Multiple security vulnerabilities have been identified in Adobe ColdFusion and Campaign Classic products, which could lead to arbitrary code execution and application denial-of-service (DoS). Affected version range is not explicitly stated in the article. These vulnerabilities pose a high risk of being targeted in the wild.
CVE-2026-48362 (CVSS 10/10): An OS command injection vulnerability was identified in Adobe ColdFusion, which could lead to arbitrary code execution and application denial-of-service (DoS). The attacker capability is high as it allows for remote code execution.[/subscribe_to_unlock_form]
Multiple security vulnerabilities have been identified in Adobe ColdFusion and Campaign Classic products, which could lead to arbitrary code execution and application denial-of-service (DoS). Affected version range is not explicitly stated in the article. These vulnerabilities pose a high risk of being targeted in the wild.
CVE-2026-48362 (CVSS 10/10): An OS command injection vulnerability was identified in Adobe ColdFusion, which could lead to arbitrary code execution and application denial-of-service (DoS). The attacker capability is high as it allows for remote code execution.[emaillocker id="1283"]
CVE-2026-48273 (CVSS 9.9/10): An eval injection vulnerability was found in Adobe ColdFusion, which could lead to arbitrary code execution and application denial-of-service (DoS). The attacker capability is high as it allows for remote code execution.
CVE-2026-71384 (CVSS 9.6/10): An incorrect authorization vulnerability was identified in Adobe ColdFusion, which could lead to arbitrary code execution and application denial-of-service (DoS). The attacker capability is high as it allows for privilege escalation.
CVE-2026-71398 (CVSS 10/10): An incorrect authorization issue was found in Adobe Campaign Classic, leading to arbitrary code execution. The attacker capability is high as it allows for remote code execution.
CVE-2026-27302 (CVSS 10/10): An incorrect authorization issue was identified in Adobe Campaign Classic, leading to arbitrary code execution. The attacker capability is high as it allows for remote code execution.
CVE-2026-48381 (CVSS 9.0/10): An SQL injection bug was found in Adobe Campaign Classic, which could lead to arbitrary code execution and application denial-of-service (DoS). The attacker capability is medium-high as it requires some user interaction.
CVE-2026-71362 (CVSS 9.1/10): An incorrect authorization issue leading to privilege escalation was identified in Adobe Commerce. The attacker capability is high as it allows for remote code execution.
These vulnerabilities collectively present a significant risk of being targeted in the wild, particularly for users who have not applied the patches yet. Administrators should apply the updates immediately.
We recommend you to update ColdFusion to the given version link: https://helpx.adobe.com/security.html
The following reports contain further technical details:
[/emaillocker]