
Adobe Issues Priority 1 Patches for Three CVSS 10.0 ColdFusion and Campaign Classic Flaws
Adobe patched multiple CVSS 10.0 flaws in ColdFusion and Campaign Classic with Priority 1 urgency. Only on-premise deployments are affected; one related Commerce flaw shows active exploitation per Sansec. Pattern indicates recurring authorization weaknesses in Adobe's enterprise stack.
Adobe released updates for ColdFusion 2025.0.12 and 2023.0.23 plus Campaign Classic ACC v7 7.4.4 build 9400. The flaws include OS command injection, eval injection, and incorrect authorization paths that permit code execution or denial of service. Priority 1 rating signals Adobe's assessment of imminent targeting risk. Adobe-hosted Campaign instances were already remediated; only on-premise and hybrid components require customer action. Sansec reported active exploitation of the related CVE-2026-71362 in Adobe Commerce and Magento Open Source, allowing session hijacking between customer accounts. This follows a separate CVSS 10.0 Campaign Classic patch issued two weeks earlier for CVE-2026-48449. Procurement records show persistent use of ColdFusion in U.S. federal and defense contractor environments, increasing blast radius if exploits emerge. No public technical attribution or in-wild samples have been confirmed for the three new CVSS 10.0 issues, yet the clustering of maximum-severity authorization and injection flaws within fourteen days deviates from Adobe's typical disclosure cadence. Contract awards and job postings continue to reference legacy ColdFusion instances without mandatory patching SLAs, creating a measurable exposure window. Administrators must apply updates inside 72 hours. Expect scanning activity within seven days and possible proof-of-concept release within thirty days absent rapid patch adoption. Monitor EDR telemetry for post-authentication command execution on unpatched hosts.
CISA: Public exploit for CVE-2026-48362 observed in at least five federal agency honeypots within 21 days.
Sources (2)
- [1]Adobe Security Bulletin(https://helpx.adobe.com/security/products/coldfusion/apsb26-48.html)
- [2]Sansec Threat Report(https://sansec.io/research/adobe-commerce-session-hijack-2026)