Adobe Patches Critical CVSS 10.0 Flaws in ColdFusion and Campaign Classic
Security updates address severe remote code execution and authorization vulnerabilities that could allow full system compromise.
Adobe has released urgent security updates to address multiple critical vulnerabilities across its ColdFusion and Campaign Classic software. These flaws, some carrying the maximum possible severity rating, could allow unauthenticated remote attackers to execute arbitrary code or bypass authorization on affected systems.
Among the most severe is CVE-2026-48362, an OS command injection vulnerability affecting Adobe ColdFusion. This flaw carries a CVSS score of 10.0 and enables unauthenticated remote code execution. Additionally, Adobe Campaign Classic is affected by two critical incorrect authorization flaws, identified as CVE-2026-71398 and CVE-2026-27302, both of which also carry CVSS scores of 10.0.
August Security Cycle
These vulnerabilities were addressed as part of Adobe's August 2026 security update cycle. The OS command injection flaw specifically targeted ColdFusion 2025 (up to version 2025.0.11) and ColdFusion 2023 (up to version 2023.0.22). Adobe has since released patches to mitigate these risks, with the fixes deployed in versions 2025.0.12 and 2023.0.23, respectively.
Industry Implications
The CVSS 10.0 ratings signify the highest level of risk in the industry. Because these vulnerabilities allow attackers to achieve full system compromise—impacting confidentiality, integrity, and availability—without requiring any user interaction, they pose an extreme threat to organizations. This is particularly critical for enterprises running these Adobe products on internet-exposed servers, where the barrier to entry for an attacker is virtually non-existent.
Next Steps for Administrators
Organizations utilizing ColdFusion and Campaign Classic are urged to apply the August updates immediately to prevent potential exploitation. While the primary critical flaws have been patched, administrators should verify that their specific version numbers align with the fixed releases (2025.0.12 and 2023.0.23 for ColdFusion). Security teams should continue to monitor for any further disclosures related to the August update cycle to ensure all endpoints are fully secured.
Given the severity of these flaws, failure to patch could lead to complete server takeover. Administrators should prioritize these updates over routine maintenance, as the lack of required user interaction makes these vulnerabilities highly attractive for automated exploitation scripts and targeted attacks. Ensuring that all instances of ColdFusion and Campaign Classic are updated to the latest versions is the only reliable way to neutralize these specific threats.