August 14, 2026
By esentry Team

Critical Adobe Vulnerabilities Create Potential Remote Code Execution Risk

Adobe has released security updates addressing multiple critical vulnerabilities in Adobe ColdFusion and Adobe Campaign Classic, including three vulnerabilities rated CVSS 10.0, the highest possible severity rating.

The vulnerabilities could allow attackers to execute arbitrary code on affected systems, potentially resulting in full compromise of the application server. Adobe has classified the affected products as Priority 1, recommending that customers apply the available updates as soon as possible.

At the time of disclosure, Adobe reported that it was not aware of active exploitation of these specific vulnerabilities.

Vulnerabilities Identified

CVE-2026-48362 – Adobe ColdFusion

CVSS: 10.0 | Critical

This is an OS command injection vulnerability that could allow an attacker to execute arbitrary operating-system commands on an affected ColdFusion server.

Potential impact:

  • Remote code execution
  • Compromise of the ColdFusion server
  • Unauthorized access to application data
  • Installation of malicious software
  • Use of the server as a foothold for further attacks

Affected versions:

  • ColdFusion 2025.0.11 and earlier
  • ColdFusion 2023.0.22 and earlier

Fixed versions:

  • ColdFusion 2025.0.12
  • ColdFusion 2023.0.23

CVE-2026-48273 – Adobe ColdFusion

CVSS: 9.9 | Critical

This eval injection vulnerability could allow attacker-controlled input to be interpreted and executed as application code, potentially resulting in arbitrary code execution.

Potential impact:

  • Application compromise
  • Arbitrary code execution
  • Unauthorized access to sensitive information
  • Potential compromise of the underlying server

Fixed versions:

  • ColdFusion 2025.0.12
  • ColdFusion 2023.0.23

CVE-2026-71398 – Adobe Campaign Classic

CVSS: 10.0 | Critical

This incorrect authorization vulnerability could allow an unauthenticated attacker to execute arbitrary code on affected Campaign Classic installations.

Potential impact:

  • Unauthorized access to application functionality
  • Remote code execution
  • Server compromise
  • Potential exposure of customer and campaign-related information
  • Further access to connected systems

Affected version:

  • Campaign Classic v7.4.3 build 9399 and earlier

Fixed version:

  • Campaign Classic v7.4.4 build 9400

Adobe notes that this vulnerability affects on-premises and hybrid deployments. Adobe-hosted Campaign Classic environments have already been remediated.

Why This Is Important

These vulnerabilities are particularly concerning because successful exploitation could allow an attacker to execute malicious code directly on an affected server. If exploited, an attacker could potentially:

  • Take control of the affected ColdFusion or Campaign Classic server.  
  • Access sensitive application and business data.  
  • Install malware or establish persistence on the compromised system.  
  • Steal credentials or other information stored on the server.  
  • Modify application files or configurations.  
  • Use the compromised server as a foothold to move further into the organization's environment.

Recommended Actions

Organizations using Adobe ColdFusion or Campaign Classic should:

  • Identify all affected deployments and verify their installed versions/builds.
  • Apply the appropriate Adobe security updates immediately.
  • Upgrade ColdFusion to 2025.0.12 or later or 2023.0.23 or later.
  • Upgrade affected Campaign Classic installations to v7.4.4 build 9400 or later.
  • Prioritize internet-facing systems for immediate remediation.
  • Restrict unnecessary external access to ColdFusion and Campaign Classic administrative interfaces.
  • Review application and server logs for suspicious requests, unexpected administrative activity, unusual processes or unauthorized changes.
  • Monitor affected systems for abnormal outbound connections and other indicators of compromise.
  • If suspicious activity is identified, conduct a compromise assessment rather than relying on patching alone.