Adobe patches critical ColdFusion and other vulnerabilities
Adobe released updates fixing 88 vulnerabilities across 12 products, including eight critical ColdFusion bugs in ColdFusion 2025 Update 11 and ColdFusion 2023 Update 22.
Adobe released security updates on Tuesday that fix 88 vulnerabilities across 12 products, including eight critical ColdFusion flaws addressed in ColdFusion 2025 Update 11 and ColdFusion 2023 Update 22. The fixes cover a mix of remote code execution and privilege escalation bugs and carry a priority 1 remediation rating.
The ColdFusion updates repair 13 security defects. Eight of those are rated critical: CVE-2026-48318, CVE-2026-48322, CVE-2026-48284, CVE-2026-48321, CVE-2026-48325, CVE-2026-48319, CVE-2026-48324 and CVE-2026-48327. Adobe lists the root causes as path traversal, code injection, improper input validation, missing authentication, SQL injection and incorrect authorization. Any of these vulnerabilities could be used to run arbitrary code or to elevate privileges on affected systems. Adobe assigned the highest remediation priority and urged customers to apply the updates as soon as possible. ColdFusion 2025 Update 11 and ColdFusion 2023 Update 22 resolve all reported ColdFusion bugs.
Other updates in Tuesday’s advisory include Commerce, Experience Manager and Illustrator. Commerce received fixes for 13 vulnerabilities, including two critical issues tracked as CVE-2026-48356 and CVE-2026-48358 that could enable privilege escalation and arbitrary code execution. Experience Manager’s update closes 13 defects, with two critical flaws — CVE-2026-48259 and CVE-2026-48359 — that can be exploited for arbitrary code execution. Illustrator received five fixes, including a critical improper input validation bug tracked as CVE-2026-48334 that could allow privilege escalation.
Adobe also issued updates for Content Credentials SDK (12 vulnerabilities), Animate (6), Audition (6), Bridge (6), Media Encoder (5), Premiere Pro (4), After Effects (3) and the Creative Cloud Desktop Application (2). Adobe reported it is not aware of active exploitation for any of the newly disclosed issues.
The patches follow fixes issued two weeks earlier for six maximum-severity ColdFusion vulnerabilities, one of which was observed being exploited shortly after public disclosure. Adobe advised customers to review the vendor’s security bulletins and install the available updates promptly to reduce exposure.








