Skip to content
Adobe

Critical ColdFusion Patches: Act Now

Adobe patcht ColdFusion

Adobe has released new security updates addressing more than 50 vulnerabilities across several products. The company highlights multiple priority 1 issues—classified as the highest risk in its rating system—especially in ColdFusion and Campaign Classic. If you run these environments, the message is straightforward: update immediately.

Below is what changed, which weaknesses received the most urgent priority, and how to plan patching so you reduce the chance of exposure.

Why Adobe calls for urgent updates

Adobe’s priority system is designed to reflect how likely a vulnerability is to be targeted by attackers. In this release, several defects were rated priority 1, meaning they are considered high risk and should be remediated without delay.

For administrators, this is a strong signal that waiting increases operational risk. Even if Adobe says it is not aware of public exploitation for the newly fixed issues, attackers often move quickly once a weakness becomes widely known.

Critical ColdFusion patches with priority 1

The most urgent portion of the update concerns ColdFusion. Adobe’s ColdFusion update carries a priority 1 rating and fixes 15 security defects. Among them, three were flagged as critical and could enable serious outcomes such as arbitrary code execution and application denial-of-service (DoS).

Adobe lists three notable critical issues:

  • OS command injection — tracked as CVE-2026-48362 (CVSS 10/10)
  • Eval injection — tracked as CVE-2026-48273 (CVSS 9.9/10)
  • Incorrect authorization — tracked as CVE-2026-71384 (CVSS 9.6/10)

In practical terms, these classes of vulnerabilities are dangerous because they can be turned into direct system impact. Command injection can allow attackers to run operating system commands, while injection flaws involving eval can undermine application logic by influencing how code is processed. Incorrect authorization can also break access controls, enabling malicious actions that should be restricted.

Campaign Classic fixes include multiple critical flaws

Adobe also released a priority 1 update for Campaign Classic. This security refresh resolves three critical flaws that can lead to arbitrary code execution.

Adobe identifies the following key vulnerabilities:

  • Incorrect authorizationCVE-2026-71398 (CVSS 10/10)
  • Incorrect authorizationCVE-2026-27302 (CVSS 10/10)
  • SQL injectionCVE-2026-48381 (CVSS 9.0/10)

Because two of these critical issues are tied to authorization failures, they may allow attackers to access functionality they should not. The SQL injection issue raises additional risk, since it can be used to tamper with database queries and potentially extract or modify data depending on how the application is designed.

Adobe’s guidance aligns with this risk profile: treat these critical ColdFusion patches and the related Campaign Classic update as urgent, and deploy both as soon as possible.

Commerce receives priority 2 remediation

For Commerce, Adobe’s update fixes seven vulnerabilities, including at least one vulnerability noted as high risk and tied to authorization problems. Adobe references CVE-2026-71362 with a CVSS score of 9.1/10 and describes it as an incorrect authorization issue that can lead to privilege escalation.

Beyond that specific defect, Adobe also mentions high-severity issues related to code execution and security feature bypass. While the release does include serious problems, the Commerce update itself is rated priority 2, reflecting a slightly lower urgency than the priority 1 items.

Adobe notes that Commerce has been targeted in attacks before. That history matters for planning. In this case, Adobe advises users to apply the Commerce update within the next 30 days.

Other product updates: Lightroom and Content Credentials

In addition to the priority 1 and priority 2 updates, Adobe rolled out other security fixes:

  • Lightroom: 11 high-severity defects
  • Content Credentials: 15 vulnerabilities across high- and medium-severity categories

Both of these updates carry a priority 3 rating in Adobe’s system. While that priority level suggests lower urgency than priority 1 or 2, it still indicates security relevance and should be included in regular patch cycles.

What Adobe says about exploits in the wild

Adobe states that it is not aware of any exploits in the wild for the vulnerabilities newly addressed in this update. Even so, the presence of multiple critical issues with very high CVSS scores means organizations should treat the patching window as time-sensitive.

Security teams often face a gap between “no known exploits” and real-world activity. Attackers can test and weaponize vulnerabilities quickly, particularly when they involve widely understood weakness classes like injection and authorization bypass.

Recommended next steps for IT and security teams

If you manage systems impacted by these releases, use a practical patching workflow. Focus on priority 1 components first, then work through the rest of the security list.

  • Verify your installed versions for ColdFusion, Campaign Classic, and Commerce.
  • Plan downtime and deployment order so you can apply critical ColdFusion patches and Campaign Classic updates without unnecessary delays.
  • Test in a staging environment where possible, especially if you have custom integrations.
  • Confirm access controls after deployment, since multiple fixed issues involve incorrect authorization.
  • Document the change and validate service health to reduce the chance of disruption.

Adobe also points to its security updates page for additional information. In day-to-day operations, that page is a useful starting point for release notes, affected versions, and implementation guidance.

Closing thoughts

Adobe’s latest security release is a reminder that urgent patches are often clustered together across product lines. The most immediate risk is concentrated in ColdFusion and Campaign Classic, where multiple priority 1 vulnerabilities include critical flaws that could enable arbitrary code execution or denial-of-service. Apply the critical ColdFusion patches now, and follow through with the related updates to reduce exposure while the window is still controlled.

Source: https://www.securityweek.com/adobe-urges-immediate-patching-of-critical-coldfusion-campaign-classic-flaws/