CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Adobe Patches Critical ColdFusion and Campaign Classic Flaws with Multiple CVSS 10.0 Ratings

August 12, 2026

Adobe has released security updates addressing multiple critical vulnerabilities in ColdFusion, Commerce, and Campaign Classic. The most severe include three CVSS 10.0 flaws that could lead to arbitrary code execution and privilege escalation.

Key vulnerabilities patched:

  • CVE-2026-48362 (CVSS 10.0) – OS command injection in ColdFusion leading to arbitrary code execution. Fixed in ColdFusion 2025.0.12 and 2023.0.23.
  • CVE-2026-48273 (CVSS 9.9) – Eval injection in ColdFusion leading to arbitrary code execution. Fixed in the same versions.
  • CVE-2026-71384 (CVSS 9.6) – Incorrect authorization in ColdFusion causing denial-of-service. Fixed in the same versions.
  • CVE-2026-71362 (CVSS 9.1) – Incorrect authorization in Commerce leading to privilege escalation.
  • CVE-2026-71398 and CVE-2026-27302 (both CVSS 10.0) – Incorrect authorization in Campaign Classic leading to arbitrary code execution. Fixed in ACC v7 7.4.4 build 9400.
  • CVE-2026-48381 (CVSS 9.0) – SQL injection in Campaign Classic leading to arbitrary code execution. Fixed in ACC v7 7.4.4 build 9400.

The updates for ColdFusion and Campaign Classic carry a Priority 1 rating, indicating a higher risk of exploitation. Campaign Classic patches apply only to fully on-premise deployments and on-premise components of hybrid setups; Adobe-hosted instances are already remediated. While no in-the-wild exploitation has been observed, administrators are urged to apply patches within 72 hours. This follows a prior maximum-severity Campaign Classic flaw (CVE-2026-48449, CVSS 10.0) patched less than two weeks earlier.

CVEs: CVE-2026-48362, CVE-2026-48273, CVE-2026-71384, CVE-2026-71362, CVE-2026-71398, CVE-2026-27302, CVE-2026-48381, CVE-2026-48449

Companies: Adobe

Products: ColdFusion, Campaign Classic, Commerce