Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

    August 13, 2026

    ASX Shareholder Plans Lawsuit Over Failed Blockchain Project

    August 13, 2026

    The adult brain can repair itself better than scientists thought

    August 13, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access
    • ASX Shareholder Plans Lawsuit Over Failed Blockchain Project
    • The adult brain can repair itself better than scientists thought
    • Indigenous groups renew legal challenge to Indonesian conservation law
    • Colombia earthquake rescue efforts enter ‘final phase’ as death toll rises
    • Nigel Farage paints himself as local hero in fight to win Clacton – POLITICO
    • Ex-Official at Southern Poverty Law Center Accused of Plotting to Misuse Far-Right Informants
    • Why Japanese firms are being so slow to use AI
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, August 13
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 13, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananAug 12, 2026Vulnerability / Web Security

    Adobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic that, if successfully exploited, could result in arbitrary code execution and privilege escalation.

    The most severe of the flaws are listed below –

    • CVE-2026-48362 (CVSS score: 10.0) – An operating system command injection vulnerability in ColdFusion that could lead to arbitrary code execution (Fixed in 2025.0.12 and 2023.0.23)
    • CVE-2026-48273 (CVSS score: 9.9) – An eval injection vulnerability in ColdFusion that could lead to arbitrary code execution (Fixed in 2025.0.12 and 2023.0.23)
    • CVE-2026-71384 (CVSS score: 9.6) – An incorrect authorization vulnerability in ColdFusion that could lead to an application denial-of-service (Fixed in 2025.0.12 and 2023.0.23)
    • CVE-2026-71362 (CVSS score: 9.1) – An incorrect authorization vulnerability in Commerce that could lead to privilege escalation
    • CVE-2026-71398 (CVSS score: 10.0) – An incorrect authorization vulnerability in Campaign Classic that could lead to arbitrary code execution (Fixed in ACC v7 7.4.4 build 9400)
    • CVE-2026-27302 (CVSS score: 10.0) – An incorrect authorization vulnerability in Campaign Classic that could lead to arbitrary code execution (Fixed in ACC v7 7.4.4 build 9400)
    • CVE-2026-48381 (CVSS score: 9.0) – An SQL injection vulnerability in Campaign Classic that could lead to arbitrary code execution (Fixed in ACC v7 7.4.4 build 9400)

    The updates for ColdFusion and Campaign Classic have a Priority 1 rating, which refers to vulnerabilities that have a higher risk of being targeted by malicious cyber attacks.

    Cybersecurity

    It’s worth noting that the Campaign Classic updates only apply to fully on-premise deployments and to the on-premise components of hybrid deployments. Adobe-hosted instances have already been remediated and require no customer action.

    Although there is no evidence of these flaws being exploited in the wild, administrators are recommended to install the update as soon as possible, preferably within 72 hours.

    The disclosure comes less than two weeks after Adobe released patches for a maximum-severity security flaw in Campaign Classic (CVE-2026-48449, CVSS score: 10.0) that could result in arbitrary code execution.

    Adobe campaign Classic ColdFusion CVSS flaws Patches
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

    Ceva Logistics Operations Disrupted by Cyberattack

    “City-Forum” data-theft attacks target Salesforce, ServiceNow portals

    WhatsApp Unveils New Scam Alert Feature

    Enterprise Defenses Recovered at the Edge and Collapsed Inside

    Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

    August 13, 2026

    ASX Shareholder Plans Lawsuit Over Failed Blockchain Project

    August 13, 2026

    The adult brain can repair itself better than scientists thought

    August 13, 2026

    Indigenous groups renew legal challenge to Indonesian conservation law

    August 13, 2026
    Latest Posts

    Record-breaking wildfires burned nearly 100,000 hectares in France, interior minister says – POLITICO

    July 25, 2026

    Former top US food safety official says Trump’s handling of cyclospora is ‘catastrophic’ | Trump administration

    July 25, 2026

    Did Trump collapse while trying to get into vehicle?

    July 25, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

    August 13, 2026

    ASX Shareholder Plans Lawsuit Over Failed Blockchain Project

    August 13, 2026

    The adult brain can repair itself better than scientists thought

    August 13, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.