VulnerabilityBleeping Computer
10.0 — CRITICAL
Adobe patches seven max severity ColdFusion, Campaign flaws
Adobe has released security patches for seven maximum-severity vulnerabilities in the ColdFusion web app development platform and the Campaign Classic marketing automation platform. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
Adobe has released security patches for seven maximum-severity vulnerabilities in ColdFusion and Campaign Classic, which can be exploited in low-complexity attacks without user interaction, posing a high risk to affected systems.
⚙️Technical Details
CVEs
CVE-2026-48276CVE-2026-48277CVE-2026-48281CVE-2026-48282CVE-2026-48316CVE-2026-48286Affected Systems: ColdFusion versions 2025.9, 2023.20 and earlier; Campaign Classic versions 7.4.3 build 9396 and earlier
Affected Systems
ColdFusion versions 2025.9, 2023.20 and earlier; Campaign Classic versions 7.4.3 build 9396 and earlier
Attack Vectors
NETWORK
💥Impact Assessment
Severity: CRITICAL
Who Is at Risk
Administrators of ColdFusion and Campaign Classic systems with unpatched versions
🛡️Recommended Actions
1Apply the security patches as soon as possible to prevent exploitation
2Monitor system logs for suspicious activity related to the patched vulnerabilities
3Implement additional security controls, such as intrusion detection and prevention systems, to detect and block potential attacks
📦Affected Products
Adobe ColdfusionCampaign Classic
🔐NVD Verified DataVERIFIED
CVE-2026-48276 ↗CVSS 10 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HWeaknesses
CWE-434
Affected Products (CPE)
Adobe Coldfusion
CVE-2026-48277 ↗CVSS 10 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HWeaknesses
CWE-20
Affected Products (CPE)
Adobe Coldfusion
CVE-2026-48281 ↗CVSS 10 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HWeaknesses
CWE-20
Affected Products (CPE)
Adobe Coldfusion
CVE-2026-48282 ↗CVSS 10 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HWeaknesses
CWE-22
Affected Products (CPE)
Adobe Coldfusion
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
