Adobe has released patches addressing multiple critical security flaws affecting ColdFusion, Commerce, and Campaign Classic This article explores vulnerability coldfusion capable. . These issues could enable attackers to execute arbitrary code and escalate privileges through successful exploitation.
The most severe vulnerabilities are listed below: - CVE-2026-48362 (CVSS score: 10.0) - An OS command injection vulnerability in ColdFusion that can lead to arbitrary code execution (Fixed in 2025.0.12 and 2023.0.23) - CVE-2026-48273 (CVSS score: 9.9) - An eval injection vulnerability in ColdFusion capable of causing arbitrary code execution (Fixed in 2025.0.12 and 2023.0.23) - CVE-2026-71384 (CVSS score: 9.6) - A misconfigured authorization flaw in ColdFusion that may result in a denial-of-service attack (Fixed in 2025.0.12 and 2023.0.23) - CVE-2026-71362 (CVSS score: 9.1) - An unauthorized access vulnerability in Commerce, potentially leading to privilege escalation - CVE-2026-71398 (CVSS score: 10.0) - A misconfigured authorization flaw in Campaign Classic that can lead to arbitrary code execution (Fixed in ACC v7 7.4.4 build 9400) - CVE-2026-27302 (CVSS score: 10.0) - Another misconfigured authorization vulnerability in Campaign Classic capable of causing arbitrary code execution (Fixed in ACC v7 7.4.4 build 9400) - CVE-2026-48381 (CVSS score: 9.0) - An SQL injection flaw in Campaign Classic that can enable arbitrary code execution (Fixed in ACC v7 7.4.4 build 9400) Updates for ColdFusion and Campaign Classic have a Priority 1 rating, indicating they pose significant risks of being targeted by malicious cyber attacks.
It's important to know that Campaign Classic updates are only applicable to fully on-premises deployments and the on-premise components of hybrid setups. Adobe-hosted instances have already been addressed, so customers don't need to take any action. Although there is no proof these flaws have been exploited in real-world scenarios, administrators should install the update as soon as possible, ideally within 72 hours.
The disclosure occurred just two weeks after Adobe released patches for a maximum-severity security flaw in Campaign Classic (CVE-2026-48449, CVSS score: 10.0), which could lead to arbitrary code execution.












