Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws
Adobe releases patches for over 50 vulnerabilities, including critical flaws in ColdFusion and Campaign Classic.
Summary
Adobe has issued urgent patches for more than 50 security vulnerabilities across its product suite. Critical flaws affecting ColdFusion and Campaign Classic could allow for arbitrary code execution and denial-of-service attacks. Adobe is prioritizing these updates due to a higher risk of exploitation.
Full text
Adobe on Tuesday rolled out patches for over 50 vulnerabilities across its products, including critical-severity bugs in ColdFusion, Campaign Classic, and Commerce. With a priority 1 rating, the ColdFusion update fixes 15 security defects, including three flagged as critical that could lead to arbitrary code execution and application denial-of-service (DoS). These include an OS command injection tracked as CVE-2026-48362 (CVSS score of 10/10), an eval injection tracked as CVE-2026-48273 (CVSS score of 9.9/10), and an incorrect authorization tracked as CVE-2026-71384 (CVSS score of 9.6/10). The update for Campaign Classic also has a priority 1 rating, as it resolves three critical flaws leading to arbitrary code execution: two incorrect authorization issues, CVE-2026-71398 and CVE-2026-27302 (CVSS score of 10/10), and an SQL injection bug, CVE-2026-48381 (CVSS score of 9.0/10). Per Adobe’s priority rating system, these security defects have a higher risk of being targeted in the wild, and users should apply the patches for both products immediately. Adobe resolved seven vulnerabilities in Commerce, including CVE-2026-71362 (CVSS score of 9.1/10), an incorrect authorization issue leading to privilege escalation. High-severity code execution and security feature bypass bugs were also addressed.Advertisement. Scroll to continue reading. The security refresh for Commerce has a priority 2 rating, as the product is known to have been targeted in attacks before. Users are advised to apply the update within the next 30 days. On Tuesday, Adobe also rolled out patches for 11 high-severity defects in Lightroom and 15 high- and medium-severity bugs in Content Credentials. Both updates have a priority 3 rating. Adobe says it is not aware of any exploits in the wild for the newly addressed vulnerabilities. Additional information can be found on Adobe’s security updates page. Related: Zoom Patches Zero-Click Code Execution Vulnerability Related: SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities Related: Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC Related: Metabase Patches Vulnerability Exploited as Zero-Day Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents BadMetabase Patches Vulnerability Exploited as Zero-DayCISA Urges Immediate Patching of Exploited Progress LoadMaster VulnerabilityCorporate Data Stolen in Levi Strauss CyberattackVishing Extortion Group UNC6671 Rebrands After Making MillionsMicrosoft, Apple Release Fresh Security Updates3.8 Million Impacted by Unlimited Technology Systems Data Breach Latest News Zoom Patches Zero-Click Code Execution VulnerabilityThe AI Governance Gap Is a Leadership Problem: Waiting Won’t Close ItSAP Patches Critical Code Injection, Memory Corruption VulnerabilitiesUS Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’Corma Raises $60 Million for Defensive Cybersecurity AI ModelExtension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious ActivitiesHacker Conversations: Marcus Hutchins and the Journey From the Gray Zone to RedemptionOpenAI Unveils New Cybersecurity Model GPT-5.6-Cyber Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Rethinking Cyber Defense for AI-Speed Attacks August 18, 2026 Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the Move1Kosmos has named Frank Cohen Chief Revenue Officer.ServiceNow has appointed Simon Mouyal as Chief Marketing Officer.James Wilkinson has been named Chief Information Security Officer for the City of Dallas.More People On The MoveExpert Insights The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It Organizations are rushing to implement AI without fully grasping where its legal protections begin and end. (Steve Durbin) Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries set for safe AI use. (Etay Maor) Timeless Compliance: Why Better Questions Beat Bigger Frameworks The best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. (Matt Honea) Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Flipboard Reddit Whatsapp Whatsapp Email
Indicators of Compromise
- cve — CVE-2026-48362
- cve — CVE-2026-48273
- cve — CVE-2026-71384
- cve — CVE-2026-71398
- cve — CVE-2026-27302
- cve — CVE-2026-48381
- cve — CVE-2026-71362