Adobe has recently issued critical security updates to address several vulnerabilities impacting its products, including ColdFusion, Commerce, and Campaign Classic. These vulnerabilities present serious threats, as they can facilitate arbitrary code execution and privilege escalation if exploited by malicious actors. The urgency for users to apply these updates is underscored by the high Common Vulnerability Scoring System (CVSS) scores assigned to these flaws, with some reaching a maximum score of 10.0.
Overview of the Vulnerabilities
Among the most critical vulnerabilities identified are:
- CVE-2026-48362 (CVSS score: 10.0): An operating system command injection vulnerability in ColdFusion, which could lead to arbitrary code execution. This flaw has been addressed in versions 2025.0.12 and 2023.0.23.
- CVE-2026-48273 (CVSS score: 9.9): An eval injection vulnerability in ColdFusion, also allowing for arbitrary code execution, which is fixed in the same updates.
- CVE-2026-71384 (CVSS score: 9.6): An incorrect authorization vulnerability that could result in application denial-of-service, now patched in 2025.0.12 and 2023.0.23.
- CVE-2026-71362 (CVSS score: 9.1): An incorrect authorization issue in Commerce that could lead to privilege escalation.
- CVE-2026-71398 (CVSS score: 10.0): Another incorrect authorization vulnerability in Campaign Classic risk exposing systems to arbitrary code execution, fixed in the scheduled ACC v7 7.4.4 build 9400.
- CVE-2026-27302 (CVSS score: 10.0): Also pertaining to Campaign Classic, resulting in similar risks, and remediated in the same build.
- CVE-2026-48381 (CVSS score: 9.0): An SQL injection vulnerability in Campaign Classic, fixed in ACC v7 7.4.4 build 9400.
Severity and Impact
The vulnerabilities associated with ColdFusion and Campaign Classic have been classified as Priority 1, indicating that they pose a significant risk for targeted attacks. It is important to highlight that, as of now, there is no evidence to suggest these vulnerabilities have been exploited in the wild. Nevertheless, cyber security experts strongly recommend that administrators implement the updates within 72 hours to safeguard their systems.
The patches are especially relevant for on-premise deployments of Campaign Classic, while Adobe-hosted environments have already been secured. This highlights the need for users relying on self-hosted solutions to take immediate action.
Previous Updates
This release of patches comes shortly after Adobe’s previous announcement concerning another critical vulnerability in Campaign Classic (CVE-2026-48449, CVSS score: 10.0), indicating a proactive approach on Adobe’s part to enhance security across its product lines. These ongoing updates reflect the evolving threat landscape and the necessity for constant vigilance in applying software updates.
What’s Next
Organizations using ColdFusion or Campaign Classic should prioritize the installation of these updates. Regular audits and updates of security measures are critical to preventing potential exploitation. Keeping abreast of announcements from Adobe and other vendors will further bolster security. With the threat of exploitation always looming, staying updated is not just beneficial but essential.
For additional information on these vulnerabilities and other updates, visit Adobe’s official security advisories. Users can also follow industry news platforms for timely updates on future vulnerabilities, patches, and security best practices.
In conclusion, while immediate action may mitigate risks, organizations should consider adopting a comprehensive approach to cybersecurity that includes regular updates and a robust incident response plan.
