Adobe Patches Three CVSS 10.0 Flaws in ColdFusion and Campaign Classic, Led by CVE-2026-48362

Adobe's mid-August release patches three CVSS 10.0 flaws — one in ColdFusion (CVE-2026-48362, an OS command injection) and two in Campaign Classic — alongside a critical Commerce fix. No exploitation is known yet, but Adobe rates the updates Priority 1 and advises patching within 72 hours.

Share
Flat white line-art of three servers labeled ColdFusion, Commerce, and Campaign Classic with one flat red dot on a deep cyber-navy background.

Adobe's mid-August security release closes multiple critical vulnerabilities across three enterprise products — ColdFusion, Commerce, and Campaign Classic — that could result in arbitrary code execution and privilege escalation. Three of the fixed flaws carry the maximum CVSS score of 10.0, and the one to sequence first is CVE-2026-48362, an operating-system command injection in ColdFusion.

Read the batch precisely, because the product list and the 10.0 list are not the same set. Adobe's August 2026 update patches three CVSS 10.0 vulnerabilities — CVE-2026-48362 in ColdFusion, and CVE-2026-71398 and CVE-2026-27302 in Campaign Classic — all three of which can lead to arbitrary code execution. Commerce is in the same release but its most severe issue, CVE-2026-71362, is rated 9.1, not 10.0. The Hacker News reports Adobe has seen no evidence of exploitation in the wild, yet the vendor rates the ColdFusion and Campaign Classic updates Priority 1 and recommends installing them within 72 hours.

The Three Maximum-Severity Flaws

CVE-2026-48362 (ColdFusion, CVSS 10.0) is an OS command injection that can lead to arbitrary code execution on the ColdFusion server. Per Adobe's advisory APSB26-90, the fix ships in ColdFusion 2025.0.12 and 2023.0.23. A command-injection flaw on an application server is the category defenders least want to see, because a single successful request can hand an attacker code execution in the server's context — and ColdFusion servers frequently sit at the front of an application stack, reachable from the network.

CVE-2026-71398 and CVE-2026-27302 (Campaign Classic, CVSS 10.0) are both incorrect-authorization flaws that can lead to arbitrary code execution. Adobe's advisory APSB26-123 lists the fix as ACC v7 7.4.4 build 9400. Incorrect authorization means the server accepts an action it should have blocked — a request that reaches functionality the caller was never entitled to use. When that gap sits on a path to code execution and needs no valid credentials, the score climbs to a perfect 10.0. Adobe notes the Campaign Classic updates apply only to fully on-premise deployments and to the on-premise components of hybrid deployments; Adobe-hosted instances were already remediated and need no customer action.

All three share the same practical property: a network-reachable path to code execution on a server that typically sits close to customer data. That profile is what pushes a vendor from "apply at the next window" to a 72-hour recommendation.

The Full Critical List

Beyond the three 10.0s, the release fixes four more high-severity flaws worth ranking into the same rollout. The table below reflects the CVEs and scores as published by Adobe and summarized by The Hacker News.

CVE Product Type CVSS
CVE-2026-48362 ColdFusion OS command injection → code execution 10.0
CVE-2026-71398 Campaign Classic Incorrect authorization → code execution 10.0
CVE-2026-27302 Campaign Classic Incorrect authorization → code execution 10.0
CVE-2026-48273 ColdFusion Eval injection → code execution 9.9
CVE-2026-71384 ColdFusion Incorrect authorization → denial of service 9.6
CVE-2026-71362 Commerce Incorrect authorization → privilege escalation 9.1
CVE-2026-48381 Campaign Classic SQL injection → code execution 9.0

Commerce's CVE-2026-71362 is the one to watch on the merchant side: an incorrect-authorization flaw that can lead to privilege escalation, fixed per Adobe's Commerce advisory APSB26-92. It is a 9.1 rather than a 10.0, but privilege escalation on an e-commerce platform still belongs in the priority tier of this rollout. The ColdFusion side adds two more that shouldn't wait: CVE-2026-48273, an eval injection at 9.9 that also reaches code execution, and CVE-2026-71384, an incorrect-authorization flaw at 9.6 that can force an application denial of service. Campaign Classic's CVE-2026-48381, an SQL injection at 9.0, rounds out the on-premise fixes in build 9400.

Why ColdFusion Sits at the Top

Among the three maximum-severity flaws, CVE-2026-48362 deserves first place for a reason that has nothing to do with its score and everything to do with the product's history. ColdFusion has a long track record as an exploitation target — The CyberSignal recently covered a maximum-severity ColdFusion flaw that moved into active exploitation shortly after disclosure. When a product has repeatedly drawn working exploits, a fresh 10.0 command-injection bug in it should be treated as a matter of days, not weeks, even without a confirmed in-the-wild report today.

The Campaign Classic pair carries its own weight. Adobe has now shipped critical Campaign Classic fixes in consecutive cycles: less than two weeks earlier the company patched CVE-2026-48449, another CVSS 10.0 flaw in the same on-premise product. Teams that closed that ticket should not assume this batch is covered — the fixed build has moved again, to ACC v7 7.4.4 build 9400.

A Cadence That Rewrites the Review Interval

This is not an isolated Adobe emergency. In July, the company shipped a batch that included seven CVSS 10.0 flaws across ColdFusion and Campaign Classic, the CVE-2026-48449 fix followed roughly two weeks ago, and now three more 10.0s land in the same two products. Three maximum-severity releases touching the same software inside a single quarter changes the operating assumption: for on-premise Adobe enterprise servers, "patched last cycle" is no longer a durable state. The review interval for these systems needs to match the pace at which new 10.0s are arriving, which right now is closer to biweekly than quarterly. Teams that treat each Adobe bulletin as a one-off keep discovering that the build which closed the last critical is the affected build for the next one.

Patch Priority

Patch Priority: Adobe August 2026
Patch All Three Products Now
Three CVSS 10.0 flaws land in this release. Update ColdFusion to 2025.0.12 or 2023.0.23, Campaign Classic to ACC v7 7.4.4 build 9400, and Commerce per APSB26-92. Adobe rates the ColdFusion and Campaign Classic updates Priority 1 and advises patching within 72 hours.
Sequence First — CVE-2026-48362
An OS command injection in ColdFusion (CVSS 10.0) that can lead to arbitrary code execution. Given ColdFusion's history as an exploitation target, deploy this fix ahead of the others.

My read: the honest framing of this release is three maximum-severity flaws across two products, not one 10.0 per product — Commerce's worst issue is a 9.1. That distinction matters for sequencing, not for whether you patch: everything in this batch is a critical fix. The order I would run is ColdFusion first, on its exploitation history and the command-injection class; then Campaign Classic, because it is the second consecutive cycle with a 10.0 and the fixed build keeps moving; then Commerce's privilege-escalation fix. None of the three 10.0s is flagged as exploited today, but a network-reachable path to code execution on a data-adjacent server is exactly the profile attackers convert quickly once a patch exposes the bug.

What to Verify

Confirm your rollout against Adobe's own advisories rather than any single summary, since the fixed versions differ by product: APSB26-90 for ColdFusion (2025.0.12 and 2023.0.23), APSB26-123 for Campaign Classic (ACC v7 7.4.4 build 9400), and APSB26-92 for Commerce. The concrete steps:

  • Inventory the three products. Identify every ColdFusion, Commerce, and Campaign Classic instance you run, including the on-premise components of hybrid setups. For Campaign Classic specifically, confirm whether the deployment is on-premise or Adobe-hosted before scheduling work — only the on-premise footprint needs the update.
  • Confirm the exact build, not "we patched." Verify ColdFusion is at 2025.0.12 or 2023.0.23 and Campaign Classic at ACC v7 7.4.4 build 9400. Because the Campaign Classic fix build has changed twice in a month, check the running version directly rather than trusting a prior ticket.
  • Restrict exposure while you patch. A command-injection or incorrect-authorization flaw that is reachable from the network is far more dangerous on an internet-facing host than on one confined to an internal segment, so narrow who can reach the management and application interfaces.
  • Watch exploitation status directly. None of the three 10.0s was being tracked as exploited at disclosure, but a listing on CISA's Known Exploited Vulnerabilities catalog would be the signal to move from "priority patch" to "drop everything."

This Adobe batch also lands in the same week as Microsoft's 421-CVE Patch Tuesday, so teams juggling both should let confirmed exploitation, not raw CVSS, set the cross-vendor order. When two large releases collide, the correct filter is the same one that ranks inside each vendor's list: reachability and evidence of active abuse first, headline score second.

Primary Documents