A security update for ColdFusion 9 and ColdFusion 10 is released on 12th November 2013. It fixes security issues specified in the this bulletin and tech-note.
If you are on ColdFusion 10, you will see a new update 12 within the ColdFusion administrator. This update includes fix for above mentioned vulnerability as well as few important bug fixes for ColdFusion 10 as specified in the technote here.