CISA warns about security flaws in Adobe and Oracle

Critical deserialization vulnerability (CVE-2017-3066) in Adobe ColdFusion and Oracle Agile PLM, actively exploited according to CISA.

miércoles, 26 de febrero de 2025 • 1 min read • Q2BSTUDIO Team

Company-Software-Apps

The United States Cybersecurity and Infrastructure Security Agency (CISA) has added two security vulnerabilities affecting Adobe ColdFusion and Oracle Agile Product Lifecycle Management (PLM) to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.

The vulnerabilities in question include:

CVE-2017-3066 (CVSS Score: 9.8) - A deserialization vulnerability impacting Adobe ColdFusion versions that allows arbitrary code execution on affected systems.

This type of flaw represents a significant risk for organizations, as attackers can exploit them to compromise systems and access sensitive information. Therefore, it is essential for companies to apply recommended security updates to mitigate risks.

At Q2BSTUDIO, a company specialized in development and technology services, we prioritize security in each of our solutions. Our team of experts continuously works on implementing best cybersecurity practices to ensure the protection of our clients' data and systems. We offer vulnerability assessment, secure development, and IT infrastructure consulting services, supporting companies in preventing digital threats.

Given the increasing sophistication of cyberattacks, having a comprehensive security strategy is essential. At Q2BSTUDIO, we help our clients strengthen their technological infrastructure and reduce risks associated with actively exploited vulnerabilities.

A BREAK?

Play for a moment before you go

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.