Skip Navigation

August 12, 2026 |

Adobe patches critical ColdFusion and Campaign Classic vulnerabilities

Loading table of contents...

At a glance:

  • Updates available for multiple critical vulnerabilities in Adobe ColdFusion and Adobe Campaign Classic, several of which received a maximum CVSS score of 10.0.

  • Successful compromise could disrupt business applications, expose sensitive data, or provide access to connected systems.

  • Adobe reports no known exploitation of these vulnerabilities, however the company recently disclosed active exploitation of a separate ColdFusion vulnerability.

Threat summary

On August 11, 2026, Adobe released security updates for Adobe ColdFusion and Adobe Campaign Classic addressing multiple critical vulnerabilities, several of which received a maximum Common Vulnerability Scoring System (CVSS) score of 10.0.

Adobe assigned the two advisories a Priority 1 rating, indicating a higher risk of future targeting.

At the time of publication, Adobe reported no known exploitation of the vulnerabilities, which affect self-managed ColdFusion deployments and on-premises Adobe Campaign Classic environments.

ColdFusion is widely used to host customer portals, line-of-business applications, application programming interfaces (APIs), and internal web services. Campaign Classic is used for customer communications, marketing operations, and customer data management.

Because both products often process sensitive business and customer information, vulnerabilities affecting these platforms can have consequences beyond the affected server, including disruption of business operations and exposure of sensitive data.

The ColdFusion vulnerabilities affect:

  • ColdFusion 2025.0.11 and earlier

  • ColdFusion 2023.0.22 and earlier

Adobe released fixes in ColdFusion 2025 Update 12 (version 2025.0.12) and ColdFusion 2023 Update 23 (version 2023.0.23).

The Campaign Classic vulnerabilities affect Adobe Campaign Classic v7 version 7.4.3 build 9399 and earlier. Adobe released fixes in Campaign Classic v7 version 7.4.4 build 9400. The advisory applies to fully on-premises deployments and the on-premises components of hybrid deployments. Adobe-hosted instances were remediated before public disclosure.

ColdFusion vulnerabilities

The most significant ColdFusion vulnerabilities are CVE-2026-48362, CVE-2026-48273, and CVE-2026-71384, which could allow code execution or affect application availability.

CVE-2026-48362 (CVSS: 10.0)

CVE-2026-48362 is an operating system (OS) command injection vulnerability that could enable a threat actor to execute commands on the affected ColdFusion server.

Successful exploitation could result in compromise of the ColdFusion server, access to hosted applications and data, and potential access to connected systems depending on the server's permissions and role within the environment.

CVE-2026-48273 (CVSS: 9.9)

CVE-2026-48273 is an eval injection vulnerability that could enable a threat actor to execute code within the affected ColdFusion environment.

It could lead to compromise of applications running on the server, exposure of sensitive business data, and access to resources available to the affected application.

CVE-2026-71384 (CVSS: 9.6)

CVE-2026-71384 is an incorrect authorization vulnerability that could enable a threat actor to trigger application denial-of-service conditions.

Exploitation could disrupt customer-facing applications, application programming interfaces (APIs), and business services hosted on the affected ColdFusion instance.

Campaign Classic vulnerabilities

Adobe also addressed three Critical vulnerabilities in Campaign Classic that could affect customer communications platforms and marketing workflows.

CVE-2026-71398 (CVSS: 10.0)

CVE-2026-71398 is an incorrect authorization vulnerability affecting Adobe Campaign Classic that could result in arbitrary code execution.

A successful compromise could provide unauthorized access to customer communications workflows, marketing operations, and associated data.

CVE-2026-27302 (CVSS: 10.0)

CVE-2026-27302 is an incorrect authorization vulnerability affecting Adobe Campaign Classic that could result in arbitrary code execution.

The impact could include unauthorized access to application functionality, customer information, and systems integrated with Campaign Classic.

CVE-2026-48381 (CVSS: 9.0)

CVE-2026-48381 is a structured query language (SQL) injection vulnerability affecting Adobe Campaign Classic that could result in arbitrary code execution.

Exploitation could expose or alter customer data stored within Campaign Classic and potentially lead to compromise of the underlying application server.

Although Adobe reports no known exploitation of these vulnerabilities, the update arrives only weeks after the company disclosed active exploitation of ColdFusion vulnerability CVE-2026-48282. Adobe later confirmed limited exploitation in the wild, and security researchers reported observing activity shortly after technical details became public.

Analysis

For most organizations, the primary concern is the role these platforms play in daily operations. ColdFusion commonly supports customer-facing applications, authentication services, application programming interfaces (APIs), and internal business systems. Campaign Classic is often used to manage customer records and communications workflows. A successful compromise could disrupt business applications, expose sensitive information, or provide access to connected systems, depending on how the environment is configured.

Adobe has not publicly disclosed the specific conditions required to exploit these vulnerabilities, and available reporting provides limited technical detail beyond the vulnerability categories and potential impact.

However, recent ColdFusion activity demonstrates continued threat actor interest in exposed deployments and highlights how quickly newly disclosed vulnerabilities can attract attention. Advances in AI-assisted code analysis and vulnerability research have reduced the time required to analyze such disclosures and develop proof-of-concept code, increasing the importance of timely patching.

Organizations running ColdFusion or Campaign Classic are advised to apply Adobe's August 2026 updates, identify internet-facing deployments, and review monitoring coverage for systems that support business-critical applications and customer data.

ThreatRoundUp_SignUp_Simplifiedx2

Stay on top of emerging threats like this.

Sign up to receive a weekly roundup of our security intelligence feed. You'll be the first to know of emerging attack vectors, threats, and vulnerabilities. 

Sign up