These updates address CVE-2025-66516, a Critical XXE in Apache Tika libraries. The following are live as part of this release :
- ColdFusion 2025 Update 6
- ColdFusion 2023 Update 18
- ColdFusion 2025 Add-on installer
Security bulletin for this release - https://helpx.adobe.com/security/products/coldfusion/apsb26-12.html
As a part of this update,
- Docker Images for ColdFusion 2023 and 2025 will be pushed to AWS ECR & Docker Hub by tomorrow
- CFFiddle will be updated with the ColdFusion 2025 Update 6 & ColdFusion 2023 Update 18 by tomorrow