Threat Advisory

Adobe ColdFusion Update Fixes 15 Flaws Including Critical Code Execution Vulnerabilities

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in Adobe ColdFusion and Campaign Classic products, which could lead to arbitrary code execution and application denial-of-service (DoS). Affected version range is not explicitly stated in the article. These vulnerabilities pose a high risk of being targeted in the wild.

CVE-2026-48362 (CVSS 10/10): An OS command injection vulnerability was identified in Adobe ColdFusion, which could lead to arbitrary code execution and application denial-of-service (DoS). The attacker capability is high as it allows for remote code execution.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in Adobe ColdFusion and Campaign Classic products, which could lead to arbitrary code execution and application denial-of-service (DoS). Affected version range is not explicitly stated in the article. These vulnerabilities pose a high risk of being targeted in the wild.

CVE-2026-48362 (CVSS 10/10): An OS command injection vulnerability was identified in Adobe ColdFusion, which could lead to arbitrary code execution and application denial-of-service (DoS). The attacker capability is high as it allows for remote code execution.[emaillocker id="1283"]

CVE-2026-48273 (CVSS 9.9/10): An eval injection vulnerability was found in Adobe ColdFusion, which could lead to arbitrary code execution and application denial-of-service (DoS). The attacker capability is high as it allows for remote code execution.

CVE-2026-71384 (CVSS 9.6/10): An incorrect authorization vulnerability was identified in Adobe ColdFusion, which could lead to arbitrary code execution and application denial-of-service (DoS). The attacker capability is high as it allows for privilege escalation.

CVE-2026-71398 (CVSS 10/10): An incorrect authorization issue was found in Adobe Campaign Classic, leading to arbitrary code execution. The attacker capability is high as it allows for remote code execution.

CVE-2026-27302 (CVSS 10/10): An incorrect authorization issue was identified in Adobe Campaign Classic, leading to arbitrary code execution. The attacker capability is high as it allows for remote code execution.

CVE-2026-48381 (CVSS 9.0/10): An SQL injection bug was found in Adobe Campaign Classic, which could lead to arbitrary code execution and application denial-of-service (DoS). The attacker capability is medium-high as it requires some user interaction.

CVE-2026-71362 (CVSS 9.1/10): An incorrect authorization issue leading to privilege escalation was identified in Adobe Commerce. The attacker capability is high as it allows for remote code execution.

These vulnerabilities collectively present a significant risk of being targeted in the wild, particularly for users who have not applied the patches yet. Administrators should apply the updates immediately.

RECOMMENDATION:

We recommend you to update ColdFusion to the given version link: https://helpx.adobe.com/security.html

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu