Adobe Addresses Critical CVE Vulnerabilities in ColdFusion and Campaign Classic

Date:

Adobe has recently issued critical security updates to address several vulnerabilities impacting its products, including ColdFusion, Commerce, and Campaign Classic. These vulnerabilities present serious threats, as they can facilitate arbitrary code execution and privilege escalation if exploited by malicious actors. The urgency for users to apply these updates is underscored by the high Common Vulnerability Scoring System (CVSS) scores assigned to these flaws, with some reaching a maximum score of 10.0.

Overview of the Vulnerabilities

Among the most critical vulnerabilities identified are:

  • CVE-2026-48362 (CVSS score: 10.0): An operating system command injection vulnerability in ColdFusion, which could lead to arbitrary code execution. This flaw has been addressed in versions 2025.0.12 and 2023.0.23.
  • CVE-2026-48273 (CVSS score: 9.9): An eval injection vulnerability in ColdFusion, also allowing for arbitrary code execution, which is fixed in the same updates.
  • CVE-2026-71384 (CVSS score: 9.6): An incorrect authorization vulnerability that could result in application denial-of-service, now patched in 2025.0.12 and 2023.0.23.
  • CVE-2026-71362 (CVSS score: 9.1): An incorrect authorization issue in Commerce that could lead to privilege escalation.
  • CVE-2026-71398 (CVSS score: 10.0): Another incorrect authorization vulnerability in Campaign Classic risk exposing systems to arbitrary code execution, fixed in the scheduled ACC v7 7.4.4 build 9400.
  • CVE-2026-27302 (CVSS score: 10.0): Also pertaining to Campaign Classic, resulting in similar risks, and remediated in the same build.
  • CVE-2026-48381 (CVSS score: 9.0): An SQL injection vulnerability in Campaign Classic, fixed in ACC v7 7.4.4 build 9400.

Severity and Impact

The vulnerabilities associated with ColdFusion and Campaign Classic have been classified as Priority 1, indicating that they pose a significant risk for targeted attacks. It is important to highlight that, as of now, there is no evidence to suggest these vulnerabilities have been exploited in the wild. Nevertheless, cyber security experts strongly recommend that administrators implement the updates within 72 hours to safeguard their systems.

The patches are especially relevant for on-premise deployments of Campaign Classic, while Adobe-hosted environments have already been secured. This highlights the need for users relying on self-hosted solutions to take immediate action.

Previous Updates

This release of patches comes shortly after Adobe’s previous announcement concerning another critical vulnerability in Campaign Classic (CVE-2026-48449, CVSS score: 10.0), indicating a proactive approach on Adobe’s part to enhance security across its product lines. These ongoing updates reflect the evolving threat landscape and the necessity for constant vigilance in applying software updates.

What’s Next

Organizations using ColdFusion or Campaign Classic should prioritize the installation of these updates. Regular audits and updates of security measures are critical to preventing potential exploitation. Keeping abreast of announcements from Adobe and other vendors will further bolster security. With the threat of exploitation always looming, staying updated is not just beneficial but essential.

For additional information on these vulnerabilities and other updates, visit Adobe’s official security advisories. Users can also follow industry news platforms for timely updates on future vulnerabilities, patches, and security best practices.

In conclusion, while immediate action may mitigate risks, organizations should consider adopting a comprehensive approach to cybersecurity that includes regular updates and a robust incident response plan.

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Share post:

spot_imgspot_img

Popular

More like this
Related

Critical PHP Object Injection Vulnerability Found in GiveWP Plugin

A recently discovered vulnerability in the GiveWP plugin poses...

AI Advances Strengthen Cybersecurity: Wordfence Unveils Critical Vulnerability Discovery

Wordfence has revealed significant advancements in its incorporation of...

Critical Unauthenticated Account Takeover Vulnerability Found in TranslatePress Plugin

On August 11, 2026, a significant security vulnerability was...

Hackers Target WordPress Sites in miniOrange Authentication Bypass Attacks

In recent weeks, hackers have escalated their attacks on...