Adobe Patches Over 50 Flaws, Tells ColdFusion and Campaign Classic Users to Act Now

Several of Adobe's most widely used business tools carried perfect-ten severity scores this week. Two products have been flagged as likely targets, and Adobe is telling administrators to patch immediately.

ThreatVectr Newsdesk· 3 min read
Extreme close-up of a glowing server rack in a dark data centre, amber and blue indicator lights reflecting off brushed metal chassis, shallow depth of field dr
Share

Key points

  • Adobe released patches fixing more than 50 security flaws across its software products on Tuesday.
  • Three ColdFusion flaws are rated critical, including one with a perfect severity score of 10 out of 10, meaning it is as dangerous as a vulnerability can be rated.
  • Two Campaign Classic flaws also scored 10 out of 10, and both products carry Adobe's highest-urgency patch rating.
  • Adobe says it has not seen these specific vulnerabilities actively exploited yet, but rates them likely targets.
  • Adobe Commerce users have 30 days to patch, while ColdFusion and Campaign Classic administrators should update today.

Adobe pushed out a large batch of security fixes on Tuesday, covering more than 50 vulnerabilities, which are weaknesses in software that criminals can exploit, across several of its products. Two of those products are getting the loudest alarm bells.

Which products are most at risk?

ColdFusion and Campaign Classic both carry Adobe's Priority 1 rating, meaning Adobe believes criminals are likely to target them soon. Administrators running either product should apply the fixes today, not this week.

ColdFusion, a platform businesses use to build and run web applications, received fixes for 15 flaws. Three are critical. The worst is CVE-2026-48362, an OS command injection flaw, meaning an attacker could send a specially crafted request and get the server to run their own commands as if they were the system administrator. It scored a perfect 10 out of 10 on the standard severity scale. A second flaw, CVE-2026-48273, scored 9.9 and involves eval injection, where malicious code gets silently executed by the server. A third, CVE-2026-71384, scored 9.6 and relates to broken authorization checks, which means a logged-in user could access things they should not.

Campaign Classic, Adobe's email marketing platform used by large organisations to send bulk communications to customers, had three critical flaws patched. Two authorization issues, CVE-2026-71398 and CVE-2026-27302, both scored 10 out of 10. An SQL injection bug, CVE-2026-48381, scored 9.0. SQL injection is a technique where an attacker sneaks malicious database commands into a form or input field to extract or destroy data.

What about Adobe Commerce and other products?

Commerce users get a 30-day window, but should not push it. Adobe Commerce, the platform retailers use to run online shops, received seven fixes including CVE-2026-71362, a 9.1-severity flaw that could let a lower-privileged user gain full administrative control. Adobe gave Commerce a Priority 2 rating because the platform has been targeted in real-world attacks before.

Product Flaws Fixed Highest Severity Patch Urgency
ColdFusion 15 10.0 (Critical) Immediate
Campaign Classic 3 10.0 (Critical) Immediate
Commerce 7 9.1 (Critical) 30 days
Lightroom 11 High Routine
Content Credentials 15 High/Medium Routine

Lightroom, the photo-editing software, and Content Credentials, a tool for verifying digital media authenticity, each received lower-priority updates covering high and medium severity issues.

Adobe says none of these vulnerabilities are actively being exploited right now, as first noted by SecurityWeek. That window will not stay open long for critical-rated flaws.

The failure mode here is simple: a business running an unpatched ColdFusion server on a public network is one scan away from a very bad Tuesday afternoon.

© 2026 Threat Vectr