HackMyIP
← Back to News
2026-08-11 SecurityWeek

Adobe Patches Critical ColdFusion, Campaign Classic Flaws – Update Now

VulnerabilityCloud Security

Adobe released security updates on Tuesday addressing more than 50 vulnerabilities across its product portfolio, including critical-severity flaws in ColdFusion, Campaign Classic, and Commerce that demand immediate attention from administrators and security teams.

The ColdFusion update, carrying Adobe's priority 1 rating, resolves 15 security defects — three of which are flagged as critical. The most severe is an OS command injection tracked as CVE-2026-48362 with a maximum CVSS score of 10.0, followed by an eval injection (CVE-2026-48273, CVSS 9.9) and an incorrect authorization bug (CVE-2026-71384, CVSS 9.6). These flaws could enable arbitrary code execution and application denial-of-service. Organizations running ColdFusion servers should immediately audit their exposed surfaces using a SSL/TLS checker and port scanner to identify any internet-facing instances that may be at risk of exploitation.

Campaign Classic also received a priority 1 update, addressing three critical vulnerabilities that allow arbitrary code execution: two incorrect authorization issues — CVE-2026-71398 and CVE-2026-27302 (CVSS 10.0 each) — and a SQL injection flaw, CVE-2026-48381 (CVSS 9.0). Meanwhile, the Commerce update resolved seven vulnerabilities, including an incorrect authorization bug (CVE-2026-71362, CVSS 9.1) leading to privilege escalation, alongside high-severity code execution and security feature bypass issues. Adobe separately patched 11 high-severity defects in Lightroom and 15 high- and medium-severity bugs in Content Credentials, both carrying a priority 3 rating.

Although Adobe reports no current evidence of in-the-wild exploitation, the priority 1 classification signals a higher likelihood of weaponization. Administrators should apply the ColdFusion and Campaign Classic patches without delay, while Commerce users have a 30-day remediation window before the priority 2 update becomes critical. Security teams should also audit credentials and authentication mechanisms — a password checker can help identify weak or compromised credentials that adversaries could leverage if these privilege escalation flaws are chained with credential-stuffing attacks.

Source: SecurityWeek →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →