Adobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic that, if successfully exploited, could result in arbitrary code execution and privilege escalation.
The most severe of the flaws are listed below –
- CVE-2026-48362 (CVSS score: 10.0) – An operating system command injection vulnerability in ColdFusion that could lead to arbitrary code execution (Fixed in 2025.0.12 and 2023.0.23)
- CVE-2026-48273 (CVSS score: 9.9) – An eval injection vulnerability in ColdFusion that could lead to arbitrary code execution (Fixed in 2025.0.12 and 2023.0.23)
- CVE-2026-71384 (CVSS score: 9.6) – An incorrect authorization vulnerability in ColdFusion that could lead to an application denial-of-service (Fixed in 2025.0.12 and 2023.0.23)
- CVE-2026-71362 (CVSS score: 9.1) – An incorrect authorization vulnerability in Commerce that could lead to privilege escalation
- CVE-2026-71398 (CVSS score: 10.0) – An incorrect authorization vulnerability in Campaign Classic that could lead to arbitrary code execution (Fixed in ACC v7 7.4.4 build 9400)
- CVE-2026-27302 (CVSS score: 10.0) – An incorrect authorization vulnerability in Campaign Classic that could lead to arbitrary code execution (Fixed in ACC v7 7.4.4 build 9400)
- CVE-2026-48381 (CVSS score: 9.0) – An SQL injection vulnerability in Campaign Classic that could lead to arbitrary code execution (Fixed in ACC v7 7.4.4 build 9400)
The updates for ColdFusion and Campaign Classic have a Priority 1 rating, which refers to vulnerabilities that have a higher risk of being targeted by malicious cyber attacks.


Leave a Reply