Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Ceva Logistics Operations Disrupted by Cyberattack

    August 13, 2026

    China’s DeepSeek Upgrades V4 Pro: Claude Fable Is Only 5% Better at 4,500% the Price

    August 13, 2026

    3,500-year-old skeletons challenge what scientists thought they knew about syphilis

    August 13, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Ceva Logistics Operations Disrupted by Cyberattack
    • China’s DeepSeek Upgrades V4 Pro: Claude Fable Is Only 5% Better at 4,500% the Price
    • 3,500-year-old skeletons challenge what scientists thought they knew about syphilis
    • Vultures are disappearing in Nigeria – but the ‘vulture king’ and others are fighting back
    • Australia politics live: Angus Taylor rebukes Andrew Bragg for expressing ‘personal views’ on migration numbers; Chris Minns steps in to deflect melon-gate question to PM | Australia news
    • Treasury Scales Back Scrutiny of U.S. Shell Companies
    • Hong’s Defeat in Wisconsin Sparks New Disagreements Within Democratic Party
    • Google’s Pixel 11 phone preorders come with up to $350 in gift cards
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, August 13
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 13, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananAug 12, 2026Vulnerability / Web Security

    Adobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic that, if successfully exploited, could result in arbitrary code execution and privilege escalation.

    The most severe of the flaws are listed below –

    • CVE-2026-48362 (CVSS score: 10.0) – An operating system command injection vulnerability in ColdFusion that could lead to arbitrary code execution (Fixed in 2025.0.12 and 2023.0.23)
    • CVE-2026-48273 (CVSS score: 9.9) – An eval injection vulnerability in ColdFusion that could lead to arbitrary code execution (Fixed in 2025.0.12 and 2023.0.23)
    • CVE-2026-71384 (CVSS score: 9.6) – An incorrect authorization vulnerability in ColdFusion that could lead to an application denial-of-service (Fixed in 2025.0.12 and 2023.0.23)
    • CVE-2026-71362 (CVSS score: 9.1) – An incorrect authorization vulnerability in Commerce that could lead to privilege escalation
    • CVE-2026-71398 (CVSS score: 10.0) – An incorrect authorization vulnerability in Campaign Classic that could lead to arbitrary code execution (Fixed in ACC v7 7.4.4 build 9400)
    • CVE-2026-27302 (CVSS score: 10.0) – An incorrect authorization vulnerability in Campaign Classic that could lead to arbitrary code execution (Fixed in ACC v7 7.4.4 build 9400)
    • CVE-2026-48381 (CVSS score: 9.0) – An SQL injection vulnerability in Campaign Classic that could lead to arbitrary code execution (Fixed in ACC v7 7.4.4 build 9400)

    The updates for ColdFusion and Campaign Classic have a Priority 1 rating, which refers to vulnerabilities that have a higher risk of being targeted by malicious cyber attacks.

    Cybersecurity

    It’s worth noting that the Campaign Classic updates only apply to fully on-premise deployments and to the on-premise components of hybrid deployments. Adobe-hosted instances have already been remediated and require no customer action.

    Although there is no evidence of these flaws being exploited in the wild, administrators are recommended to install the update as soon as possible, preferably within 72 hours.

    The disclosure comes less than two weeks after Adobe released patches for a maximum-severity security flaw in Campaign Classic (CVE-2026-48449, CVSS score: 10.0) that could result in arbitrary code execution.

    Adobe campaign Classic ColdFusion CVSS flaws Patches
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Ceva Logistics Operations Disrupted by Cyberattack

    “City-Forum” data-theft attacks target Salesforce, ServiceNow portals

    WhatsApp Unveils New Scam Alert Feature

    Enterprise Defenses Recovered at the Edge and Collapsed Inside

    Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

    OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models’ Reasoning

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Ceva Logistics Operations Disrupted by Cyberattack

    August 13, 2026

    China’s DeepSeek Upgrades V4 Pro: Claude Fable Is Only 5% Better at 4,500% the Price

    August 13, 2026

    3,500-year-old skeletons challenge what scientists thought they knew about syphilis

    August 13, 2026

    Vultures are disappearing in Nigeria – but the ‘vulture king’ and others are fighting back

    August 13, 2026
    Latest Posts

    Record-breaking wildfires burned nearly 100,000 hectares in France, interior minister says – POLITICO

    July 25, 2026

    Former top US food safety official says Trump’s handling of cyclospora is ‘catastrophic’ | Trump administration

    July 25, 2026

    Did Trump collapse while trying to get into vehicle?

    July 25, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Ceva Logistics Operations Disrupted by Cyberattack

    August 13, 2026

    China’s DeepSeek Upgrades V4 Pro: Claude Fable Is Only 5% Better at 4,500% the Price

    August 13, 2026

    3,500-year-old skeletons challenge what scientists thought they knew about syphilis

    August 13, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.