NOW LIVE! ColdFusion 2025 and 2023 security updates- January 2026
We are pleased to inform you that we've released security updates for ColdFusion 2025 and 2023 releases. For more information, see the respective tech notes:
What's new and changed
The releases address CVE-2025-66516, a critical XXE in Apache Tika libraries. Adobe strongly recommends that you apply this update as soon as possible. Note that this update is cumulative and includes fixes from previous updates.
This update upgrades the embedded Apache Tika libraries, providing the latest security and stability enhancements, while preserving existing application behavior.
View the tech notes, and the security bulletin, APSB26-12, for more information.
Download the updates
Docker and CFFiddle
- CFFiddle is now updated with the changes
- The Docker images are also updated:
Please download and apply the updates and provide your feedback.

