# Adobe Ships Emergency Patches for Three CVSS 10.0 Flaws Across ColdFusion and Campaign Classic


## The Threat


Adobe dropped a Priority 1 patch batch this week covering seven high-severity vulnerabilities across ColdFusion, Commerce, and Campaign Classic — including three that hit the maximum possible CVSS score of 10.0. The flaws span OS command injection, eval injection, authorization failures, and SQL injection, and the worst of them hand unauthenticated attackers a straight path to remote code execution on affected servers.


ColdFusion took the hardest hit. CVE-2026-48362, an OS command injection flaw, scores a perfect 10.0 and requires no authentication to exploit — an attacker who can reach the service can run arbitrary system commands. A second ColdFusion flaw, CVE-2026-48273, achieves code execution through eval injection and scores 9.9. Together, these two represent about the worst class of web application vulnerabilities possible: pre-auth RCE with no meaningful barrier to entry.


Campaign Classic got three patches of its own, two at CVSS 10.0. Both CVE-2026-71398 and CVE-2026-27302 are authorization failures that result in code execution — a pattern that suggests Adobe's Campaign Classic authentication layer has structural problems, not just isolated edge cases. This is the second Campaign Classic CVSS 10.0 batch in two weeks; a separate flaw, CVE-2026-48449, was patched less than a fortnight ago. On-premise and hybrid deployments are the exposure surface; Adobe's own cloud-hosted instances are already patched.


## Severity and Impact


| CVE | Product | CVSS Score | Vulnerability Type | Impact | CWE |

|-----|---------|------------|-------------------|--------|-----|

| CVE-2026-48362 | ColdFusion | 10.0 | OS Command Injection | Arbitrary Code Execution | CWE-78 |

| CVE-2026-48273 | ColdFusion | 9.9 | Eval Injection | Arbitrary Code Execution | CWE-95 |

| CVE-2026-71384 | ColdFusion | 9.6 | Incorrect Authorization | Application Denial of Service | CWE-863 |

| CVE-2026-71362 | Commerce | 9.1 | Incorrect Authorization | Privilege Escalation | CWE-863 |

| CVE-2026-71398 | Campaign Classic | 10.0 | Incorrect Authorization | Arbitrary Code Execution | CWE-863 |

| CVE-2026-27302 | Campaign Classic | 10.0 | Incorrect Authorization | Arbitrary Code Execution | CWE-863 |

| CVE-2026-48381 | Campaign Classic | 9.0 | SQL Injection | Arbitrary Code Execution | CWE-89 |


All ColdFusion and Campaign Classic entries carry Adobe's Priority 1 rating — reserved for flaws Adobe considers at elevated risk of active exploitation. No in-the-wild exploitation has been confirmed at time of publication, but Adobe is advising patch deployment within 72 hours.


## Affected Products


Adobe ColdFusion

  • ColdFusion 2025 — all versions prior to 2025.0.12
  • ColdFusion 2023 — all versions prior to 2023.0.23

  • Adobe Commerce

  • Versions affected by CVE-2026-71362 (see Adobe Security Bulletin for full version matrix)

  • Adobe Campaign Classic

  • ACC v7 — all builds prior to 7.4.4 build 9400
  • Applies to fully on-premise and on-premise components of hybrid deployments only
  • Adobe-hosted (cloud) Campaign Classic instances: already patched, no customer action required

  • ## Mitigations


    ColdFusion (Priority 1 — patch within 72 hours)

  • Upgrade to ColdFusion 2025.0.12 or ColdFusion 2023.0.23 immediately
  • If patching cannot happen within 72 hours, restrict ColdFusion admin console access at the network layer — do not expose it to the public internet under any circumstances
  • Audit ColdFusion server logs for unusual command execution or outbound connections

  • Campaign Classic (Priority 1 — patch within 72 hours)

  • Upgrade on-premise and hybrid on-premise components to ACC v7 build 7.4.4 (build 9400)
  • Adobe-hosted instances require no action
  • Review database access logs for anomalous query patterns that may indicate SQL injection attempts against CVE-2026-48381

  • Adobe Commerce

  • Apply the patch for CVE-2026-71362 per Adobe's Security Bulletin
  • Audit admin user roles and privilege assignments for any unexpected escalation

  • General hardening for all affected products

  • Ensure none of these services are directly internet-exposed without a WAF in front
  • Implement network segmentation so that a compromised app server cannot pivot laterally to internal databases or directory services
  • Enable alerting on privilege changes and new administrative account creation

  • ## References


  • [Adobe Security Bulletin APSB26 — ColdFusion](https://helpx.adobe.com/security/products/coldfusion.html)
  • [Adobe Security Bulletin — Campaign Classic](https://helpx.adobe.com/security/products/campaign.html)
  • [Adobe Security Bulletin — Commerce](https://helpx.adobe.com/security/products/magento.html)
  • [NIST NVD — CVE-2026-48362](https://nvd.nist.gov/vuln/detail/CVE-2026-48362)
  • [NIST NVD — CVE-2026-71398](https://nvd.nist.gov/vuln/detail/CVE-2026-71398)

  • ---


    ## HackWire Analysis


    The number that should stop enterprise security teams cold is not 10.0 — it's *two weeks*. Adobe patched a CVSS 10.0 Campaign Classic code execution flaw less than a fortnight ago (CVE-2026-48449), and here we are again with two more perfect-score Campaign Classic RCEs plus a SQL injection on top. That's four maximum-severity Campaign Classic flaws in rapid succession, all in the authorization and input-handling layers. This is not a run of bad luck — it's a signal that Adobe's Campaign Classic codebase has a structural trust problem, and the current patch-by-patch approach is not resolving it.


    ColdFusion's history makes this week's disclosure even more alarming. ColdFusion has been a recurring target for nation-state and ransomware actors for years — CISA has issued emergency directives about ColdFusion exploitation before. A pre-auth OS command injection at CVSS 10.0 is precisely the class of flaw that gets weaponized within days of public disclosure, not weeks. The 72-hour patch window Adobe recommends isn't conservative; it's probably already optimistic for organizations with slow change control processes.


    The practical exposure here is significant. ColdFusion remains common in government, healthcare, and financial services — sectors that often run older software stacks under extended support agreements. Any organization still on ColdFusion 2023 or 2025 without patching should treat this as an incident-in-waiting, not a routine patch cycle item.


    For Campaign Classic specifically, the on-premise and hybrid deployment footprint is where the real risk sits. Organizations that moved to Adobe-managed cloud hosting are fine — everyone else has a 72-hour window and should be burning it now. If you're running on-prem Campaign Classic and you haven't heard from your security team yet today, that's a problem worth escalating before end of business.


    — HackWire Editorial


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)