FeedApplication SecurityMultiple Vulnerabilities in Adobe Products Could Allow for A...
Application SecurityCIS Advisories
10.0CRITICAL

Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution

📅 1 July 2026 at 19:09 UTC📰 CIS AdvisoriesView original source ↗

Multiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution.Adobe Campaign Classic is an enterprise-grade marketing automation platform that helps organizations design, automate, and track complex, personalized cross-channel marketing campaigns.Adobe ColdFusion is a commercial rapid web application development platform used to build and deploy dynamic web and mobile applications.Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

Multiple vulnerabilities in Adobe products, including Campaign Classic and ColdFusion, could allow for arbitrary code execution, posing a significant risk to users with administrative privileges.

⚙️Technical Details
Affected Systems
Adobe Campaign Classic ACC v7: 7.4.3 build 9396 and earlierColdFusion 2025 Update 9 and earlier versionsColdFusion 2023 Update 20 and earlier versions
Attack Vectors
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
💥Impact Assessment
Severity: HIGH
🛡️Recommended Actions
1Apply the stable channel update provided by Adobe to vulnerable systems immediately after appropriate testing.
2Establish and maintain a documented vulnerability management process for enterprise assets.
3Remediate detected vulnerabilities in software through processes and tooling on a monthly, or more frequent, basis.
📦Affected Products
Adobe CampaignLinux Linux KernelMicrosoft WindowsAdobe Coldfusion
🔐NVD Verified DataVERIFIED
CVE-2026-48286CVSS 10CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Weaknesses
CWE-863
Affected Products (CPE)
Adobe CampaignLinux Linux KernelMicrosoft Windows
CVE-2026-48276CVSS 10CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Weaknesses
CWE-434
Affected Products (CPE)
Adobe Coldfusion
CVE-2026-48283CVSS 10CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Weaknesses
CWE-434
Affected Products (CPE)
Adobe Coldfusion
CVE-2026-48277CVSS 10CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Weaknesses
CWE-20
Affected Products (CPE)
Adobe Coldfusion
CVE-2026-48281CVSS 10CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Weaknesses
CWE-20
Affected Products (CPE)
Adobe Coldfusion

Read the full article

This is a curated summary. The complete article is available at CIS Advisories.

Read on CIS Advisories
← Back to feed