Adobe Releases Critical Security Updates for ColdFusion and Campaign Classic

Adobe has issued critical security updates for its ColdFusion and Campaign Classic products, addressing multiple vulnerabilities that could lead to arbitrary code execution and privilege escalation.

The most severe vulnerabilities include:

  • CVE-2026-48362: An operating system command injection flaw in ColdFusion, allowing arbitrary code execution. This has been fixed in versions 2025.0.12 and 2023.0.23.
  • CVE-2026-48273: An eval injection vulnerability in ColdFusion, also leading to arbitrary code execution. Resolved in versions 2025.0.12 and 2023.0.23.
  • CVE-2026-71384: An incorrect authorization issue in ColdFusion that could result in application denial-of-service. Addressed in versions 2025.0.12 and 2023.0.23.
  • CVE-2026-71398: An incorrect authorization vulnerability in Campaign Classic, enabling arbitrary code execution. Fixed in ACC v7 7.4.4 build 9400.
  • CVE-2026-27302: Another incorrect authorization flaw in Campaign Classic, leading to arbitrary code execution. Resolved in ACC v7 7.4.4 build 9400.
  • CVE-2026-48381: An SQL injection vulnerability in Campaign Classic, potentially resulting in arbitrary code execution. Fixed in ACC v7 7.4.4 build 9400.

These updates have been assigned a Priority 1 rating, indicating a higher risk of exploitation. Notably, the Campaign Classic updates apply to fully on-premise deployments and the on-premise components of hybrid deployments. Adobe-hosted instances have already been patched and require no customer action.

While there is no evidence of these vulnerabilities being exploited in the wild, administrators are strongly advised to install the updates promptly, preferably within 72 hours.

This release follows Adobe’s recent patch for a maximum-severity security flaw in Campaign Classic (CVE-2026-48449), which could also result in arbitrary code execution.

Given the critical nature of these vulnerabilities, organizations using Adobe ColdFusion and Campaign Classic should prioritize these updates to safeguard their systems against potential threats.