Adobe Fixes Three CVSS 10.0 Flaws in ColdFusion & Campaign Classic
Adobe has rolled out emergency patches addressing multiple critical security vulnerabilities across ColdFusion, Commerce, and Campaign Classic that could allow attackers to execute arbitrary code, escalate privileges, or trigger denial-of-service conditions. The most severe issues carry a maximum CVSS score of 10.0, with the company assigning a Priority 1 rating to the ColdFusion and Campaign Classic updates — a designation reserved for flaws at elevated risk of real-world exploitation.
The ColdFusion lineup includes CVE-2026-48362 (CVSS 10.0), an OS command injection flaw enabling arbitrary code execution, and CVE-2026-48273 (CVSS 9.9), an eval injection vulnerability with the same impact. Both are fixed in versions 2025.0.12 and 2023.0.23. CVE-2026-71384 (CVSS 9.6), an incorrect authorization bug, can lead to application denial-of-service. In Campaign Classic, CVE-2026-71398 and CVE-2026-27302 (both CVSS 10.0) are authorization failures enabling arbitrary code execution, while CVE-2026-48381 (CVSS 9.0) is a SQL injection flaw with the same impact — all addressed in ACC v7 7.4.4 build 9400. Adobe Commerce users should also patch CVE-2026-71362 (CVSS 9.1), an authorization weakness allowing privilege escalation.
Adobe notes that hosted Campaign Classic instances have already been remediated, but on-premise and hybrid deployments require immediate customer action. Administrators are urged to apply the fixes within 72 hours, particularly since ColdFusion servers are frequently internet-facing — a quick port scanner check can help identify any exposed instances that may need attention alongside the patch. Given the severity ratings, security teams should also verify that TLS configurations are hardened; an SSL/TLS checker is a useful way to confirm valid certificates and cipher suites on affected web front-ends.
No exploitation has been observed in the wild for these specific flaws, but the disclosure follows closely on a separate maximum-severity Campaign Classic patch (CVE-2026-48449, CVSS 10.0) released less than two weeks earlier — a pattern that highlights how exposed enterprise web stacks remain a prime target. Organizations running these products should audit access controls, rotate any service account credentials that may have interacted with vulnerable endpoints, and run a broader privacy checkup to ensure no residual exposure persists after patching.