Adobe has released emergency security updates addressing 12 vulnerabilities across its ColdFusion and Campaign Classic products, including seven critical flaws rated at the maximum CVSS score of 10.0 that could allow unauthenticated attackers to execute arbitrary code on affected systems.
The most severe vulnerability, tracked as CVE-2026-48449 in Adobe Campaign Classic, is an incorrect authorization flaw (CWE-863) that enables attackers to execute arbitrary code without any user interaction. Adobe confirmed that its own hosted instances have already been remediated, but organizations running on-premises deployments must apply the patches manually.
The updates also address six critical vulnerabilities in Adobe ColdFusion versions 2025.9, 2023.20, and earlier (CVE-2026-48276, CVE-2026-48277, CVE-2026-48281, CVE-2026-48316, and CVE-2026-48282). These flaws can be exploited by attackers without privileges and allow arbitrary code execution, arbitrary file system reads, privilege escalation, security feature bypass, and cross-site scripting attacks.
A second Campaign Classic vulnerability, CVE-2026-48286, also received a CVSS score of 10.0 and stems from an authorization weakness that could let attackers execute arbitrary code. Together with CVE-2026-48449, the two Campaign Classic flaws represent a particularly dangerous combination for enterprise marketing teams that rely on the platform for customer communications and campaign automation.
Adobe’s advisory emphasized that the hosted Campaign Classic instances were patched before public disclosure, limiting the immediate risk for customers using Adobe’s cloud infrastructure. However, organizations operating self-managed Campaign Classic environments face significant exposure until they deploy the fixes. The company recommended that all customers update to the latest versions as soon as possible.
The batch of fixes arrives amid a particularly active period for enterprise software vulnerabilities. Cisco disclosed an actively exploited zero-day in its Firewall Management Center earlier this week, and security researchers have documented a surge in attacks targeting widely deployed enterprise applications. The concentration of maximum-severity flaws in a single Adobe update cycle underscores the ongoing challenge of securing complex enterprise software stacks.
Security teams are urged to prioritize patching, particularly for Campaign Classic deployments handling sensitive customer data. The vulnerabilities could allow attackers to gain full control of affected systems, potentially leading to data breaches, supply chain compromises, or use as a staging ground for lateral movement within corporate networks.
Sources: The Hacker News, BleepingComputer, Adobe Security Bulletin
Author: Technology Desk
discussion