Skip to content
feed: live
>_ 0dayNews
adobe

Adobe Patches Critical Flaws in ColdFusion, Campaign Classic

Adobe patches critical RCE and DoS flaws in ColdFusion and Campaign Classic. Arbitrary code execution risk confirmed. Adobe explicitly urges immediate patching — act now.

Adobe Patches Critical Flaws in ColdFusion, Campaign Classic
Image: AI-generated — no human photographer / 0dayNews AI Cover (comfyui) · Generated on-site infrastructure — no external license
fuse Marisol "Fuse" Delgado · Published · 2 min read

Adobe pushed a round of critical security updates today for ColdFusion and Campaign Classic, patching flaws that could be exploited for arbitrary code execution and denial-of-service. Adobe is explicitly urging immediate patching — not “apply at next maintenance window,” not “assess risk.” Immediate.

That phrasing shows up in Adobe advisories when they already know exploitation is probable.

What Was Patched

Two product lines in today’s release:

ColdFusion — Adobe’s enterprise application server, used heavily in government agencies, financial institutions, and older enterprise web stacks. SecurityWeek classifies the flaws as critical, enabling arbitrary code execution. Full technical detail — CVE identifiers, CVSS scores, and affected build versions — is in Adobe’s security bulletins, linked from the SecurityWeek report.

Campaign Classic — Adobe’s on-premises marketing automation platform. Also carrying critical-rated flaws in today’s release.

Verify your affected version ranges against Adobe’s bulletin before declaring yourself clear. Patch Tuesday releases from Adobe sometimes cover multiple build lines and the affected ranges are specific.

Why You Should Care About ColdFusion Specifically

ColdFusion has been a target all summer.

CVE-2026-48282 — a CVSS 10.0 path-traversal-to-RCE — was exploited within 24 hours of Adobe’s July patch. Shadowserver tracked around 800 exposed instances at the time CISA added it to the Known Exploited Vulnerabilities catalog. The 72-hour patch window Adobe called for closed with active exploitation already confirmed.

If you’re running ColdFusion and already patched CVE-2026-48282, that doesn’t cover today’s advisory. These are different flaws.

If you haven’t patched CVE-2026-48282 yet, you have two separate problems now.

Campaign Classic Context

Campaign Classic had its own CVSS 10.0 incorrect authorization RCE (CVE-2026-48449) patched on August 1. Today’s release is separate from that fix. If you’re running ACC, you need both updates.

The access profile on Campaign Classic matters here: it typically sits on top of CRM systems and customer data stores. Code execution on the application server isn’t bounded by what the marketing department knows about — it’s bounded by what the platform can reach.

What to Do

If you run ColdFusion:

  1. Pull Adobe’s August 2026 ColdFusion security bulletin and identify your affected build.
  2. Apply the patch. If the instance is internet-accessible and you can’t patch in the next few hours, take it offline until you can. The July precedent shows exploitation moving fast on ColdFusion disclosures.
  3. If a managed service provider or hosting partner runs ColdFusion on your behalf, get a written confirmation that the update has been applied before assuming you’re protected.

If you run Campaign Classic:

  1. Confirm you applied the August 1 fix for CVE-2026-48449 first.
  2. Apply today’s update separately — they’re distinct patches.
  3. Audit the integration points: what CRM systems, databases, and downstream services can ACC reach? Map that now, before you need it for an IR report.

For both: Adobe’s bulletin will list the patched build versions. Verify your running version against it. Don’t assume vendor-managed instances are current — confirm it.

Adobe has had multiple critical code execution disclosures this summer. The response posture from threat actors has been fast. Treat this disclosure on the same timeline.

Track actively exploited CVEs on the KEV tracker.

Found this useful? Share it.