Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws
Adobe on Tuesday rolled out patches for over 50 vulnerabilities across its products, including critical-severity bugs in ColdFusion, Campaign Classic, and Commerce.
With a priority 1 rating, the ColdFusion update fixes 15 security defects, including three flagged as critical that could lead to arbitrary code execution and application denial-of-service (DoS).
These include an OS command injection tracked as CVE-2026-48362 (CVSS score of 10/10), an eval injection tracked as CVE-2026-48273 (CVSS score of 9.9/10), and an incorrect authorization tracked as CVE-2026-71384 (CVSS score of 9.6/10).
The update for Campaign Classic also has a priority 1 rating, as it resolves three critical flaws leading to arbitrary code execution: two incorrect authorization issues, CVE-2026-71398 and CVE-2026-27302 (CVSS score of 10/10), and an SQL injection bug, CVE-2026-48381 (CVSS score of 9.0/10).
Per Adobe’s priority rating system, these security defects have a higher risk of being targeted in the wild, and users should apply the...
Copyright of this story solely belongs to securityweek.com. To see the full text click HERE