• News/
  • bleepingcomputer-20260701073452

Adobe patches seven max severity ColdFusion, Campaign flaws

BleepingComputer
·
Sergiu Gatlan
·
Published Jul 1, 2026
·
Updated

Adobe has released security patches for seven maximum-severity vulnerabilities in the ColdFusion web app development platform and the Campaign Classic marketing automation platform. All these vulnerabilities can be exploited in low-complexity attacks that don't require user interaction and were tagged with priority 1, indicating a high risk of being targeted. "This update resolves vulnerabilities being targeted, or which have a higher risk of being targeted, by exploit(s) in the wild for a given product version and platform. Adobe recommends administrators install the update as soon as possible. (for example, within 72 hours)," Adobe says. " Adobe is not aware of any exploits in the wild for any of the issues addressed in these updates," the company added in advisories released on Tuesday. Six of these critical security flaws (tracked as CVE-2026-48276, CVE-2026-48277, CVE-2026-48281, CVE-2026-48316, and CVE-2026-48282) affect ColdFusion versions 2025.9, 2023.20 and earlier, and can be exploited by attackers without privileges to gain remote code execution on unpatched systems. The Campaign Classic max severity vulnerability (tracked as CVE-2026-48286) affects versions 7.4.3 build 9396 and earlier and could lead to arbitrary code execution in the current user's context after successful exploitation. According to Adobe's security advisory, CVE-2026-48286 only affects on-premises Adobe Campaign instances (including fully on-premises deployments and on-premises components in hy...

Read full article

Affected Software

3 affected components
Adobe ColdFusion web app development platform>=2023.20<=2025.9
Adobe ColdFusion web app development platform<=2023.20 and earlier
Adobe Campaign Classic marketing automation platform<=7.4.3 build 9396 and earlier
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses Adobe's security patches for seven critical vulnerabilities in ColdFusion and Campaign Classic.

2

What security implications are discussed in the article?

The vulnerabilities can be exploited through low-complexity attacks without user interaction.

3

What specific products are affected by the vulnerabilities?

The affected products are Adobe ColdFusion and Adobe Campaign Classic.

4

When were the vulnerabilities exploited according to the article?

The vulnerabilities were kevin-listed for exploitation starting July 1, 2026.

5

What is the severity level of the vulnerabilities mentioned in the article?

All seven vulnerabilities are classified as maximum-severity.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203