Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2808+ Articles
167+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Adobe Patches Three CVSS 10.0 Flaws in ColdFusion and Campaign Classic
Adobe Patches Three CVSS 10.0 Flaws in ColdFusion and Campaign Classic
NEWS

Adobe Patches Three CVSS 10.0 Flaws in ColdFusion and Campaign Classic

Adobe's August 2026 patch cycle fixes 3 maximum-severity RCE vulnerabilities across ColdFusion and Campaign Classic. Priority 1 — patch within 72 hours.

Dylan H.

News Desk

August 13, 2026
4 min read

Overview

Adobe released emergency security updates on August 11, 2026 addressing a cluster of critical vulnerabilities across ColdFusion, Adobe Campaign Classic, and Adobe Commerce. Three vulnerabilities earned the maximum CVSS score of 10.0, with the ColdFusion and Campaign Classic advisories both assigned Priority 1 — Adobe's highest urgency rating, indicating elevated risk of imminent exploitation. Adobe recommends patching within 72 hours.

No active in-the-wild exploitation was confirmed at time of publication, but Priority 1 status signals that exploitation attempts are expected.

ColdFusion — 15 Vulnerabilities, 3 Critical

Adobe patched 15 ColdFusion vulnerabilities in total, with the following critical flaws at the top of the severity stack:

CVETypeCVSSFixed In
CVE-2026-48362OS Command Injection → RCE10.0ColdFusion 2023.0.23, 2025.0.12
CVE-2026-48273Eval Injection → RCE9.9ColdFusion 2023.0.23, 2025.0.12
CVE-2026-71384Incorrect Authorization → DoS9.6ColdFusion 2023.0.23, 2025.0.12

CVE-2026-48362 is the headline flaw: a raw OS command injection vulnerability that allows an unauthenticated remote attacker to execute arbitrary system commands on the underlying server. ColdFusion is commonly used in enterprise backend systems, making this a high-value target for initial access operations.

CVE-2026-48273 uses eval injection — a code execution path through ColdFusion's expression evaluation engine — to achieve equivalent RCE with near-maximal severity (9.9). An attacker who exploits this gains the ability to run arbitrary application server code, access connected databases, and move laterally to resources reachable from the ColdFusion host.

CVE-2026-71384 is a denial-of-service via authorization bypass, rated 9.6 — allowing disruption of customer-facing applications and APIs without code execution.

Campaign Classic — 3 Critical RCE Vulnerabilities

Adobe Campaign Classic (ACC), the on-premises marketing automation platform, received patches for three critical flaws, two of which also score a maximum 10.0:

CVETypeCVSSFixed In
CVE-2026-71398Incorrect Authorization → RCE10.0ACC v7 build 9400
CVE-2026-27302Incorrect Authorization → RCE10.0ACC v7 build 9400
CVE-2026-48381SQL Injection → RCE9.0ACC v7 build 9400

Both CVSS 10.0 flaws are authorization bypass vulnerabilities that lead to arbitrary code execution on the Campaign Classic server — a particularly dangerous combination in environments where the Campaign server has elevated database and network access. CVE-2026-48381 is a SQL injection that escalates to code execution via database stored procedure abuse (the classic xp_cmdshell path in SQL Server environments).

Deployment note: These patches apply exclusively to on-premises and hybrid deployments. Organizations running Campaign Classic on Adobe's cloud infrastructure do not need to act — Adobe patches those instances directly.

Adobe Commerce — High Severity Additions

Adobe also patched Adobe Commerce, though at lower priority:

CVETypeCVSS
CVE-2026-71362Incorrect Authorization → Privilege Escalation9.1

Additional high-severity Commerce vulnerabilities include code execution and security bypass flaws, though full Commerce advisory details are Priority 2.

Patching Context

This bulletin is part of Adobe's new twice-monthly security release cadence (second and fourth Tuesday), announced by Chief Security Officer Aanchal Gupta in July 2026. The cadence is designed to give organizations a more predictable patching schedule while allowing Adobe to ship critical fixes more rapidly.

Priority 1 status for both ColdFusion and Campaign Classic means Adobe has assessed these products as "higher risk of being targeted in the wild." Given that CVSS 10.0 flaws in widely-deployed enterprise products historically attract exploitation within days of patch release — as attackers reverse-engineer the patch to reconstruct the attack surface — organizations should treat the 72-hour recommendation as a hard deadline, not a guideline.

Recommended Actions

  1. Identify exposure immediately — inventory all ColdFusion 2023/2025 and Campaign Classic v7 deployments in your environment
  2. Apply patches within 72 hours:
    • ColdFusion: update to 2023.0.23 or 2025.0.12
    • Campaign Classic: update to v7.4.4 build 9400
  3. For on-premises Campaign Classic: validate that all server components (application, database, and marketing servers) are updated together
  4. Restrict external access to ColdFusion admin interfaces (/CFIDE/administrator/) at the network perimeter while patching proceeds
  5. Review access logs for anomalous POST requests, unusual process spawning, or unexpected outbound connections from ColdFusion or Campaign Classic hosts
  6. Subscribe to Adobe's security notification service to receive Priority 1 alerts as soon as they are issued

References

  • Adobe Security Bulletin — ColdFusion (APSB26-39)
  • Adobe Security Bulletin — Campaign Classic (APSB26-40)
  • The Hacker News — Adobe CVSS 10.0 Patches
  • NVD — CVE-2026-48362
#Adobe#ColdFusion#Campaign Classic#RCE#patch tuesday#critical vulnerability#CVE

Related Articles

Adobe's September 2026 Patch Tuesday Fixes 170+ Flaws Across Experience Manager, ColdFusion & More

Adobe patched over 170 vulnerabilities this cycle, led by 107 in Experience Manager and critical RCEs in ColdFusion and Campaign Classic.

3 min read

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Adobe has patched a maximum-severity vulnerability in Campaign Classic (ACC), its enterprise marketing automation platform. The flaw carries a perfect CVSS score of 10.0 and allows unauthenticated remote code execution with no user interaction required.

4 min read

CVE-2026-47928: Adobe ColdFusion Critical RCE — CVSS 9.6

Adobe ColdFusion 2023.19 and 2025.8 are affected by a critical improper input validation flaw enabling unauthenticated remote code execution with scope change.

2 min read
Back to all News