Adobe issues critical ColdFusion and Campaign Classic security fixes

Adobe has released security updates for ColdFusion, Commerce and Campaign Classic, addressing seven critical vulnerabilities that can lead to arbitrary code execution, privilege escalation or denial of service. Three of the issues carry the maximum CVSS score of 10.0: one in ColdFusion and two in Campaign Classic.
The ColdFusion fixes are available in versions 2025.0.12 and 2023.0.23. Campaign Classic customers running affected on-premise deployments, or the on-premise components of hybrid deployments, should update to ACC v7 7.4.4 build 9400. Adobe-hosted Campaign Classic instances have already been remediated and require no customer action.
Maximum-severity flaws affect application platforms
CVE-2026-48362 is an operating-system command injection flaw in ColdFusion with a CVSS score of 10.0. Successful exploitation could allow arbitrary code execution. CVE-2026-48273, rated 9.9, is an eval injection issue in the same product that could also result in arbitrary code execution.
Adobe also fixed CVE-2026-71384, an incorrect authorization vulnerability in ColdFusion rated 9.6 that could cause an application denial of service. Together, the ColdFusion issues are addressed in the two supported versions named in the advisory.
Campaign Classic and Commerce updates
Campaign Classic receives fixes for CVE-2026-71398 and CVE-2026-27302, both incorrect authorization vulnerabilities rated CVSS 10.0 and capable of leading to arbitrary code execution. CVE-2026-48381 is a CVSS 9.0 SQL injection vulnerability in Campaign Classic that could likewise enable arbitrary code execution.
For context, Adobe critical application patching cycle also concerns the critical patching cycle around ColdFusion and Campaign Classic, where high-severity application flaws require close attention from platform administrators. Adobe issued the Campaign Classic fixes only for fully on-premise installations and the on-premise portions of hybrid environments.
Adobe additionally addressed CVE-2026-71362, a CVSS 9.1 incorrect authorization vulnerability in Commerce that could lead to privilege escalation. The company assigned Priority 1 ratings to the ColdFusion and Campaign Classic updates, indicating a higher risk that malicious cyber attacks could target the affected flaws.
What administrators should do
Adobe said it has no evidence that these vulnerabilities have been exploited in the wild. Even so, it recommends installing the updates as soon as possible, preferably within 72 hours. The disclosure follows Adobe’s patch for Campaign Classic CVE-2026-48449, another CVSS 10.0 arbitrary-code-execution issue, released less than two weeks earlier.
Businesses should inventory ColdFusion, Commerce and Campaign Classic deployments, distinguish hosted services from customer-managed components, and verify that the specified fixes are installed. For on-premise teams, prioritising the Priority 1 updates and recording the resulting version state is the immediate operational implication.

