# Adobe Plugs 123 Vulnerabilities as ColdFusion, Campaign Classic Marked for Imminent Exploitation


## The Threat


Adobe's latest Patch Tuesday release delivers fixes for 123 vulnerabilities spanning 11 products, with nearly half residing in high-impact enterprise software. The advisory represents a significant security posture shift for organizations running Adobe's widely-deployed infrastructure tools, particularly those relying on Experience Manager, ColdFusion, and Campaign Classic in production environments.


The vulnerability landscape is split sharply between low-risk and critical categories. More than half the flaws are cross-site scripting (XSS) issues concentrated in Adobe Experience Manager, which allow attackers to execute arbitrary code within the context of vulnerable applications. While the majority have been assigned Adobe's priority rating of 3—indicating no expected exploitation—two critical vulnerabilities in Campaign Classic and several high-severity flaws in ColdFusion carry priority 1 ratings, signaling that Adobe expects threat actors will actively weaponize them. This distinction is not academic: ColdFusion has been the target of sustained threat actor interest for years, and the convergence of critical vulnerabilities with a history of exploitation creates immediate risk.


The patches address multiple attack vectors, including memory exposure, denial-of-service conditions, privilege escalation pathways, and security feature bypasses. While Adobe reports no current in-the-wild exploitation campaigns, the priority 1 designation suggests this window of opportunity is likely to close rapidly as exploit code propagates through underground channels.


## Severity and Impact


| Product | CVE Count | Critical (CVSS 9.0–10) | High (CVSS 7.0–8.9) | Max CVSS | Primary Attack Vector | Auth Required |

|---|---|---|---|---|---|---|

| Adobe Experience Manager | 57 | 4 | 18 | 8.8 | Network / XSS | None / Low |

| Adobe Campaign Classic | 2 | 2 | 0 | 10.0 | Network | None |

| ColdFusion | 7 | 1 | 5 | 9.1 | Network | None / Low |

| Acrobat & Reader (Win/Mac) | 20 | 2 | 8 | 9.8 | Local / Network | None |

| Dreamweaver | 3 | 1 | 1 | 9.4 | Network | Low |

| Experience Manager Forms | 2 | 1 | 0 | 9.8 | Network | None |

| InDesign | 2 | 1 | 0 | 9.6 | Network | None |

| InCopy | 2 | 1 | 0 | 9.6 | Network | None |

| Format Plugins | 2 | 1 | 0 | 8.8 | Network | Low |

| Substance 3D Sampler | 2 | 1 | 0 | 9.4 | Network | Low |

| Content Credentials SDK | 2 | 0 | 0 | 5.3 | Network | None |


Key Metrics: Two CVSS 10.0 vulnerabilities (Campaign Classic); six additional critical-severity code execution flaws across Experience Manager, ColdFusion, Acrobat, and creative tools; majority classified as improper input validation (CWE-20) and cross-site scripting (CWE-79).


## Affected Products


Critical Priority (1) – Expect Exploitation:

  • Adobe Campaign Classic (both flaws are CVSS 10.0 arbitrary code execution)
  • Adobe ColdFusion (7 vulnerabilities including critical privilege escalation and feature bypass)

  • High-Impact (Priority 2–3) – Enterprise Exposure:

  • Adobe Experience Manager (57 vulnerabilities, predominantly XSS; includes improper input validation bugs leading to feature bypass)
  • Acrobat and Reader for Windows and macOS (20 vulnerabilities spanning code execution, denial-of-service, and memory exposure)

  • Creative & Professional Tools:

  • Adobe Dreamweaver (3 vulnerabilities, including 1 critical code execution flaw)
  • Adobe InDesign (2 vulnerabilities including 1 critical code execution issue)
  • Adobe InCopy (2 vulnerabilities including 1 critical code execution issue)
  • Adobe Experience Manager Forms (2 vulnerabilities, 1 critical)

  • Supporting Platforms:

  • Adobe Format Plugins (2 vulnerabilities)
  • Substance 3D Sampler (2 vulnerabilities)
  • Adobe Content Credentials SDK (2 denial-of-service vulnerabilities)

  • ## Mitigations


    Immediate Actions (Next 72 Hours):

    1. Prioritize ColdFusion and Campaign Classic patching — these products carry priority 1 threat ratings and should be updated first, given the likely imminent availability of working exploits.

    2. Deploy patches for Acrobat and Reader across your organization — the 20 disclosed vulnerabilities include code execution flaws that could be leveraged in targeted phishing campaigns or watering-hole attacks.

    3. Patch Experience Manager instances to mitigate the XSS attack surface, particularly if your implementation is internet-facing or processes user-supplied content.


    Short-Term (1–2 Weeks):

  • Apply patches for Dreamweaver, InDesign, InCopy, and Experience Manager Forms if these tools are deployed in shared or multi-user environments.
  • Test patches in staging environments before production rollout to identify any compatibility issues with custom configurations or plugins.

  • Detection & Monitoring:

  • Review web application firewall (WAF) logs for suspicious input patterns targeting Experience Manager endpoints (look for XSS payload signatures).
  • Monitor ColdFusion application server logs for unusual template execution or privilege escalation attempts.
  • Implement SIEM rules to flag successful authentication followed immediately by unusual ColdFusion tag execution.

  • Network Segmentation:

  • Isolate ColdFusion servers from direct internet exposure where possible; place them behind application-aware proxies that can filter malicious input.
  • Restrict administrative console access to Campaign Classic and Experience Manager to internal networks or VPN-only.

  • Patch Management Strategy:

  • Establish a rolling patching schedule if immediate enterprise-wide updates are infeasible; prioritize systems processing sensitive data or exposed to untrusted input first.

  • ## References


  • Adobe Security Advisory: https://helpx.adobe.com/security/products/adobe_security_update.html
  • Adobe ColdFusion Security Updates: https://helpx.adobe.com/security/products/coldfusion.html
  • Adobe Campaign Classic Release Notes: https://experienceleague.adobe.com/en/docs/campaign-classic/using/release-notes/latest-release
  • Experience Manager Patch Notes: https://experienceleague.adobe.com/en/docs/experience-manager-release-information/aem-release-updates/release-updates-and-roadmaps

  • ---


    ## HackWire Analysis


    The sheer scale of this advisory—123 vulnerabilities across 11 products—masks a more granular risk picture that defenders must parse carefully. Adobe's priority ratings provide a critical lifeline: the fact that only two products (ColdFusion and Campaign Classic) earned priority 1 means organizations can triage intelligently rather than treating all 123 flaws as equally urgent. However, the priority 1 assignments carry outsized weight precisely *because* ColdFusion has been a persistent target. Threat actors maintain institutional knowledge of ColdFusion exploitation techniques from past campaigns, and the convergence of two critical code execution flaws with a proven attack surface suggests that exploit code could materialize within days, not weeks.


    The Experience Manager concentration—57 of 123 vulnerabilities—reflects the reality that Adobe's enterprise content management platform is a high-value target for supply-chain attacks. XSS flaws in CMS platforms are particularly dangerous because they can be weaponized to compromise not just the system itself, but downstream users who consume published content. Organizations running public-facing Experience Manager instances should deprioritize the majority of priority 3 flaws in favor of the four critical issues, which pose code execution risk.


    A secondary pattern emerges in the creative tools tier (Dreamweaver, InDesign, InCopy). The existence of critical code execution vulnerabilities in these products is notable because they're often perceived as "client-side" tools with lower attack surface than enterprise platforms. But in modern workflows—where design files are stored in networked repositories, shared via collaboration platforms, and processed by automated pipelines—a malicious file can become a vector for lateral movement through an organization's entire creative department.


    What's conspicuously absent from this advisory is any mention of in-the-wild exploitation. This grace period is likely to be brief. The responsible move for defenders is to treat priority 1 and critical-severity flaws as imminent threats and deprioritize the "known good" priority 3 flaws unless they directly impact your specific deployment model. — *HackWire Editorial*


    ---


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)