Adobe Ships Emergency Fixes for Seven CVSS 10.0 Bugs in ColdFusion, Campaign Classic
Out-of-band advisories cover arbitrary code execution and privilege escalation paths. Self-managed deployments carry the full remediation burden; cloud tenants do not.

Key points
- Adobe published maximum-severity patches for ColdFusion and Campaign Classic on Tuesday.
- Flaws include arbitrary code execution, privilege escalation, arbitrary file system read, and security feature bypass.
- Cloud-hosted Campaign Classic tenants are patched by Adobe; self-managed deployments are not.
- ColdFusion's history as an active exploit target means defenders should treat this batch as urgent.
- Regulated entities should document their remediation timeline now, before any regulator asks.
What did Adobe actually fix?
The ColdFusion advisory states the update resolves vulnerabilities that could lead to arbitrary code execution, privilege escalation, arbitrary file system read, and security feature bypass. Read that verb list carefully: each outcome maps to a distinct class of regulatory concern. The Campaign Classic advisory covers a parallel set of code-execution and privilege-escalation defects in the on-premises marketing automation product.
Adobe assigns its own priority ratings alongside CVSS scores. Products carrying a Priority 1 designation carry the vendor's recommendation of a prompt patch window, a timeline federal civilian agencies will effectively inherit if CISA adds any of these CVEs to the Known Exploited Vulnerabilities catalog.
Should you worry about disclosure obligations?
ColdFusion sits inside a large number of legacy application stacks at regulated entities. Registrants subject to the SEC's cyber disclosure rule under Item 1.05 of Form 8-K face a four-business-day reporting clock once they make a materiality determination after a confirmed intrusion. The Commission has already brought enforcement actions tied to disclosure quality, not just the breach itself.
EU-based operators running Campaign Classic on-premises should review the notification timelines under NIS2: an early warning upon awareness of a significant incident, followed by a full incident notification within a short window. Member state transposition remains uneven, but the substantive triggers are in force.
For critical infrastructure entities in the United States, CIRCIA is the one to watch. We've tracked that rulemaking across 26 stories since May 2026, and the picture hasn't changed: neither the covered-incident nor the ransom-payment reporting requirement is enforceable yet, but both will be soon after the final rule lands.
Does ColdFusion's past predict its future here?
It does, and that's the uncomfortable part. ColdFusion has been a recurring intrusion vector, and prior vulnerabilities in the product were cited in confirmed federal agency compromises after appearing on CISA's KEV list. That pattern is exactly why defenders shouldn't treat this as a routine patch cycle.
Adobe credits multiple external researchers in the advisory acknowledgments. No in-the-wild exploitation has been reported at publication time.
Apply the updates, review ColdFusion administrator access logs, and write down what you did and when. If a regulator asks later, that record is what you'll need.



