{"id":2350,"date":"2026-08-12T11:58:25","date_gmt":"2026-08-12T11:58:25","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2350"},"modified":"2026-08-12T11:58:25","modified_gmt":"2026-08-12T11:58:25","slug":"adobe-patches-three-cvss-10-0-coldfusion-and-campaign-classic-flaws","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2350","title":{"rendered":"Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Aug 12, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Web Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj36vXq6xqWIDA09DIFwTp0gAZyTEpTdUoOrczmHr0NAOmxBDBySv4K6oEmzSup0sZylULeZlzf2unPADh99H5kx8-oktejFUPTM2t5aM6WrdTy99m6Qs12z4A58UYbqU2LhZRa20yY9FGy8FFB-pMvUFsA3MolrrA4nYOWVf9IS42Y0vUn3sMtu0BCty3g\/s1700-e365\/adobe-cve.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Adobe has <a href=\"https:\/\/helpx.adobe.com\/security.html\" target=\"_blank\">shipped updates<\/a> to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic that, if successfully exploited, could result in arbitrary code execution and privilege escalation.<\/p>\n<p>The most severe of the flaws are listed below &#8211;<\/p>\n<ul>\n<li><strong><a href=\"https:\/\/helpx.adobe.com\/security\/products\/coldfusion\/apsb26-90.html\" target=\"_blank\">CVE-2026-48362<\/a><\/strong> (CVSS score: 10.0) &#8211; An operating system command injection vulnerability in ColdFusion that could lead to arbitrary code execution (Fixed in 2025.0.12 and 2023.0.23)<\/li>\n<li><strong><a href=\"https:\/\/helpx.adobe.com\/security\/products\/coldfusion\/apsb26-90.html\" target=\"_blank\">CVE-2026-48273<\/a><\/strong> (CVSS score: 9.9) &#8211; An eval injection vulnerability in ColdFusion that could lead to arbitrary code execution (Fixed in 2025.0.12 and 2023.0.23)<\/li>\n<li><strong><a href=\"https:\/\/helpx.adobe.com\/security\/products\/coldfusion\/apsb26-90.html\" target=\"_blank\">CVE-2026-71384<\/a><\/strong> (CVSS score: 9.6) &#8211; An incorrect authorization vulnerability in ColdFusion that could lead to an application denial-of-service (Fixed in 2025.0.12 and 2023.0.23)<\/li>\n<li><strong><a href=\"https:\/\/helpx.adobe.com\/security\/products\/magento\/apsb26-92.html\" target=\"_blank\">CVE-2026-71362<\/a><\/strong> (CVSS score: 9.1) &#8211; An incorrect authorization vulnerability in Commerce that could lead to privilege escalation<\/li>\n<li><strong><a href=\"https:\/\/helpx.adobe.com\/security\/products\/campaign\/apsb26-123.html\" target=\"_blank\">CVE-2026-71398<\/a><\/strong> (CVSS score: 10.0) &#8211; An incorrect authorization vulnerability in Campaign Classic that could lead to arbitrary code execution (Fixed in ACC v7 7.4.4 build 9400)<\/li>\n<li><strong><a href=\"https:\/\/helpx.adobe.com\/security\/products\/campaign\/apsb26-123.html\" target=\"_blank\">CVE-2026-27302<\/a><\/strong> (CVSS score: 10.0) &#8211; An incorrect authorization vulnerability in Campaign Classic that could lead to arbitrary code execution (Fixed in ACC v7 7.4.4 build 9400)<\/li>\n<li><strong><a href=\"https:\/\/helpx.adobe.com\/security\/products\/campaign\/apsb26-123.html\" target=\"_blank\">CVE-2026-48381<\/a><\/strong> (CVSS score: 9.0) &#8211; An SQL injection vulnerability in Campaign Classic that could lead to arbitrary code execution (Fixed in ACC v7 7.4.4 build 9400)<\/li>\n<\/ul>\n<p>The updates for ColdFusion and Campaign Classic have a <a href=\"https:\/\/helpx.adobe.com\/security\/severity-ratings.html\" target=\"_blank\">Priority 1 rating<\/a>, which refers to vulnerabilities that have a higher risk of being targeted by malicious cyber attacks.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/zero-trust-claude-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj8iAp2j8rqTq6aptj6yiYHC-B73UxnWI2NQMt0azp6OVLq9JkO8cpYokLWa8t_IKqrHKPsaM5D_lQ9Ip7kZTi3at4oYfzN1m1b_T4b6MuzBWtmlhdLcQ0nZHicD94rliREFDRewsKBQCTYrAAVNzYKj84_0EZskDUxvkc972s9fYAqcQGEQjVZTc0cr7TB\/s728-e100\/ThreatLocker-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>It&#8217;s worth noting that the Campaign Classic updates only apply to fully on-premise deployments and to the on-premise components of hybrid deployments. Adobe-hosted instances have already been remediated and require no customer action.<\/p>\n<p>Although there is no evidence of these flaws being exploited in the wild, administrators are recommended to install the update as soon as possible, preferably within 72 hours.<\/p>\n<p>The disclosure comes less than two weeks after Adobe released patches for a maximum-severity security flaw in Campaign Classic (CVE-2026-48449, CVSS score: 10.0) that could result in arbitrary code execution.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Aug 12, 2026Vulnerability \/ Web Security Adobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic that, if successfully exploited, could result in&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2351,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[1135,6,2287,2286,497,11,57],"class_list":["post-2350","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-adobe","tag-campaign","tag-classic","tag-coldfusion","tag-cvss","tag-flaws","tag-patches"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2350","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2350"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2350\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2351"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2350"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2350"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2350"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}