOne of the biggest highlights in this release is the update of numerous underlying libraries and frameworks that power ColdFusion. Update 25 includes major upgrades to components such as:Apache Maven 3.9.16 Log4j 2.25.4 Jetty 9.4.58 jQuery 3.7.1 Apache Tika 2.9.4 Commons libraries Netty components CXF services frameworkThese upgrades help improve compatibility, stability, maintainability, and overall platform security.Query-of-Queries EnhancementsDevelopers who r
I installed the update 25 for CF2023 manually. We always install updates on our dev server first which is running CF2023 developer. The update UI didn’t show any issues. After the update some of the packages were removed including cfadmin. Thankfully visiting cfadmin link showed me how to install it from cfpm.bat. I was able to install cfadmin and then from it install the rest of the missing packages.The update log does show timeouts on downloading some packages but the status on this entry is still shown as Successful after the errors.Did someone encounter this issue ? Environment: CF2023 developer on Windows Server 2019 Log entry related to packages:Downloading the package axis-2023.0.25.330977.jarRead timed outDownloading the dependent package sharepoint-2023.0.25.330977.jarRead timed outDownloading the package adminapi-2023.0.25.330977.jarDownloading the package adminapi-2023.0.25.330977.zipRead timed outDownloading the package administrator-2023.0.25.330977.jarDownloading the pack
Server Product ColdFusion 2021Version 2021,0,23,330486Operating System Windows Server 2019; IISWe are looking at upgrading from CF 2021 to CF 2023 and one of the first steps O have is to remove the IIS connectors via the wsconfig (ben a while since the last upgrade form CF 2016 o CF 2021, so fuzzy). We have two separate systems, a dev and a production, This is all on dev. but i get the same behavior on both instances. I made sure that Visual C++ Redistributable for Visual Studio was installed (it was, but I updated/repaired just in case). I run wsconfig As Administrator (via Explorer or CMD. I just do not get anything to pull down to remove. These instances have been moved since the CF 2016 > CF2021 upgrade, when we migrated rom Windows 2012 to Windows 2019. I am presuming the issue lies there, but not sure how to go about correcting, and do not want o just take too many guesses as we will have to repeat for production.
Let's say the perfect CF developer job exists. It offers fair pay, flexible hours, and fun work. Let's say that job is snagged by an ideal candidate. All seems alright.Then they see the codebase and lack of improvement roadmap. Their eyes go wide like Gollum's. And poof, they're gone. All the pay in the world won't bring them back.An old CF app tells a story. Tidy folders, useful comments, tests, source control, and clear steps all say, "People care." A jungle of copied code, mystery files, and manual steps says, "Fly, you fools!"👉 Need more CF development help? Explore TeraTech’s ColdFusion development services. We help teams care for old CF apps, clean up messy code, and add skilled CF developers. Developers are interviewing your appGood developers know old apps come with baggage. No one expects a 15-year-old CF app to look brand new. But they do want to see that your team can make it better.Think about two CF jobs with the same pay. The first app has source control, a working loc
First of all, I have no coldfusion experience at all. So when answering or asking for coldfusion specifics, please try to keep your answer/question somewhat lightweight :)I’m trying to setup a minimal cfusion2025 image that runs on openshift. I currently have some issues with the image’s existing cfuser or the pod’s permissions.Dockerfile:FROM adobecoldfusion/coldfusion2025:latestUSER rootCOPY ./sources /appEXPOSE 8080 8500Pod logs:Skipping Configuration and Setting Wizardsed: couldn't open temporary file /opt/coldfusion/cfusion/lib/sedFCBEbg: Permission deniedsed: couldn't open temporary file /opt/coldfusion/cfusion/lib/sedMKjs1Y: Permission deniedUpdating webroot to /appConfiguring virtual directorieschown: changing ownership of '/app': Operation not permitted (os error 1)chown: changing ownership of '/app/index.cfm': Operation not permittedchown: changing ownership of '/app/test': Operation not permittedchown: changing ownership of '/app/test/cfm': Operation not permittedchown: chan
Photoshop version:27.9.1Steps to reproduce:Open a PSD/document. Place an image and convert it to a Smart Object. Use Free Transform to scale the Smart Object down. Press Ctrl+T again. Choose Distort. Move the four corner handles to create a trapezoid/perspective shape. Press Enter to commit the transformation. The transformed object itself remains in the correct position. However, the Transform bounding box/handles immediately jump to the upper-left corner of the document, completely away from the object. Pressing Ctrl+T temporarily puts the bounding box back around the object, but after pressing Enter it jumps to the upper-left corner again.Expected result:The Transform bounding box should remain around the transformed Smart Object.Actual result:After committing a Distort transformation, the bounding box and transform handles jump to the upper-left corner of the document and no longer correspond to the transformed object's position or dimensions.Additional information:The problem does
On the ColdFusion Downloads Page (https://guides.adobe.com/coldfusion/en/docs/install-and-configure-coldfusion/coldfusion-downloads.html), the Java updates section is behind by weeks. The most up-to-date Java listed for CF 2023 is 17.0.20, which had a significant security issue and caused version 17.0.20.1 to be released on Aug 18, 2026. It is now 31 days later and the update has not been posted on your page yet, please help us avoid additional conversations with our security folks and post those soon!Screenshot of downloads page Java versions on 9/21/2026:Java Releases:
Hello, automated emails sent by our ColdFusion Application (Sunapsis) are failing to reach our users. Our MS Stack team suggested implementing a service account in order to meet higher authentication requirements. Has someone done this in ColdFusion?Also, is it possible we will need to setup an Azure App for OAuth authentication? If so, what documentation does Adobe have for configuring CF 2023 to use the app, client, secret, etc.?Thank you!
Have you listened to the new episode 142 of CF Alive is out? Charlie Arehart joins me to talk about moving to ColdFusion 2025 (and the sneaky Update 8, aka ColdFusion 2026).Charlie always finds hidden gems in every release!This time we dug into:1) The new AI, MCP, and RAG stuff everyone's talking about (plus what's easy to miss past the AI headlines).2) Subscription-only licensing now. What that really costs your budget over 5 years vs old model.3) The longest "removed features" list Charlie's ever seen. If one old tag is holding your app together, you'll want to hear this.4) HTTPS on CF Admin is easy to turn on now. What Charlie still finds broken out in the field.5) Under the hood, Java 21 and Tomcat 10.1 landed together.If you're planning an upgrade from CF2018 or CF2021, don't walk into Mordor without a map. This episode is your map!See the full episode + show notes.
I'm curious if anyone testing out cf2025, that uses CKeditor has figured out what to do about the out of date messages that it produces when using ckeditor? I will probably just convert them all to regular text areas, its just pretty annoying how its not up to date with cf2025. I'm running a development box using the development version.
Hello Team,These days I am facing weird issue with bulk emails delievery in my application. For example, if I am sending around 300 emails via cfmail tag, sometimes these all emails will go fine and sometimes some emails will stuck in my undelievered emails folder.I end up sending these emails manually, sometimes it gets really bad when undelievered emails goes upto 2000. Through error logs, I am able to see below error:Nov 17, 2023 07:05:09 AM Error [mailWorker-9] - com.sun.mail.smtp.SMTPSendFailedException: 451 4.7.500 Access denied, please try again later. Which is really weird, because rest all successfully delievered emails are sent via same server/using same credentials. Not sure, why it starts saying "Access denied" all of a sudden.Looking forward to hear some possible solutions from community. Please feel free to comment in case you faced similar issue in your application.Thanks,Dhanshree Joshi
implementing CF23 update 24 where it seems to be complaining about the colon in the dbvarname. The procedure name is just PACKAGE.PROCEDURE_NAME I don't see the cause of the problem. Actual error: The value ":v_session_id" contains invalid characters. <cfprocparam dbvarname=":v_session_id" value="#functionHere()#" type="IN" cfsqltype="cf_sql_varchar">
Has anyone else experienced problems implementing CF23 update 24 where it seems to be complaining about the colon in the dbvarname. The procedure name is just PACKAGE.PROCEDURE_NAME I don't see the cause of the problem. Actual error: The value ":v_session_id" contains invalid characters. cfprocparam dbvarname=":v_session_id" value="#functionHere()#" type="IN" cfsqltype="cf_sql_varchar"
When using CFChart with an external style file, CF can no longer find it after applying the latest patch. The error returned is: Could not locate the style file ../includes/css/currency.piegraph. Current version: 2023,0,24,330957Previous version (which still works): 11,0,19,314546Server: Windows Server 2019. Code:<cfchart style="..\includes\css\currency.piegraph" chartwidth="500"></cfchart> I have tried using relative path, absolute path, and also ExpandPath() and made sure the file exists but CF doesn’t like it. We have other servers not yet updated but they can locate the file just fine. Please suggest a fix.
NOW LIVE — the September 2026 security updates for ColdFusion 2025 and ColdFusion 2023 have been released. The updates resolve critical, important, and moderate vulnerabilities that could lead to arbitrary code execution, arbitrary file system read, privilege escalation, security feature bypass, and memory exposure.What’s includedThe September 2026 release contains:SQL table and stored-procedure identifier validation New SQL validation opt-out flags XSLT collection() and uri-collection() blocked New XSLT compatibility flag AJAX widget HTML input sanitization guidance Configurable deserialization limits Package updatesDownload the updatesColdFusion 2025 updates ColdFusion 2023 updatesSee the tech notesColdFusion (2025 release) Update 13 ColdFusion (2023 release) Update 24Feedback and supportAs always, if you encounter issues after updating or need assistance planning your rollout, contact support or reply to this post with details. Your feedback helps us prioritize follow‑up fixes and c
Adobe has released ColdFusion 2025 Update 12 and ColdFusion 2023 Update 23. The releases resolve critical, important, and moderate vulnerabilities that could lead to arbitrary code execution, arbitrary file system read, privilege escalation, security feature bypass, and memory exposure.View the security bulletin, APSB26-90, for more information.Download the updatesColdFusion 2025 updates ColdFusion 2023 updatesWhat’s newNew JVM flag-Dcoldfusion.xml.saxon.allowCollection -Dcoldfusion.debugger.bindhost -Dcoldfusion.websocket.requireAuthForInvokeFor more details, view:JVM arguments in CF 2025 JVM arguments in CF 2023New Application.cfc flagthis.wsRequireAuthForInvokeThis flag controls whether a WebSocket client must be authenticated before it can invoke access="remote" CFC methods over the channel. By default, its value is True.For more details, view Application variables in ColdFusion.Tomcat upgradeTomcat 10.1.57 in CF 2025.12 Tomcat 9.0.120.0 in CF 2023.23New config file propertyccssecr
Website was working fine with hotfix 22.
<cfxml variable="xmlObject" casesensitive="yes"><gallery><album title="Product Detail"><cfoutput query="rsImageFiles"><img src = " http://www.bloodtest.in/Images/Products/#rsImageFiles.Name#" caption = "Flat View" /></cfoutput></album></gallery></cfxml>creates this xml file:<?xml version="1.0" encoding="UTF-8"?><gallery><album title="Product Detail"><img caption="Flat View" src=" http://www.bloodtest.in/Images/Products/B1004Back.jpg"/><img caption="Flat View" src=" http://www.bloodtest.in/Images/Products/B1004Full.jpg"/><img caption="Flat View" src=" http://www.bloodtest.in/Images/Products/B1004Main.jpg"/><img caption="Flat View" src=" http://www.bloodtest.in/Images/Products/B1004Thumb.jpg"/></album></gallery>The elements 'src' and 'caption' have been rearranged. Any way to avoid this?
Hi,I recently downloaded and installed the version ColdFusion 2025 trial edition using GUI installer.After the installation,I was able to access the ColdFusion Administrator page successfully.However,I do not see the start/stop option for the ColdFusion Application Service in the windows Services console. So, I am unable to restart the service.Could you please advise how to enable or access the ColdFusion service? Thank you
Hi Support team, I am working on a project in ColdFusion version 2023. Looking to setup the project in dev environment, but it seems the developer/trial version for 2023 link is not activeon the website url below. Can see only latest version 2025 for download.https://guides.adobe.com/coldfusion/en/docs/install-and-configure-coldfusion/coldfusion-downloads.htmlPlease share the link to download the developer edition for 2023. Thanks
If you have schedule tasks that use CRONtime it would be nice to see that reflected in the Settings Summary.
Remix with Firefly Community Gallery
Thousands of free creations to fall in love with and remix in Firefly.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.