Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Adobe Patches Critical Apache Tika Bug in ColdFusion

Adobe Patches Critical Apache Tika Bug in ColdFusion

Posted on January 13, 2026January 13, 2026 By CWS

Adobe has launched safety updates for 11 merchandise on January 2026 Patch Tuesday, addressing a complete of 25 vulnerabilities, together with a vital code execution flaw.

The critical-severity difficulty, tracked as CVE-2025-66516 (CVSS rating of 10/10), is an XML Exterior Entity (XXE) injection bug in Apache Tika modules that might be exploited through XFA recordsdata positioned inside PDF paperwork.

The safety defect was patched in early December, when Apache warned that profitable exploitation might result in info leaks, SSRF assaults, denial-of-service (DoS), or distant code execution (RCE).

On Tuesday, Adobe launched a ColdFusion safety replace to resolve CVE-2025-66516, noting that every one ColdFusion 2025 Replace 5 and earlier variations, and ColdFusion 2023 Replace 17 and earlier variations are affected, on all platforms.

The vulnerability was addressed in ColdFusion 2025 Replace 6 and ColdFusion 2023 Replace 18. Adobe has slapped a precedence ranking of ‘1’ on the safety bulletin, urging customers to replace as quickly as doable.

One other Adobe product that acquired an replace on January 2026 Patch Tuesday is Dreamweaver. The safety refresh resolves 5 high-severity flaws, 4 resulting in arbitrary code execution and one resulting in arbitrary system file write.Commercial. Scroll to proceed studying.

Excessive-severity safety defects had been resolved in Bridge, Illustrator, InCopy, InDesign, Substance 3D Modeler, Substance 3D Sampler, Substance 3D Stager, and Substance 3D Painter. For some merchandise, the updates additionally mounted medium-severity bugs.

Adobe additionally launched fixes for a medium-severity vulnerability in Substance 3D Designer, warning it might result in reminiscence leaks.

All of the remaining advisories have a precedence ranking of ‘3’, as the problems had been addressed in merchandise that haven’t been traditionally focused in assaults.

The corporate makes no point out of any of those vulnerabilities being exploited within the wild. Extra info may be discovered on Adobe’s safety advisories web page.

Microsoft on Tuesday patched 112 vulnerabilities, together with a zero-day exploited in assaults.

Associated: Microsoft Patches Exploited Home windows Zero-Day, 111 Different Vulnerabilities

Associated: SAP’s January 2026 Safety Updates Patch Important Vulnerabilities

Associated: Adobe Patches Almost 140 Vulnerabilities

Associated: Cyber Insights 2026: Exterior Assault Floor Administration

Security Week News Tags:Adobe, Apache, Bug, ColdFusion, Critical, Patches, Tika

Post navigation

Previous Post: Microsoft Patches Exploited Windows Zero-Day, 111 Other Vulnerabilities
Next Post: CrowdStrike to Acquire Browser Security Firm Seraphic for $420 Million

Related Posts

Adobe Addresses 80 Security Flaws in Multiple Software Adobe Addresses 80 Security Flaws in Multiple Software Security Week News
SonicWall Patches High-Severity Flaws in Firewalls, Email Security Appliance SonicWall Patches High-Severity Flaws in Firewalls, Email Security Appliance Security Week News
Russian Government Now Actively Managing Cybercrime Groups: Security Firm Russian Government Now Actively Managing Cybercrime Groups: Security Firm Security Week News
Google Launched Behind-the-Scenes Campaign Against California Privacy Legislation; It Passed Anyway Google Launched Behind-the-Scenes Campaign Against California Privacy Legislation; It Passed Anyway Security Week News
Mycroft Raises .5 Million for AI-Powered Security and Compliance Platform Mycroft Raises $3.5 Million for AI-Powered Security and Compliance Platform Security Week News
GreyNoise Flags 9,000 ASUS Routers Backdoored Via Patched Vulnerability GreyNoise Flags 9,000 ASUS Routers Backdoored Via Patched Vulnerability Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • F-Droid 2.0 Debuts with Major Redesign for App Discovery
  • China and US to Create AI Safety Channel Amid Ongoing Talks
  • Lunex Stealer Exploits AMD Driver for Credential Theft
  • Local AI Model Evades EDR Detection with Modified Credential Dumper
  • Enhancing AI Agent Security with Zero Trust Principles

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • F-Droid 2.0 Debuts with Major Redesign for App Discovery
  • China and US to Create AI Safety Channel Amid Ongoing Talks
  • Lunex Stealer Exploits AMD Driver for Credential Theft
  • Local AI Model Evades EDR Detection with Modified Credential Dumper
  • Enhancing AI Agent Security with Zero Trust Principles

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark