Skip to content

Adobe patches three security vulnerabilities with maximum CVSS score of 10.0 in ColdFusion and Campaign Classic

Bottom line: Adobe is patching three critical vulnerabilities with a CVSS score of 10.0 in ColdFusion and Campaign Classic that could enable unauthorized code execution.

Adobe has released updates for ColdFusion, Commerce and Campaign Classic that address multiple critical vulnerabilities. Three of the flaws reach the maximum CVSS score of 10.0 and, if successfully exploited, allow remote code execution as well as privilege escalation.

Adobe has released out-of-cycle security updates addressing critical vulnerabilities in ColdFusion, Commerce and Campaign Classic. At the center is CVE-2026-48362, with a CVSS score of 10.0 — an OS command injection vulnerability in ColdFusion that could allow attackers to execute arbitrary commands on the affected system. Adobe lists the flaw as one of several vulnerabilities with the highest possible severity rating, with a total of three flaws reaching the maximum value of 10.0, according to the source. Further details on the remaining two CVSS 10.0 vulnerabilities, as well as on the affected versions and specific patch numbers, are not available from the excerpt at hand.

For CISOs, the combination of ColdFusion and Campaign Classic is particularly relevant, as both products are frequently used in business-critical environments for web applications and marketing automation respectively, and are often exposed to internet access. Command injection vulnerabilities with a CVSS score of 10.0 are typically considered fully remotely exploitable without requiring authentication — a factor that has historically made ColdFusion servers a preferred target for automated attacks as soon as vulnerability details become public or proof-of-concept code emerges.

Security teams should review the advisories provided by Adobe, identify affected ColdFusion, Commerce and Campaign Classic installations, and apply the patches as a priority. Especially for publicly accessible ColdFusion instances, an additional short-term check for indicators of compromise is advisable, as critical command injection flaws have repeatedly been actively exploited shortly after disclosure in the past.


Source: thehackernews.com · Published August 12, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: