>samit_hota
Back to security news

Security News · SN-2026-381

CRITICALCVE-2026-48362MITIGATED

Adobe Fixes Critical Code Execution Bugs in ColdFusion and Campaign

Affected: Adobe ColdFusion · Adobe Campaign Classic · Adobe Commerce · Adobe Lightroom · Adobe Content Credentials

Samit Hota·
#news#ransomware#adobe

Enterprise security operations teams face an immediate patching directive after Adobe released security updates for over 50 vulnerabilities across its enterprise software portfolio. The release highlights maximum-severity flaws in Adobe ColdFusion and Adobe Campaign Classic that permit remote arbitrary code execution, database compromise, and system-level control.

Because Adobe assigns its highest urgency rating to the updates for both ColdFusion and Campaign Classic, administrators should treat these patches as high-priority emergency deployments. While Adobe reports no evidence of active in-the-wild exploitation for these specific flaws at publication time, both platforms remain primary targets for threat actors seeking initial access into enterprise networks.

Critical ColdFusion Vulnerabilities

Adobe ColdFusion received a Priority 1 rating to address 15 total vulnerabilities, three of which carry critical severity ratings and open systems to application denial-of-service (DoS) or complete remote code execution (RCE).

The most severe flaw, tracked as CVE-2026-48362, is an OS command injection vulnerability rated with a maximum CVSS score of 10/10. OS command injection occurs when an application passes untrusted user input directly to a system shell or system execution function without sufficient sanitization or parameterization. An attacker who successfully leverages this vulnerability can execute arbitrary system commands with the privileges of the underlying ColdFusion service account, frequently resulting in full operating system compromise.

Two other critical ColdFusion issues addressed in this update include:

  • CVE-2026-48273 (CVSS 9.9): An eval injection vulnerability. Eval injection allows attackers to feed malicious code into dynamic language interpreter functions (such as dynamic CFML or Java evaluation routines), executing arbitrary code directly within the runtime environment.
  • CVE-2026-71384 (CVSS 9.6): An incorrect authorization vulnerability that allows unauthorized users to bypass permission checks and access restricted application functions or endpoints.

ColdFusion applications routinely interface with enterprise backend databases and internal corporate infrastructure. Successful exploitation of an RCE on a ColdFusion server typically serves as a bridge for lateral movement, privilege escalation, and active domain enumeration.

Campaign Classic and Commerce Security Updates

Adobe Campaign Classic—an enterprise cross-channel marketing automation platform—also received a Priority 1 security update covering three critical vulnerabilities capable of granting remote code execution:

  • CVE-2026-71398 and CVE-2026-27302 (CVSS 10/10): Critical incorrect authorization vulnerabilities that allow attackers to bypass security boundary controls and trigger code execution routines without proper credentials.
  • CVE-2026-48381 (CVSS 9.0): A high-severity SQL injection flaw. SQL injection vulnerabilities occur when user-supplied input is directly concatenated into database queries. Attackers can leverage this to read, modify, or delete backend marketing data, extract stored customer personally identifiable information (PII), or in certain server configurations, execute database administrative functions.

Separately, Adobe issued a Priority 2 security update for Adobe Commerce (formerly Magento), resolving seven vulnerabilities. Among these is CVE-2026-71362 (CVSS 9.1), an incorrect authorization defect leading to privilege escalation. Additional high-severity flaws fixed in Commerce include code execution bugs and security feature bypasses. Because e-commerce platforms like Adobe Commerce are historically targeted for web skimmer (Magecart) deployment and payment data harvesting, Adobe recommends applying this patch within 30 days.

Round out the patch cycle, Adobe resolved 11 high-severity flaws in Adobe Lightroom and 15 high- and medium-severity flaws in Content Credentials. Both received Priority 3 ratings, indicating lower risk of immediate targeting in typical enterprise threat models.

Risk Context and Blast Radius

Middle-tier enterprise applications like ColdFusion and Campaign Classic represent exceptionally attractive targets for threat actors ranging from ransomware affiliates to nation-state initial access brokers.

When an OS command injection bug like CVE-2026-48362 exists on a public-facing ColdFusion server, automated scanning scripts can discover and exploit the endpoint within hours of public disclosure or patch diffing. Because ColdFusion often runs with elevated service rights or sits on dual-homed network segments near core databases, an attacker who gains execution on the host can quickly deploy web shells, dump process memory to harvest credentials, and establish persistent command-and-control (C2) channels.

Similarly, Adobe Campaign Classic holds expansive access to customer relationship management (CRM) data, campaign databases, and communication relays. A successful breach of Campaign via SQL injection or authorization bypass risks widespread sensitive data exfiltration and potential misuse of messaging channels for spear-phishing or brand impersonation.

Organizations using affected Adobe products should prioritize the following remediation steps:

  1. Immediate Patching for Priority 1 Products: Apply the latest security updates for Adobe ColdFusion and Adobe Campaign Classic immediately. Prioritize public-facing instances, web application firewalls (WAFs), and external ingress gateways.
  2. Schedule Commerce Updates: Deploy patches for Adobe Commerce instances within a 30-day maintenance window, testing in staging environments to ensure checkout workflows remain operational.
  3. Audit Service Account Permissions: Ensure ColdFusion and Campaign application services run under least-privilege service accounts rather than local system or administrative accounts to limit the blast radius if an unpatched vulnerability is targeted.
  4. Inspect Logs for Anomalous Executions: Review web server, application, and database logs for unusual OS command invocation, unexpected SQL syntax errors, or untrusted access attempts directed at ColdFusion and Campaign endpoints.

Found something similar in your stack?

Let's find out before it becomes an incident.

Book an advisory call