<- ALL CYBER NEWS

Critical

Adobe, ColdFusion, Campaign Classic, CVE-2026-48362, Code Execution, Priority 1

Adobe ColdFusion CVE-2026-48362: Three CVSS 10.0 Flaws

Adobe ColdFusion CVE-2026-48362 leads three CVSS 10.0 code-execution flaws with Campaign Classic. Affected versions, fixes, and hardening.

Adobe ColdFusion CVE-2026-48362 Leads Three CVSS 10.0 Flaws in August Update

Adobe has patched three maximum-severity CVSS 10.0 vulnerabilities across ColdFusion and Campaign Classic, led by Adobe ColdFusion CVE-2026-48362, an OS command-injection flaw that allows arbitrary code execution. The two other perfect-10 bugs, CVE-2026-71398 and CVE-2026-27302, are incorrect-authorization flaws in Campaign Classic that also lead to code execution. Adobe rated the ColdFusion and Campaign Classic updates Priority 1, its highest-risk tier, and while none is reported exploited yet, ColdFusion's history says that window is short. Patch ColdFusion to 2025.0.12 or 2023.0.23 and Campaign Classic to ACC v7 7.4.4 build 9400 now.

The ColdFusion pair is the priority within the priority. CVE-2026-48362 (NVD, CVSS 10.0, CWE-78) is an operating-system command injection that hands an attacker arbitrary code execution, and it is joined by CVE-2026-48273 (CVSS 9.9), an eval-injection flaw with the same outcome, and CVE-2026-71384 (CVSS 9.6), an authorization defect that can force a denial of service. On the Campaign Classic side, CVE-2026-71398 and CVE-2026-27302 are both CVSS 10.0 incorrect-authorization bugs leading to code execution, alongside CVE-2026-48381 (CVSS 9.0), a SQL-injection flaw. Adobe Commerce also received a fix, CVE-2026-71362 (CVSS 9.1), for a privilege-escalation issue.

The reason "not yet exploited" should not buy much comfort here is ColdFusion's track record. ColdFusion flaws land on CISA's Known Exploited Vulnerabilities catalog with grim regularity, because ColdFusion processes often run under elevated or service accounts with write access to web directories, which turns command execution into durable web-shell persistence. An OS command-injection bug like CVE-2026-48362 is also among the easiest classes to reconstruct from a patch diff: attackers decompile the updated code, find the patched method, and build a working exploit while slower shops are still scheduling the update. A Priority 1 rating from Adobe is the vendor saying it expects exactly that.

How urgent is CVE-2026-48362 if it is not being exploited?

Treat it as patch-this-week, and sooner if your ColdFusion is internet-facing. A CVSS 10.0 OS command-injection on a platform with a long KEV history and easy patch-diffing is a textbook pre-exploitation window. Apply 2025.0.12 or 2023.0.23, then lock the ColdFusion administrator surface. Restrict /CFIDE/administrator and related REST and API sub-paths to management networks or a VPN via WAF rules or a reverse proxy, so that even an unpatched instance is not reachable by an anonymous attacker on the internet.

How do I check whether a ColdFusion server was already hit?

Hunt for the aftermath of command execution. Review web-root directories such as /CFIDE/ and your application roots for unexpected .cfm or .cfc files, the classic ColdFusion web-shell drop. In your endpoint and process telemetry, alert on any case where coldfusion.exe, cfserver.exe, or the underlying java.exe spawns a shell like cmd.exe, powershell.exe, or /bin/sh. In HTTP logs, look for anomalous POST requests to .cfm endpoints and traversal patterns in parameters.

CVE

Product

CVSS

Effect

CVE-2026-48362

ColdFusion

10.0

OS command injection, code execution

CVE-2026-48273

ColdFusion

9.9

Eval injection, code execution

CVE-2026-71398

Campaign Classic

10.0

Incorrect authorization, code execution

CVE-2026-27302

Campaign Classic

10.0

Incorrect authorization, code execution

CVE-2026-71362

Commerce

9.1

Incorrect authorization, privilege escalation

Fixes: ColdFusion 2025.0.12 and 2023.0.23; Campaign Classic ACC v7 7.4.4 build 9400.

Our read

Understanding risk means weighting the base rate, not just the current exploit status. ColdFusion is a platform attackers return to precisely because a single command-execution bug tends to convert into privileged, persistent access, and history says a Priority 1 ColdFusion 10.0 rarely stays theoretical for long. Our analysis of CISA's 2025 KEV data found that 67% of the year's actively exploited vulnerabilities would have been missed by an annual pentest, which is the gap between testing once and verifying continuously that an internet-facing app is patched and its admin surface is closed. Do not wait for CVE-2026-48362 to appear in KEV to treat it like it already has.

Reporting by The Hacker News; CVE severities, priority ratings, and fixed versions per Adobe's security bulletins and NVD. Sources linked above.

Related: JetBrains TeamCity CVE-2026-63077 under active exploitation · Metabase zero-day: unauthenticated SQL injection to admin

Liked this briefing? Share it:

More briefings

Related posts appear on the live page
Get the briefings first
Breaking security news, verified fast, with the one fact the headlines skip. No spam - unsubscribe anytime.