Adobe Patches Over 50 Flaws, Tells ColdFusion and Campaign Classic Users to Act Now
Several of Adobe's most widely used business tools carried perfect-ten severity scores this week. Two products have been flagged as likely targets, and Adobe is telling administrators to patch immediately.

Key points
- Adobe released patches fixing more than 50 security flaws across its software products on Tuesday.
- Three ColdFusion flaws are rated critical, including one with a perfect severity score of 10 out of 10.
- Two Campaign Classic flaws also scored 10 out of 10, and both products carry Adobe's highest-urgency patch rating.
- Adobe hasn't seen these vulnerabilities actively exploited yet, but rates them likely targets.
- Commerce users have 30 days to patch; ColdFusion and Campaign Classic administrators should update today.
Adobe pushed out a large batch of security fixes on Tuesday, covering more than 50 vulnerabilities across several products. Two of those products are getting the loudest alarm bells.
Which products are most at risk?
ColdFusion and Campaign Classic both carry Adobe's Priority 1 rating, meaning Adobe believes criminals are likely to target them soon. Administrators running either product should apply the fixes today, not this week.
ColdFusion, a platform businesses use to build and run web applications, received fixes for 15 flaws, three of them critical. The worst is CVE-2026-48362, an OS command injection flaw scored a perfect 10 out of 10: an attacker sends a crafted request and gets the server running their own commands as system administrator. We first covered that CVE on 11 August 2026. A second flaw, CVE-2026-48273, scored 9.9 and involves eval injection, where malicious code gets silently executed by the server. A third, CVE-2026-71384, scored 9.6 and relates to broken authorization checks, so a logged-in user can reach things they shouldn't.
Campaign Classic, Adobe's bulk email marketing platform, had three critical flaws patched. CVE-2026-71398 and CVE-2026-27302 are authorization issues that both scored 10 out of 10. CVE-2026-48381, an SQL injection bug where an attacker sneaks malicious database commands into an input field to extract or destroy data, scored 9.0. This isn't Campaign Classic's first rodeo: we reported a separate perfect-10 flaw in the platform on 1 August 2026, also involving a failed permission check.
What about Adobe Commerce and other products?
Commerce users get 30 days, but shouldn't push it. Adobe Commerce, the platform retailers use to run online shops, received seven fixes. The lead flaw, CVE-2026-71362, scored 9.1 and lets a lower-privileged user gain full administrative control. The Priority 2 rating reflects the platform's history of real-world targeting.
| Product | Flaws Fixed | Highest Severity | Patch Urgency |
|---|---|---|---|
| ColdFusion | 15 | 10.0 (Critical) | Immediate |
| Campaign Classic | 3 | 10.0 (Critical) | Immediate |
| Commerce | 7 | 9.1 (Critical) | 30 days |
| Lightroom | 11 | High | Routine |
| Content Credentials | 15 | High/Medium | Routine |
Lightroom and Content Credentials, a tool for verifying digital media authenticity, each received lower-priority updates covering high and medium severity issues.
Adobe says none of these vulnerabilities are actively exploited right now, as first reported by SecurityWeek. That window won't stay open long.
The failure mode here is simple: an unpatched ColdFusion server on a public network is one scan away from a very bad Tuesday afternoon.



