Vulnerabilities Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws The security defects could be exploited for arbitrary code execution and denial-of-service. By Ionut Arghire | August 11, 2026 (12:50 PM ET) Flipboard Reddit Whatsapp Whatsapp Email Adobe on Tuesday rolled out patches for over 50 vulnerabilities across its products, including critical-severity bugs in ColdFusion, Campaign Classic, and Commerce. With a priority 1 rating, the ColdFusion update fixes 15 security defects, including three flagged as critical that could lead to arbitrary code execution and application denial-of-service (DoS). These include an OS command injection tracked as CVE-2026-48362 (CVSS score of 10/10), an eval injection tracked as CVE-2026-48273 (CVSS score of 9.9/10), and an incorrect authorization tracked as CVE-2026-71384 (CVSS score of 9.6/10). The update for Campaign Classic also has a priority 1 rating, as it resolves three critical flaws leading to arbitrary code execution: two incorrect authorization issues, CVE-2026-71398 and CVE-2026-27302 (CVSS score of 10/10), and an SQL injection bug, CVE-2026-48381 (CVSS score of 9.0/10). Per Adobe’s priority rating system, these security defects have a higher risk of being targeted in the wild, and users should apply the patches for both products immediately. Adobe resolved seven vulnerabilities in Commerce, including CVE-2026-71362 (CVSS score of 9.1/10), an incorrect authorization issue leading to privilege escalation. High-severity code execution and security feature bypass bugs were also addressed. Advertisement. Scroll to continue reading. The security refresh for Commerce has a priority 2 rating, as the product is known to have been targeted in attacks before. Users are advised to apply the update within the next 30 days. On Tuesday, Adobe also rolled out patches for 11 high-severity defects in Lightroom and 15 high- and medium-severity bugs in Content Credentials. Both updates have a priority 3 rating. Adobe says it is not aware of any exploits in the wild for the newly addressed vulnerabilities. Additional information can be found on Adobe’s security updates page. Related: Zoom Patches Zero-Click Code Execution Vulnerability Related: SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities Related: Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC Related: Metabase Patches Vulnerability Exploited as Zero-Day Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC ‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad Metabase Patches Vulnerability Exploited as Zero-Day CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability Corporate Data Stolen in Levi Strauss Cyberattack Vishing Extortion Group UNC6671 Rebrands After Making Millions Microsoft, Apple Release Fresh Security Updates 3.8 Million Impacted by Unlimited Technology Systems Data Breach Latest News Zoom Patches Zero-Click Code Execution Vulnerability The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities US Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’ Corma Raises $60 Million for Defensive Cybersecurity AI Model Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities Hacker Conversations: Marcus Hutchins and the Journey From the Gray Zone to Redemption OpenAI Unveils New Cybersecurity Model GPT-5.6-Cyber Trending Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Rethinking Cyber Defense for AI-Speed Attacks August 18, 2026 Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the Move 1Kosmos has named Frank Cohen Chief Revenue Officer. ServiceNow has appointed Simon Mouyal as Chief Marketing Officer. James Wilkinson has been named Chief Information Security Officer for the City of Dallas. More People On The Move Expert Insights The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It Organizations are rushing to implement AI without fully grasping where its legal protections begin and end. (Steve Durbin) Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries set for safe AI use. (Etay Maor) Timeless Compliance: Why Better Questions Beat Bigger Frameworks The best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. (Matt Honea) Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Flipboard Reddit Whatsapp Whatsapp Email
Adobe has released Priority 1 patches for critical vulnerabilities in ColdFusion and Campaign Classic, including an OS command injection (CVE-2026-48362, CVSS 10.0), an eval injection (CVE-2026-48273, CVSS 9.9), and multiple incorrect authorization flaws leading to arbitrary code execution. These flaws pose a high risk of in-the-wild exploitation. Adobe urges immediate patching for these products and recommends applying the Priority 2 update for Commerce within 30 days.