Skip to content
Adobe

Adobe Patches: CVSS 10.0 ColdFusion Fixes

Adobe patches ColdFusion

Adobe has released security updates addressing several critical vulnerabilities affecting ColdFusion, Commerce, and Campaign Classic. Some issues carry maximum or near-maximum severity and, if an attacker can exploit them, may enable arbitrary code execution or privilege escalation. Among the most urgent items are the CVSS 10.0 ColdFusion fixes for command injection and other high-impact weaknesses.

Adobe assigns a Priority 1 rating to the ColdFusion and Campaign Classic updates. This priority level is intended for vulnerabilities with a higher likelihood of being actively targeted. Even without public evidence of exploitation in the wild, administrators are advised to patch promptly—ideally within 72 hours.

What Adobe fixed in ColdFusion

ColdFusion received multiple updates that address vulnerabilities rated as critical. The most severe issues include a command injection flaw and an eval injection flaw, both with potential to lead to arbitrary code execution.

  • CVE-2026-48362 (CVSS 10.0): operating system command injection in ColdFusion, potentially resulting in arbitrary code execution. Fixed in 2025.0.12 and 2023.0.23.
  • CVE-2026-48273 (CVSS 9.9): eval injection vulnerability in ColdFusion, potentially resulting in arbitrary code execution. Fixed in 2025.0.12 and 2023.0.23.
  • CVE-2026-71384 (CVSS 9.6): incorrect authorization weakness in ColdFusion that could enable an application denial-of-service. Fixed in 2025.0.12 and 2023.0.23.

In practical terms, the updates target multiple pathways that could allow hostile input to be interpreted as commands or executable logic. That’s why the release is positioned as high urgency for systems running affected ColdFusion versions—these are exactly the types of defects that defenders prefer to close quickly.

Commerce vulnerability with high impact

Beyond ColdFusion, Adobe also addressed a critical authorization-related issue in Commerce. This specific flaw is described as an authorization problem that could allow an attacker to gain elevated capabilities.

  • CVE-2026-71362 (CVSS 9.1): incorrect authorization vulnerability in Commerce that could lead to privilege escalation.

While the details in this bulletin focus on the authorization aspect and its effect, the risk framing is clear: if attackers can bypass authorization controls, they may take actions beyond what the compromised user account is supposed to be allowed to do.

Campaign Classic critical issues for on-prem deployments

Adobe’s advisory also covers multiple vulnerabilities in Campaign Classic, including several rated at maximum severity. Two of these authorization weaknesses are listed with a CVSS score of 10.0, and there is also an SQL injection item with a CVSS score of 9.0.

  • CVE-2026-71398 (CVSS 10.0): incorrect authorization vulnerability in Campaign Classic that could lead to arbitrary code execution. Fixed in ACC v7 7.4.4 build 9400.
  • CVE-2026-27302 (CVSS 10.0): incorrect authorization vulnerability in Campaign Classic that could lead to arbitrary code execution. Fixed in ACC v7 7.4.4 build 9400.
  • CVE-2026-48381 (CVSS 9.0): SQL injection vulnerability in Campaign Classic that could lead to arbitrary code execution. Fixed in ACC v7 7.4.4 build 9400.

These defects combine authorization failures with input-handling problems that could, under attacker control, result in execution of unintended operations. Adobe also notes that Campaign Classic updates only apply to fully on-premise deployments and to the on-premise components of hybrid setups.

Are hosted instances affected?

Adobe clarifies that Adobe-hosted instances for Campaign Classic have already been remediated. As a result, customers running Adobe-hosted deployments do not need to take action for the hosted environment.

If you operate a fully on-premise Campaign Classic installation (or the on-prem parts of a hybrid deployment), you should verify your current build and upgrade to the version specified in the advisory: ACC v7 7.4.4 build 9400.

Patch priority, timing, and recommended action

The updates for ColdFusion and Campaign Classic carry a Priority 1 rating. Adobe’s guidance emphasizes the higher risk of targeted malicious activity against these weaknesses.

Although Adobe states that there is no evidence of these flaws being exploited in the wild, the company still recommends installation as soon as possible. The preferred window is within 72 hours, which aligns with common incident-prevention practices for high-severity issues.

Why this release matters now

This patch cycle arrives shortly after Adobe released fixes for another maximum-severity Campaign Classic issue (noted in the bulletin as CVE-2026-48449 with a CVSS score of 10.0). Even if that earlier flaw is different from the ones listed here, the overall message is consistent: defenders should expect continued remediation needs when products expose critical code execution paths.

For security teams, this is a reminder that asset coverage and version tracking are essential. The fastest way to reduce exposure is to ensure your ColdFusion and Campaign Classic installations are running the patched builds referenced in the advisory.

Quick checklist for administrators

If you manage environments that include ColdFusion, Commerce, or Campaign Classic, use this practical checklist to turn the bulletin into action.

  • Inventory affected systems: confirm which hosts run the affected product components and versions.
  • Apply the referenced fixes: for ColdFusion, update to 2025.0.12 or 2023.0.23; for Campaign Classic on-prem, update to ACC v7 7.4.4 build 9400.
  • Focus on Priority 1 scope: treat the ColdFusion and Campaign Classic updates as urgent and schedule work to meet the 72-hour target.
  • Validate deployment type: confirm whether your Campaign Classic environment is fully on-premise, hybrid (on-prem components), or Adobe-hosted.
  • Document results: record patch dates and resulting versions for audit readiness.

Conclusion

Adobe’s latest security release includes high-impact CVSS 10.0 ColdFusion fixes and multiple critical patches for Campaign Classic and Commerce. With Priority 1 labeling and fixes that address command injection, eval injection, authorization failures, and SQL injection, the advisory clearly targets scenarios that could enable arbitrary code execution or privilege escalation.

Even in the absence of confirmed real-world exploitation, administrators are encouraged to update quickly—ideally within 72 hours—and to ensure they patch the correct on-prem components for Campaign Classic deployments.

Source: https://thehackernews.com/2026/08/adobe-patches-three-cvss-100-coldfusion.html