The United States Cybersecurity and Infrastructure Security Agency (CISA) has added two security vulnerabilities affecting Adobe ColdFusion and Oracle Agile Product Lifecycle Management (PLM) to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.
The vulnerabilities in question include:
CVE-2017-3066 (CVSS Score: 9.8) - A deserialization vulnerability impacting Adobe ColdFusion versions that allows arbitrary code execution on affected systems.
This type of flaw represents a significant risk for organizations, as attackers can exploit them to compromise systems and access sensitive information. Therefore, it is essential for companies to apply recommended security updates to mitigate risks.
At Q2BSTUDIO, a company specialized in development and technology services, we prioritize security in each of our solutions. Our team of experts continuously works on implementing best cybersecurity practices to ensure the protection of our clients' data and systems. We offer vulnerability assessment, secure development, and IT infrastructure consulting services, supporting companies in preventing digital threats.
Given the increasing sophistication of cyberattacks, having a comprehensive security strategy is essential. At Q2BSTUDIO, we help our clients strengthen their technological infrastructure and reduce risks associated with actively exploited vulnerabilities.





