Adobe has released crucial updates aimed at resolving significant security flaws in its ColdFusion, Commerce, and Campaign Classic products. These vulnerabilities, if left unpatched, could allow unauthorized code execution and privilege escalation, posing serious risks to systems.
Critical Vulnerabilities Addressed
The most pressing vulnerabilities addressed include a command injection flaw in ColdFusion (CVE-2026-48362) with a CVSS score of 10.0, enabling arbitrary code execution. This has been rectified in versions 2025.0.12 and 2023.0.23. Another critical issue, CVE-2026-48273, involves an eval injection, also fixed in the same versions.
Additionally, CVE-2026-71384, an authorization flaw causing denial-of-service in ColdFusion, and CVE-2026-71362 in Commerce leading to privilege escalation, have been addressed. Campaign Classic vulnerabilities CVE-2026-71398 and CVE-2026-27302, both scoring 10.0, involved incorrect authorization that could lead to arbitrary code execution, now resolved in ACC v7 7.4.4 build 9400.
Priority and Implementation
Adobe has assigned a Priority 1 rating to these updates, indicating an elevated risk of exploitation by attackers. This rating underscores the urgent need for users to apply these patches promptly to safeguard their systems.
It is important to note that the updates for Campaign Classic are pertinent only to on-premise systems and components of hybrid setups. Adobe-hosted configurations have been automatically secured and do not necessitate user intervention.
Security Recommendations
Currently, there is no evidence suggesting active exploitation of these vulnerabilities. Nevertheless, system administrators are strongly advised to implement these updates swiftly, ideally within a 72-hour window, to mitigate potential threats.
This disclosure follows closely on the heels of Adobe’s recent patch for another high-severity flaw in Campaign Classic (CVE-2026-48449), which also posed a risk of arbitrary code execution.
The swift action in releasing these updates highlights Adobe’s commitment to maintaining robust security standards and protecting users from emerging cyber threats.
