Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws
Adobe patches seven flaws in ColdFusion, Commerce, and Campaign Classic, including actively exploited CVE-2026-71362 enabling customer account takeover.
Adobe issued Priority 1 updates fixing CVSS 10.0 flaws in ColdFusion (CVE-2026-48362, OS command injection) and Campaign Classic (CVE-2026-71398, CVE-2026-27302, incorrect authorization), plus CVE-2026-71362 (CVSS 9.1) in Adobe Commerce and Magento Open Source. Sansec reports threat actors are actively exploiting CVE-2026-71362 to switch customer sessions to other accounts and access private customer data. Adobe-hosted Campaign Classic instances are already remediated, while on-premise deployments are urged to patch within 72 hours. ColdFusion fixes ship in versions 2025.0.12 and 2023.0.23, and Campaign Classic fixes in v7 7.4.4 build 9400.
- CVE-2026-48362, CVE-2026-71398 and CVE-2026-27302 are rated CVSS 10.0 and marked Priority 1 by Adobe
- Sansec observed attackers exploiting CVE-2026-71362 to hijack customer sessions in Commerce and Magento
- ColdFusion fixes ship in 2025.0.12 and 2023.0.23; Campaign Classic fixes in 7.4.4 build 9400
- Adobe-hosted Campaign Classic instances already remediated; on-premise deployments must act quickly
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-71398 | Unauthenticated RCE in Adobe Campaign Classic via Incorrect Authorization Adobe Campaign Classic contains an incorrect authorization flaw (CWE-863) that allows an unauthenticated remote attacker to execute arbitrary code in the context of the current user. The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:C) indicates the flaw is reachable over the network with no privileges and no user interaction, and the changed scope shows the executed code crosses a security boundary, meaning a request to a vulnerable Campaign Classic instance can lead to code running beyond the application layer. A successful attacker gains code execution with high impact to confidentiality, integrity, and availability on the affected server. Organizations running Adobe Campaign Classic — typically large enterprises operating on-premises or hybrid marketing infrastructure — are affected; the available data does not specify affected version ranges, so defenders should consult the Adobe security bulletin for exact builds. There is currently no evidence of in-the-wild exploitation, no known public proof-of-concept, and the flaw is not in CISA's KEV; EPSS assigns a 0.8% probability of exploitation within 30 days (54th percentile). Do: Patch Campaign Classic to the fixed release identified in the Adobe security bulletin for this CVE, verifying the exact affected and fixed builds there since version ranges were not included in this data. Until patched, restrict network access to Campaign Classic servers from untrusted networks and review application and system logs for unexpected process or command execution. If your instances are hosted or managed by Adobe, confirm with Adobe that hosted environments have already been remediated. | 10.0 group max | <1% |
| nichelikely hundreds to low thousands of server instances across enterprise deployments (no public install-count data) | ||
| CVE-2026-48273 | Eval Injection RCE in Adobe ColdFusion (CVSS 9.9, low-privileged attacker) CVE-2026-48273 is a critical (CVSS 9.9) eval injection flaw (CWE-95) in Adobe ColdFusion in which untrusted input is not properly neutralized before it is placed into dynamically evaluated code. A remote attacker who has only low-privileged access to a vulnerable ColdFusion server can trigger the flaw over the network, with no user interaction required. Successful exploitation yields arbitrary code execution in the context of the current user, and the changed CVSS scope (S:C) indicates the impact can extend beyond the directly vulnerable component, a pattern typical of ColdFusion flaws that enable broader system-level code execution. All Adobe ColdFusion deployments are potentially affected; the source data does not specify affected version ranges, so admins should consult Adobe's bulletin for the exact versions fixed. As of this writing there is no known public proof-of-concept and the flaw is not in CISA KEV, though EPSS assigns a 1.7% probability of exploitation within 30 days; the fix shipped in Adobe's large recent patch batch, which also addressed three CVSS 10.0 ColdFusion and Campaign Classic flaws. Do: Apply the Adobe ColdFusion security update covering this CVE from the current patch batch immediately on all ColdFusion servers, prioritizing any that are internet-exposed, and confirm your exact version against Adobe's bulletin since fixed versions are not listed here. Because only low-privileged access is required and no user interaction is needed, audit which accounts and request paths feed untrusted input into dynamically evaluated expressions and restrict or validate such inputs. No public PoC or known exploitation exists yet, so monitor Adobe advisories and threat feeds for updated indicators of compromise. | 9.9 | 2% |
| large~tens of thousands of internet-exposed ColdFusion servers (estimate; Adobe does not publish install counts) | ||
| CVE-2026-48362 +1 in the same advisory: …71384 | Unauthenticated OS Command Injection RCE in Adobe ColdFusion Adobe ColdFusion is affected by an OS command injection vulnerability (CWE-78, Improper Neutralization of Special Elements used in an OS Command) rated critical at CVSS 10.0. It is triggered over the network with no authentication and no user interaction (AV:N/AC:L/PR:N/UI:N), so any network-accessible ColdFusion server is directly reachable by an unauthenticated attacker. Successful exploitation yields arbitrary code execution in the context of the current user, and the changed scope (S:C) indicates the injected commands can impact resources beyond the vulnerable ColdFusion component itself, such as other services or systems reachable from it. All ColdFusion deployments are plausibly affected; the data does not specify affected or fixed version ranges, so administrators should check Adobe's security bulletin (the related coverage notes Adobe patched this flaw alongside Campaign Classic issues). Exploitation has not been confirmed: it is not in CISA KEV and no public proof-of-concept is known, though EPSS assigns a 4.3% probability of exploitation within 30 days (91st percentile), warranting prompt patching. Do: Apply the ColdFusion security update published in Adobe's security bulletin as the primary fix, prioritizing internet-facing ColdFusion servers because the vector is network-based and unauthenticated; check the bulletin for exact affected and fixed version numbers, which were not included in this data. As interim mitigation, restrict network access to ColdFusion services and review web and access logs for signs of command-execution or probing activity given the elevated EPSS score. | 10.0 group max | 4% |
| largetens of thousands of installations, with only a few thousand likely internet-exposed | ||
| CVE-2026-48449 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2026-71362 | Unauthenticated Privilege Escalation Flaw in Adobe Commerce (Magento) CVE-2026-71362 is an incorrect-authorization flaw (CWE-863) in Adobe Commerce, the e-commerce platform formerly known as Magento, in which authorization checks are applied incorrectly and can be bypassed. It is triggered over the network without authentication or user interaction, per the CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N). A successful attacker gains elevated access to sensitive resources — a privilege-escalation condition that Adobe's APSB26-92 advisory and press coverage describe as an account-takeover risk. Any organization running an unpatched Adobe Commerce/Magento deployment is affected; exact version ranges are listed in Adobe security bulletin APSB26-92. The flaw came under active attack shortly after public disclosure, and its EPSS score of 25.1% (98th percentile) signals a high likelihood of continued near-term exploitation. Do: Apply the fix released under Adobe advisory APSB26-92 immediately, prioritizing internet-facing Commerce/Magento instances, and check the bulletin for the exact patched version ranges for your deployment. Because exploitation requires no credentials or user interaction, review admin accounts, API integrations, and user/role assignments for unauthorized privilege changes, and restrict admin-panel and storefront API access where feasible. Monitor Adobe's advisory for indicators of compromise given confirmed in-the-wild exploitation. | 9.1 | 25% |
| mass≈200,000+ Magento/Adobe Commerce storefronts worldwide |
Full article426 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananAug 12, 2026Vulnerability / Web Security
Adobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic that, if successfully exploited, could result in arbitrary code execution and privilege escalation.
The most severe of the flaws are listed below -
- CVE-2026-48362 (CVSS score: 10.0) - An operating system command injection vulnerability in ColdFusion that could lead to arbitrary code execution (Fixed in 2025.0.12 and 2023.0.23)
- CVE-2026-48273 (CVSS score: 9.9) - An eval injection vulnerability in ColdFusion that could lead to arbitrary code execution (Fixed in 2025.0.12 and 2023.0.23)
- CVE-2026-71384 (CVSS score: 9.6) - An incorrect authorization vulnerability in ColdFusion that could lead to an application denial-of-service (Fixed in 2025.0.12 and 2023.0.23)
- CVE-2026-71362 (CVSS score: 9.1) - An incorrect authorization vulnerability in Commerce that could lead to privilege escalation
- CVE-2026-71398 (CVSS score: 10.0) - An incorrect authorization vulnerability in Campaign Classic that could lead to arbitrary code execution (Fixed in ACC v7 7.4.4 build 9400)
- CVE-2026-27302 (CVSS score: 10.0) - An incorrect authorization vulnerability in Campaign Classic that could lead to arbitrary code execution (Fixed in ACC v7 7.4.4 build 9400)
- CVE-2026-48381 (CVSS score: 9.0) - An SQL injection vulnerability in Campaign Classic that could lead to arbitrary code execution (Fixed in ACC v7 7.4.4 build 9400)
The updates for ColdFusion and Campaign Classic have a Priority 1 rating, which refers to vulnerabilities that have a higher risk of being targeted by malicious cyber attacks.
It's worth noting that the Campaign Classic updates only apply to fully on-premise deployments and to the on-premise components of hybrid deployments. Adobe-hosted instances have already been remediated and require no customer action.
Although there is no evidence of these flaws being exploited in the wild, administrators are recommended to install the update as soon as possible, preferably within 72 hours.
The disclosure comes less than two weeks after Adobe released patches for a maximum-severity security flaw in Campaign Classic (CVE-2026-48449, CVSS score: 10.0) that could result in arbitrary code execution.
Update
Indications have emerged that threat actors are exploiting CVE-2026-71362, a critical flaw in Adobe Commerce and Magento Open Source, according to Sansec.
"The vulnerability lets attackers switch a customer session to another customer account," the Dutch e-commerce security company said. "This gives them access to the victim's account and private customer data."
(The story was updated after publication on August 13, 2026, to include additional insights from Sansec.)
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/08/adobe-patches-three-cvss-100-coldfusion.html