Adobe Patches Critical Flaws in ColdFusion, Commerce, and Campaign Classic
Adobe has released urgent security updates to address multiple critical vulnerabilities across its ColdFusion, Commerce, and Campaign Classic platforms. These flaws, some rated with a CVSS score of 10.0, could enable arbitrary code execution, privilege escalation, and denial-of-service attacks. IT security professionals and privacy-conscious users are strongly advised to apply these patches immediately.

**Adobe** has rolled out critical security updates to mitigate several high-severity vulnerabilities impacting its **ColdFusion**, **Commerce**, and **Campaign Classic** products. Successful exploitation of these flaws could lead to severe consequences, including arbitrary code execution and privilege escalation.
### Key Vulnerabilities Addressed
The most critical vulnerabilities patched in this release include:
* **CVE-2026-48362** (CVSS score: 10.0): An operating system command injection vulnerability in ColdFusion, potentially leading to arbitrary code execution. (Fixed in ColdFusion 2025.0.12 and 2023.0.23)
* **CVE-2026-48273** (CVSS score: 9.9): An eval injection vulnerability in ColdFusion, also allowing for arbitrary code execution. (Fixed in ColdFusion 2025.0.12 and 2023.0.23)
* **CVE-2026-71384** (CVSS score: 9.6): An incorrect authorization vulnerability in ColdFusion, which could result in an application denial-of-service. (Fixed in ColdFusion 2025.0.12 and 2023.0.23)
* **CVE-2026-71362** (CVSS score: 9.1): An incorrect authorization vulnerability in Commerce that could lead to privilege escalation.
* **CVE-2026-71398** (CVSS score: 10.0): An incorrect authorization vulnerability in Campaign Classic, potentially leading to arbitrary code execution. (Fixed in ACC v7 7.4.4 build 9400)
* **CVE-2026-27302** (CVSS score: 10.0): Another incorrect authorization vulnerability in Campaign Classic, also enabling arbitrary code execution. (Fixed in ACC v7 7.4.4 build 9400)
* **CVE-2026-48381** (CVSS score: 9.0): An SQL injection vulnerability in Campaign Classic that could facilitate arbitrary code execution. (Fixed in ACC v7 7.4.4 build 9400)
### Urgent Action Recommended
**Adobe** has assigned a Priority 1 rating to the updates for **ColdFusion** and **Campaign Classic**, indicating a higher likelihood of these vulnerabilities being targeted by malicious actors. While there is currently no evidence of these flaws being exploited in the wild, administrators are strongly urged to install the updates as soon as possible, ideally within 72 hours.
It's important to note that updates for **Campaign Classic** specifically apply to fully on-premise deployments and the on-premise components of hybrid deployments. **Adobe**-hosted instances have already been remediated, requiring no further action from customers.
This release follows closely on the heels of another critical patch less than two weeks ago, which addressed **CVE-2026-48449** (CVSS score: 10.0), a maximum-severity flaw in **Campaign Classic** that also permitted arbitrary code execution.