CVE Tools
Back to feed
Patch released ColdFusion web-app Commerce Adobe rce

Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

The Hacker News·By The Hacker News··2 min read
CVE Tools coverage

Adobe has distributed security updates for its ColdFusion, Commerce, and Campaign Classic platforms to resolve multiple high-severity vulnerabilities that could enable remote code execution and privilege escalation. Among the patched issues are three defects with a maximum CVSS score of 10.0: two incorrect authorization flaws in Campaign Classic (CVE-2026-71398 and CVE-2026-27302) and one operating system command injection vulnerability in ColdFusion (CVE-2026-48362). Additionally, an eval injection flaw in ColdFusion (CVE-2026-48273) and incorrect authorization weaknesses in both ColdFusion and Commerce are addressed.

No active exploitation of these specific bugs has been observed, but Adobe rates the updates as Priority 1 due to the significant risk they pose. Administrators should apply the fixes immediately, ideally within 72 hours. For ColdFusion, users must upgrade to versions 2025.0.12 or 2023.0.23, while Campaign Classic on-premise and hybrid deployments need to be updated to ACC v7 7.4.4 build 9400; note that Adobe-hosted instances do not require manual intervention.