Hi all,
I got a chance to dig into this more. I did a fresh install of coldfusion 2021 on a new server and had no issues. So I took its JVM config and copied over the java args. At that point, my current server could get past 11.0.10 with no issue. The removed lines ended up being
-Djava.security.manager
-Djava.security.policy={application.home}\\lib\\coldfusion.policy
-Djava.security.auth.policy={application.home}\\lib\\neo_jaas.policy
-Dlog4j2.formatMsgNoLookups=true
We haven't done too much with this server overall. However, we did follow a few guides during the log4j mishaps. I'm guessing these came from this.
Again though, thank you so much for the help and tips. It was a great learning experience.
I had spoken slightly too soon. I reached back out to the client and they said they did need the sandbox security set (the clients local IT added it when putting in content). Ultimately, this issue turned out to be: https://community.adobe.com/t5/coldfusion-discussions/coldfusion-2021-conflict-between-sandbox-security-and-java-11-0-11/m-p/12207456
I applied the workaround provided by Charlie into the jvm.config args -Djdk.lang.Process.allowAmbiguousCommands=true