Threat Intelligence

Adobe Issues Urgent Patches for Critical ColdFusion and Campaign Classic Vulnerabilities

The Hacker News · 12 Aug 2026
Key Takeaway If your business uses Adobe ColdFusion, Commerce, or Campaign Classic, apply the latest security updates immediately to avoid being an easy target for attackers.

Adobe has released patches for a set of critical security flaws affecting ColdFusion, Commerce, and Campaign Classic. Several of these vulnerabilities carry the highest possible severity rating (CVSS 10.0), meaning they are extremely easy to exploit and could have severe consequences if left unaddressed.

One of the most serious issues, CVE-2026-48362, is a command injection vulnerability in ColdFusion. If exploited, it could allow an attacker to run arbitrary commands on the underlying operating system, potentially giving them full control of the affected system. Other flaws disclosed in this update could similarly lead to arbitrary code execution or privilege escalation, giving attackers deeper access than intended.

While these products are more commonly used by larger enterprises and web developers than typical small businesses, any organisation running ColdFusion-based websites, Adobe Commerce stores, or Campaign Classic marketing tools should treat this as an urgent update. Unpatched systems with maximum-severity vulnerabilities are prime targets for automated attacks, as threat actors often scan the internet for exploitable systems shortly after such flaws are made public.

Adobe ColdFusion Vulnerability Patch Management Critical Security Update

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.