Bottom line: Adobe fixes 88 vulnerabilities in a major patch cycle, including eight critical flaws in ColdFusion that enable remote code injection, SQL injection, and authentication bypass.
Adobe has released updates for twelve product lines in its current patch day and thereby closed a total of 88 vulnerabilities. ColdFusion in particular is affected by eight critical gaps that enable unauthorized code execution and privilege escalation.
Adobe has provided security updates for twelve product lines as part of its current patch day. The update closes a total of 88 vulnerabilities. Thirteen security flaws were identified in the web application platform ColdFusion, eight of which have been classified as critical. Particularly serious are the gaps with the CVE identifications CVE-2026-48318, CVE-2026-48322 and CVE-2026-48284: they include code injections, SQL injections, missing or insufficient input validation, path traversal, and insufficient authentication checks. These vulnerabilities enable an attacker to execute arbitrary code and illegally escalate system privileges. Adobe has provided the fixes in ColdFusion 2025 Update 11 and ColdFusion 2023 Update 22 and classified them as Priority 1.
This patch release follows less than two weeks after an emergency update for ColdFusion in which a vulnerability was already being actively exploited in the field. The particularly high release frequency highlights the considerable risk potential for organizations operating ColdFusion infrastructure.
Beyond ColdFusion, other core products have critical security vulnerabilities. In Adobe Commerce, 13 vulnerabilities were fixed, two of which are critical (CVE-2026-48356 and CVE-2026-48358), which enable code execution and privilege escalation. Adobe Experience Manager also contained 13 security gaps, including the critical flaws CVE-2026-48259 and CVE-2026-48359. In Adobe Illustrator, a critical security vulnerability was corrected due to faulty input validation (CVE-2026-48334), which enables privilege escalation.
The remaining corrections are distributed across a series of other Adobe products: The Content Credentials SDK received twelve security corrections. The programs Animate, Audition and Bridge were each updated with six patches. Additional bug fixes affect Media Encoder, Premiere Pro (four patches), After Effects (three patches) and the Creative Cloud Desktop application (two patches).
According to Adobe, as of the time of publication, there is no evidence of active exploitation of the fixed vulnerabilities. Administrators should deploy the provided updates in a timely manner, particularly for ColdFusion, Commerce and Experience Manager.
Source: www.it-daily.net · Published 16 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrasing and classification through Lumi News Pipeline v1.7.3.