Adobe Patches Seven Critical Flaws in ColdFusion and Campaign Classic
Adobe has released urgent patches for seven maximum-severity vulnerabilities affecting its ColdFusion and Campaign Classic platforms, with some flaws already being targeted by exploits.

Adobe has issued critical security updates to address seven high-severity vulnerabilities impacting its ColdFusion web application development platform and the Adobe Campaign Classic marketing automation software. These flaws, all rated with maximum severity, pose a significant risk to organizations running these products.
The vulnerabilities are described as low-complexity attacks that do not require any user interaction, making them prime targets for exploitation. Adobe has classified these issues with a Priority 1 rating, indicating a high likelihood of them being actively targeted by malicious actors. The company strongly advises administrators to apply the patches as soon as possible, ideally within 72 hours, to mitigate potential risks.
While Adobe stated it was not aware of any exploits in the wild for these specific issues at the time of the advisory, the "higher risk of being targeted" designation underscores the urgency. Six of the critical vulnerabilities (CVE-2026-48276, CVE-2026-48277, CVE-2026-48281, CVE-2026-48316, and CVE-2026-48282) affect ColdFusion versions 2025.9, 2023.20, and earlier. Successful exploitation of these flaws could allow unauthenticated attackers to achieve remote code execution on vulnerable systems.
The seventh critical vulnerability, CVE-2026-48286, affects Adobe Campaign Classic versions 7.4.3 build 9396 and earlier. This flaw could lead to arbitrary code execution within the context of the current user. Importantly, this vulnerability specifically impacts on-premises Adobe Campaign instances, including those in hybrid deployments. Adobe has already addressed this issue in its hosted instances.
In a broader move to enhance its security response, Adobe's Chief Security Officer, Aanchal Gupta, announced that the company will transition to a twice-monthly schedule for its security bulletins. Starting July 14, 2026, Adobe Security Bulletins and Advisories will be published on the second and fourth Tuesday of each month. This change aims to expedite the delivery of security updates, though the company's out-of-band response process for actively exploited or zero-day vulnerabilities will remain in effect.
This batch of patches comes after a period of heightened vulnerability disclosures for Adobe products. Earlier in the year, Adobe released emergency patches for a critical Acrobat Reader vulnerability (CVE-2026-34621) that had been exploited as a zero-day since December. The company's products have historically been frequent targets for attackers.
Over the past five years, the Cybersecurity and Infrastructure Security Agency (CISA) has added 79 security flaws in Adobe products to its Known Exploited Vulnerabilities (KEV) catalog. A significant portion of these, 10 in total, have been observed being abused by ransomware gangs, highlighting the severe impact of unpatched Adobe software.
Organizations utilizing Adobe ColdFusion or Adobe Campaign Classic are strongly urged to review the latest security advisories and apply the provided patches immediately. The potential for unauthenticated remote code execution and arbitrary code execution makes these vulnerabilities a critical priority for patching to prevent widespread compromise.
This new advisory from SecurityWeek details additional critical vulnerabilities affecting Adobe ColdFusion and Campaign Classic, expanding on the initial report. Specifically, it highlights six maximum-severity flaws in ColdFusion versions 2025 and 2023, stemming from issues like unrestricted file uploads and path traversal. Furthermore, the update addresses two critical-severity path traversal and improper input validation bugs in ColdFusion that could lead to arbitrary file system reads and privilege escalation, alongside other medium-severity defects.
This new article details seven specific critical vulnerabilities affecting Adobe ColdFusion and Campaign Classic, including multiple CVEs rated CVSS 10.0 for arbitrary code execution. It highlights that the ColdFusion vulnerabilities specifically impact versions 2025 Update 9 and earlier, and 2023 Update 20 and earlier, with patches available as Update 10 and Update 21 respectively. The article also provides a more granular breakdown of the CVEs, categorizing them by exploit type such as unrestricted file upload, improper input validation, and path traversal.
This new article provides specific CVE identifiers for the vulnerabilities patched in Adobe ColdFusion and Adobe Campaign Classic, detailing the exact nature of each flaw, such as unrestricted file uploads, improper input validation, and path traversal. It also credits the security researchers who discovered some of these issues and clarifies that the Campaign Classic vulnerability only affects on-premise deployments, while noting Adobe has not found any exploits in the wild for these specific flaws.
This new analysis from WatchTowr Labs delves into specific vulnerabilities within Adobe ColdFusion, particularly focusing on the Remote Development Services (RDS) feature. The researchers highlight that exploitation of certain flaws, including arbitrary code execution and file system read vulnerabilities, may require RDS to be enabled and potentially have authentication disabled, providing a deeper technical look at the attack surface beyond the initial advisory.
The Canadian Centre for Cyber Security (CCCS) has issued a specific warning that threat actors have already begun exploiting CVE-2026-48282 in the wild. This advisory comes just two days after Adobe released security updates for the critical vulnerability affecting Adobe ColdFusion versions 2025.9, 2023.20, and earlier, highlighting the immediate risk to unpatched systems.
This new article confirms that CVE-2026-48282, a critical path traversal flaw in Adobe ColdFusion, is actively being exploited by threat actors. While Adobe's initial advisory stated no exploits were in the wild, this report highlights that exploitation attempts began within hours of the vulnerability's disclosure, underscoring the urgency for patching.
Threat actors have begun actively exploiting CVE-2026-48282, a critical path traversal vulnerability in Adobe ColdFusion, within hours of its public disclosure. This exploitation occurred despite Adobe's initial advisory stating no known in-the-wild activity, highlighting a significantly compressed window between patch release and active exploitation.
CISA has now added CVE-2026-48282 to its Known Exploited Vulnerabilities (KEV) catalog, mandating federal agencies patch the actively exploited Adobe ColdFusion flaw by Friday, June 10th, as per Binding Operational Directive (BOD) 26-04. This directive prioritizes patching based on KEV inclusion, automated exploitation potential, online exposure, and impact.