Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2368+ Articles
158+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Adobe Patches Three CVSS 10.0 Flaws in ColdFusion and Campaign Classic
Adobe Patches Three CVSS 10.0 Flaws in ColdFusion and Campaign Classic
NEWS

Adobe Patches Three CVSS 10.0 Flaws in ColdFusion and Campaign Classic

Adobe's August 2026 patch cycle fixes 3 maximum-severity RCE vulnerabilities across ColdFusion and Campaign Classic. Priority 1 — patch within 72 hours.

Dylan H.

News Desk

August 13, 2026
4 min read

Overview

Adobe released emergency security updates on August 11, 2026 addressing a cluster of critical vulnerabilities across ColdFusion, Adobe Campaign Classic, and Adobe Commerce. Three vulnerabilities earned the maximum CVSS score of 10.0, with the ColdFusion and Campaign Classic advisories both assigned Priority 1 — Adobe's highest urgency rating, indicating elevated risk of imminent exploitation. Adobe recommends patching within 72 hours.

No active in-the-wild exploitation was confirmed at time of publication, but Priority 1 status signals that exploitation attempts are expected.

ColdFusion — 15 Vulnerabilities, 3 Critical

Adobe patched 15 ColdFusion vulnerabilities in total, with the following critical flaws at the top of the severity stack:

CVETypeCVSSFixed In
CVE-2026-48362OS Command Injection → RCE10.0ColdFusion 2023.0.23, 2025.0.12
CVE-2026-48273Eval Injection → RCE9.9ColdFusion 2023.0.23, 2025.0.12
CVE-2026-71384Incorrect Authorization → DoS9.6ColdFusion 2023.0.23, 2025.0.12

CVE-2026-48362 is the headline flaw: a raw OS command injection vulnerability that allows an unauthenticated remote attacker to execute arbitrary system commands on the underlying server. ColdFusion is commonly used in enterprise backend systems, making this a high-value target for initial access operations.

CVE-2026-48273 uses eval injection — a code execution path through ColdFusion's expression evaluation engine — to achieve equivalent RCE with near-maximal severity (9.9). An attacker who exploits this gains the ability to run arbitrary application server code, access connected databases, and move laterally to resources reachable from the ColdFusion host.

CVE-2026-71384 is a denial-of-service via authorization bypass, rated 9.6 — allowing disruption of customer-facing applications and APIs without code execution.

Campaign Classic — 3 Critical RCE Vulnerabilities

Adobe Campaign Classic (ACC), the on-premises marketing automation platform, received patches for three critical flaws, two of which also score a maximum 10.0:

CVETypeCVSSFixed In
CVE-2026-71398Incorrect Authorization → RCE10.0ACC v7 build 9400
CVE-2026-27302Incorrect Authorization → RCE10.0ACC v7 build 9400
CVE-2026-48381SQL Injection → RCE9.0ACC v7 build 9400

Both CVSS 10.0 flaws are authorization bypass vulnerabilities that lead to arbitrary code execution on the Campaign Classic server — a particularly dangerous combination in environments where the Campaign server has elevated database and network access. CVE-2026-48381 is a SQL injection that escalates to code execution via database stored procedure abuse (the classic xp_cmdshell path in SQL Server environments).

Deployment note: These patches apply exclusively to on-premises and hybrid deployments. Organizations running Campaign Classic on Adobe's cloud infrastructure do not need to act — Adobe patches those instances directly.

Adobe Commerce — High Severity Additions

Adobe also patched Adobe Commerce, though at lower priority:

CVETypeCVSS
CVE-2026-71362Incorrect Authorization → Privilege Escalation9.1

Additional high-severity Commerce vulnerabilities include code execution and security bypass flaws, though full Commerce advisory details are Priority 2.

Patching Context

This bulletin is part of Adobe's new twice-monthly security release cadence (second and fourth Tuesday), announced by Chief Security Officer Aanchal Gupta in July 2026. The cadence is designed to give organizations a more predictable patching schedule while allowing Adobe to ship critical fixes more rapidly.

Priority 1 status for both ColdFusion and Campaign Classic means Adobe has assessed these products as "higher risk of being targeted in the wild." Given that CVSS 10.0 flaws in widely-deployed enterprise products historically attract exploitation within days of patch release — as attackers reverse-engineer the patch to reconstruct the attack surface — organizations should treat the 72-hour recommendation as a hard deadline, not a guideline.

Recommended Actions

  1. Identify exposure immediately — inventory all ColdFusion 2023/2025 and Campaign Classic v7 deployments in your environment
  2. Apply patches within 72 hours:
    • ColdFusion: update to 2023.0.23 or 2025.0.12
    • Campaign Classic: update to v7.4.4 build 9400
  3. For on-premises Campaign Classic: validate that all server components (application, database, and marketing servers) are updated together
  4. Restrict external access to ColdFusion admin interfaces (/CFIDE/administrator/) at the network perimeter while patching proceeds
  5. Review access logs for anomalous POST requests, unusual process spawning, or unexpected outbound connections from ColdFusion or Campaign Classic hosts
  6. Subscribe to Adobe's security notification service to receive Priority 1 alerts as soon as they are issued

References

  • Adobe Security Bulletin — ColdFusion (APSB26-39)
  • Adobe Security Bulletin — Campaign Classic (APSB26-40)
  • The Hacker News — Adobe CVSS 10.0 Patches
  • NVD — CVE-2026-48362
#Adobe#ColdFusion#Campaign Classic#RCE#patch tuesday#critical vulnerability#CVE

Related Articles

Critical VMware vCenter RCE Flaw Exploited for Reverse SSH Access

CVE-2026-59310 is under active exploitation just 5 days after disclosure, with 361 victims across 47 countries receiving reverse SSH backdoors.

5 min read

SAP Commerce Cloud RCE Flaw Lets Unauthenticated Attackers Execute Arbitrary Code

CVE-2026-58231 scores CVSS 10.0 in SAP Commerce Cloud Data Hub Adapter — patch immediately as unauthenticated RCE with full system compromise is possible.

4 min read

Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts

A critical pre-auth RCE vulnerability in Progress Kemp LoadMaster has been added to CISA's Known Exploited Vulnerabilities catalog following 792 documented exploitation attempts across 65 source IPs over 41 days.

3 min read
Back to all News