Adobe Patches Critical ColdFusion, Campaign Classic Flaws – Update Now
Adobe released security updates on Tuesday addressing more than 50 vulnerabilities across its product portfolio, including critical-severity flaws in ColdFusion, Campaign Classic, and Commerce that demand immediate attention from administrators and security teams.
The ColdFusion update, carrying Adobe's priority 1 rating, resolves 15 security defects — three of which are flagged as critical. The most severe is an OS command injection tracked as CVE-2026-48362 with a maximum CVSS score of 10.0, followed by an eval injection (CVE-2026-48273, CVSS 9.9) and an incorrect authorization bug (CVE-2026-71384, CVSS 9.6). These flaws could enable arbitrary code execution and application denial-of-service. Organizations running ColdFusion servers should immediately audit their exposed surfaces using a SSL/TLS checker and port scanner to identify any internet-facing instances that may be at risk of exploitation.
Campaign Classic also received a priority 1 update, addressing three critical vulnerabilities that allow arbitrary code execution: two incorrect authorization issues — CVE-2026-71398 and CVE-2026-27302 (CVSS 10.0 each) — and a SQL injection flaw, CVE-2026-48381 (CVSS 9.0). Meanwhile, the Commerce update resolved seven vulnerabilities, including an incorrect authorization bug (CVE-2026-71362, CVSS 9.1) leading to privilege escalation, alongside high-severity code execution and security feature bypass issues. Adobe separately patched 11 high-severity defects in Lightroom and 15 high- and medium-severity bugs in Content Credentials, both carrying a priority 3 rating.
Although Adobe reports no current evidence of in-the-wild exploitation, the priority 1 classification signals a higher likelihood of weaponization. Administrators should apply the ColdFusion and Campaign Classic patches without delay, while Commerce users have a 30-day remediation window before the priority 2 update becomes critical. Security teams should also audit credentials and authentication mechanisms — a password checker can help identify weak or compromised credentials that adversaries could leverage if these privilege escalation flaws are chained with credential-stuffing attacks.