Adobe urges immediate patches for ColdFusion, Campaign Classic

Adobe on Tuesday urged customers to install priority 1 patches for ColdFusion and Campaign Classic to fix multiple critical code-execution, SQL injection and authorization vulnerabilities.

On Tuesday Adobe released updates addressing more than 50 security defects across its products and urged customers to install critical patches for ColdFusion and Campaign Classic immediately.

The ColdFusion update is assigned priority 1 and corrects 15 security defects, including three critical flaws that could allow arbitrary code execution or application denial-of-service. The flaws are an OS command injection tracked as CVE-2026-48362 (CVSS 10.0), an eval injection tracked as CVE-2026-48273 (CVSS 9.9), and an incorrect-authorization vulnerability tracked as CVE-2026-71384 (CVSS 9.6).

Campaign Classic also received a priority 1 update that addresses three critical issues that can lead to code execution: two incorrect-authorization flaws, CVE-2026-71398 and CVE-2026-27302 (both CVSS 10.0), and an SQL injection, CVE-2026-48381 (CVSS 9.0).

Adobe’s priority 1 designation indicates these defects have a higher risk of being targeted by attackers and the company instructed customers to apply those patches immediately.

The Commerce update fixes seven vulnerabilities, including an incorrect-authorization bug tracked as CVE-2026-71362 (CVSS 9.1) that could allow privilege escalation. Adobe assigned the Commerce refresh a priority 2 rating and recommended installations within 30 days because the product has been targeted in prior attacks.

Lightroom received fixes for 11 high-severity defects, and Content Credentials was updated for 15 high- and medium-severity issues. Both updates carry priority 3 ratings.

Adobe reported it is not aware of active exploits for the vulnerabilities addressed in this release. The company posted full technical details and installation guidance on its security updates page and advised administrators to follow the provided instructions to reduce exposure.

Articles by this author