CVE Tools

Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws

SecurityWeekBy Ionut Arghire

PatchColdFusionCampaign Classic

Our summary

Adobe has released security updates addressing more than 50 vulnerabilities, with top-priority patches targeting Critical-severity defects in ColdFusion, Campaign Classic, and Commerce. The ColdFusion update resolves 15 issues, including CVE-2026-48362 (OS command injection) and CVE-2026-48273 (eval injection), which pose risks of arbitrary code execution and denial-of-service. Similarly, the Campaign Classic patch addresses three critical flaws, such as CVE-2026-71398 and CVE-2026-27302 (incorrect authorization) and CVE-2026-48381 (SQL injection), enabling potential remote code execution. While Adobe reports no known active exploitation, administrators are urged to apply these Priority 1 patches immediately due to the high likelihood of real-world targeting.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store