Adobe has released a series of urgent patches addressing over 50 vulnerabilities across its software suite, with a particular focus on critical issues found in ColdFusion and Campaign Classic. This development, announced on Tuesday, highlights the company’s efforts to mitigate serious security risks.
ColdFusion Security Flaws
The latest update for ColdFusion, given a priority 1 rating, addresses 15 security vulnerabilities. Among these, three are deemed critical and pose significant threats such as arbitrary code execution and application denial-of-service (DoS). The most severe, tracked as CVE-2026-48362, is an OS command injection vulnerability with a perfect CVSS score of 10/10. Other critical flaws include an eval injection (CVE-2026-48273) and incorrect authorization issues (CVE-2026-71384), each carrying substantial risk scores.
Critical Issues in Campaign Classic
Similarly, Campaign Classic has also received a priority 1 update that addresses three critical vulnerabilities. Two of these involve incorrect authorization, designated as CVE-2026-71398 and CVE-2026-27302, both with a CVSS score of 10/10. Additionally, an SQL injection flaw, CVE-2026-48381, is included, holding a CVSS score of 9.0/10. Adobe has urged users to apply these patches immediately due to their high risk of being exploited in the wild.
Additional Software Updates
In Adobe Commerce, seven vulnerabilities have been resolved, including a critical incorrect authorization issue (CVE-2026-71362) that could allow privilege escalation, scoring 9.1/10 on the CVSS scale. These vulnerabilities are assigned a priority 2 rating, with a recommendation to update within 30 days.
Furthermore, Adobe has delivered patches for 11 high-severity defects in Lightroom and 15 assorted severity issues in Content Credentials, both marked with a priority 3 rating. Currently, Adobe has no reports of exploits for these newly patched vulnerabilities.
For more details on these updates, Adobe users can visit the company’s security updates page. Staying informed and applying patches promptly is crucial for maintaining software security and protecting against potential threats.
