Skip to main content
CybersecurityVulnerability Management

Adobe Fixes Zero-Day Flaws in ColdFusion, Campaign Classic

Modern office interior with a blank laptop screen on a desk surrounded by neutral-colored furniture.

CVE-2026-48362 (CVSS score: 10.0) is among the critical vulnerabilities Adobe has patched across ColdFusion, Commerce and Campaign Classic — flaws that, according to the advisory, could allow arbitrary code execution or privilege escalation if left unaddressed.

CVE list and immediate risks

Adobe’s advisory enumerates multiple high-severity vulnerabilities and the specific impacts tied to each CVE. The most severe call out operating system command injection and eval injection in ColdFusion (CVE-2026-48362, CVE-2026-48273 — both rated at the top of the scale), and multiple incorrect-authorization and injection flaws in Campaign Classic (including CVE-2026-71398 and CVE-2026-27302, both CVSS 10.0). Other notable entries include:

  • CVE-2026-71384 (CVSS 9.6) — an incorrect authorization issue in ColdFusion that could lead to an application denial-of-service.
  • CVE-2026-71362 (CVSS 9.1) — an incorrect authorization vulnerability in Commerce with potential for privilege escalation.
  • CVE-2026-48381 (CVSS 9.0) — an SQL injection in Campaign Classic that could result in arbitrary code execution.

Adobe characterizes the ColdFusion and Campaign Classic updates as Priority 1, which the advisory defines as vulnerabilities that have a higher risk of being targeted by malicious cyber attacks.

What was fixed and where — ColdFusion, Campaign Classic, Commerce

The advisory lists the exact builds and releases that contain fixes. ColdFusion issues were fixed in two releases: 2025.0.12 and 2023.0.23. Campaign Classic remediation is included in ACC v7 7.4.4 build 9400. The Commerce vulnerability (CVE-2026-71362) is identified as presenting privilege-escalation risk, and is included among the updates Adobe shipped.

On‑premise vs. Adobe-hosted: who must act

The Campaign Classic fixes apply only to fully on‑premise deployments and the on‑premise components of hybrid deployments; Adobe-hosted Campaign Classic instances have already been remediated and, per the advisory, require no customer action. Administrators of on‑premise and hybrid on‑premise components therefore hold the responsibility to deploy the ACC v7 7.4.4 build 9400 update. ColdFusion administrators must apply the 2025.0.12 or 2023.0.23 updates as appropriate for their installations. The advisory notes there is no evidence these flaws are being exploited in the wild, but recommends installing the updates as soon as possible — preferably within 72 hours.

What this means for ColdFusion administrators, Campaign Classic on‑premise operators, and Adobe‑hosted customers

  • ColdFusion administrators: prioritize applying the 2025.0.12 or 2023.0.23 updates to mitigate command‑injection and eval‑injection vectors (CVE-2026-48362 and CVE-2026-48273) and the incorrect‑authorization bug that could enable denial‑of‑service (CVE-2026-71384).
  • Campaign Classic on‑premise operators: deploy ACC v7 7.4.4 build 9400 to address multiple critical issues — including CVE-2026-71398 and CVE-2026-27302 (both CVSS 10.0) and CVE-2026-48381 (SQL injection) — keeping in mind the advisory’s Priority 1 rating and 72‑hour preference for patching.
  • Adobe‑hosted customers: according to Adobe, no action is required; hosted Campaign Classic instances have already been remediated.

Context and near‑term implications

The advisory arrives less than two weeks after Adobe issued patches for another maximum‑severity Campaign Classic flaw, CVE-2026-48449 (CVSS 10.0). While Adobe reports no current evidence of exploitation, the combination of multiple CVSS 10.0 defects and the Priority 1 designation increases the urgency for affected administrators to move quickly. The concrete remediation windows and fixed build numbers give operators a clear checklist: install the specified ColdFusion releases or the ACC v7 7.4.4 build 9400, and treat Commerce updates addressing CVE-2026-71362 as high priority.

Practical questions remain for operators balancing change windows and risk: can organizations complete the recommended 72‑hour patching cycle without disrupting critical services, and will hybrid customers correctly identify and update only the on‑premise components that require action? Adobe’s advisory supplies the technical fixes and an urgent timeframe; the onus now falls to administrators to implement them.

Read the original advisory: https://thehackernews.com/2026/08/adobe-patches-three-cvss-100-coldfusion.html