# Adobe Ships Emergency Patches for Three CVSS 10.0 Flaws Across ColdFusion and Campaign Classic
## The Threat
Adobe dropped a Priority 1 patch batch this week covering seven high-severity vulnerabilities across ColdFusion, Commerce, and Campaign Classic — including three that hit the maximum possible CVSS score of 10.0. The flaws span OS command injection, eval injection, authorization failures, and SQL injection, and the worst of them hand unauthenticated attackers a straight path to remote code execution on affected servers.
ColdFusion took the hardest hit. CVE-2026-48362, an OS command injection flaw, scores a perfect 10.0 and requires no authentication to exploit — an attacker who can reach the service can run arbitrary system commands. A second ColdFusion flaw, CVE-2026-48273, achieves code execution through eval injection and scores 9.9. Together, these two represent about the worst class of web application vulnerabilities possible: pre-auth RCE with no meaningful barrier to entry.
Campaign Classic got three patches of its own, two at CVSS 10.0. Both CVE-2026-71398 and CVE-2026-27302 are authorization failures that result in code execution — a pattern that suggests Adobe's Campaign Classic authentication layer has structural problems, not just isolated edge cases. This is the second Campaign Classic CVSS 10.0 batch in two weeks; a separate flaw, CVE-2026-48449, was patched less than a fortnight ago. On-premise and hybrid deployments are the exposure surface; Adobe's own cloud-hosted instances are already patched.
## Severity and Impact
| CVE | Product | CVSS Score | Vulnerability Type | Impact | CWE |
|-----|---------|------------|-------------------|--------|-----|
| CVE-2026-48362 | ColdFusion | 10.0 | OS Command Injection | Arbitrary Code Execution | CWE-78 |
| CVE-2026-48273 | ColdFusion | 9.9 | Eval Injection | Arbitrary Code Execution | CWE-95 |
| CVE-2026-71384 | ColdFusion | 9.6 | Incorrect Authorization | Application Denial of Service | CWE-863 |
| CVE-2026-71362 | Commerce | 9.1 | Incorrect Authorization | Privilege Escalation | CWE-863 |
| CVE-2026-71398 | Campaign Classic | 10.0 | Incorrect Authorization | Arbitrary Code Execution | CWE-863 |
| CVE-2026-27302 | Campaign Classic | 10.0 | Incorrect Authorization | Arbitrary Code Execution | CWE-863 |
| CVE-2026-48381 | Campaign Classic | 9.0 | SQL Injection | Arbitrary Code Execution | CWE-89 |
All ColdFusion and Campaign Classic entries carry Adobe's Priority 1 rating — reserved for flaws Adobe considers at elevated risk of active exploitation. No in-the-wild exploitation has been confirmed at time of publication, but Adobe is advising patch deployment within 72 hours.
## Affected Products
Adobe ColdFusion
Adobe Commerce
Adobe Campaign Classic
## Mitigations
ColdFusion (Priority 1 — patch within 72 hours)
Campaign Classic (Priority 1 — patch within 72 hours)
Adobe Commerce
General hardening for all affected products
## References
---
## HackWire Analysis
The number that should stop enterprise security teams cold is not 10.0 — it's *two weeks*. Adobe patched a CVSS 10.0 Campaign Classic code execution flaw less than a fortnight ago (CVE-2026-48449), and here we are again with two more perfect-score Campaign Classic RCEs plus a SQL injection on top. That's four maximum-severity Campaign Classic flaws in rapid succession, all in the authorization and input-handling layers. This is not a run of bad luck — it's a signal that Adobe's Campaign Classic codebase has a structural trust problem, and the current patch-by-patch approach is not resolving it.
ColdFusion's history makes this week's disclosure even more alarming. ColdFusion has been a recurring target for nation-state and ransomware actors for years — CISA has issued emergency directives about ColdFusion exploitation before. A pre-auth OS command injection at CVSS 10.0 is precisely the class of flaw that gets weaponized within days of public disclosure, not weeks. The 72-hour patch window Adobe recommends isn't conservative; it's probably already optimistic for organizations with slow change control processes.
The practical exposure here is significant. ColdFusion remains common in government, healthcare, and financial services — sectors that often run older software stacks under extended support agreements. Any organization still on ColdFusion 2023 or 2025 without patching should treat this as an incident-in-waiting, not a routine patch cycle item.
For Campaign Classic specifically, the on-premise and hybrid deployment footprint is where the real risk sits. Organizations that moved to Adobe-managed cloud hosting are fine — everyone else has a 72-hour window and should be burning it now. If you're running on-prem Campaign Classic and you haven't heard from your security team yet today, that's a problem worth escalating before end of business.
— HackWire Editorial
## Related Coverage