Table of Contents
Key Takeaway
- ⚡ The Flaws: The Adobe ColdFusion vulnerability patch addresses three CVSS 10.0 vulnerabilities — CVE-2026-48362 in ColdFusion (OS command injection), CVE-2026-71398 and CVE-2026-27302 in Campaign Classic (both incorrect authorization leading to arbitrary code execution).
- 🎯 The Impact: ColdFusion hosts customer portals, business applications, APIs, and internal web services. Campaign Classic manages customer records and communications. Compromise disrupts operations and exposes sensitive data.
- 📊 The Scope: 7 vulnerabilities total across ColdFusion (3 flaws), Commerce (1 flaw, CVE-2026-71362 now actively exploited per Sansec), and Campaign Classic (3 flaws). All rated Priority 1 by Adobe.
- 🏢 The Urgency: Adobe recommends patching within 72 hours. No confirmed exploitation of the ColdFusion flaws yet, but CVE-2026-71362 in Commerce is already being exploited to switch customer sessions and steal account data.
- 🔑 What You Should Do: Update ColdFusion to 2025.0.12 or 2023.0.23, update Campaign Classic to v7.4.4 build 9400, identify all internet-facing deployments, and review monitoring coverage.
Adobe’s August 2026 security update delivered a jarring set of fixes: three vulnerabilities rated CVSS 10.0 — the maximum possible score — across ColdFusion and Campaign Classic. The Adobe ColdFusion vulnerability patch addresses CVE-2026-48362, an operating system command injection flaw that could allow a threat actor to execute commands directly on the affected server. Two additional CVSS 10.0 flaws in Campaign Classic (CVE-2026-71398 and CVE-2026-27302) could result in arbitrary code execution through incorrect authorization. Adobe assigned Priority 1 rating to both advisories, indicating a higher risk of future targeting.
The timing adds urgency. This disclosure comes less than two weeks after Adobe patched a separate maximum-severity Campaign Classic flaw (CVE-2026-48449, CVSS 10.0) and after the company confirmed limited exploitation of a prior ColdFusion vulnerability (CVE-2026-48282). Security researchers observed activity shortly after technical details became public for that earlier flaw. The pattern is clear: when Adobe ColdFusion vulnerability details are published, attackers move quickly.
The ColdFusion Vulnerabilities in Detail
The most severe Adobe ColdFusion vulnerability is CVE-2026-48362, rated CVSS 10.0. According to Field Effect’s security intelligence team, this is an operating system command injection vulnerability that could enable a threat actor to execute commands on the affected ColdFusion server. Successful exploitation could result in compromise of the ColdFusion server, access to hosted applications and data, and potential access to connected systems depending on the server’s permissions and role within the environment.
CVE-2026-48273, rated CVSS 9.9, is an eval injection vulnerability that could enable a threat actor to execute code within the affected ColdFusion environment. This could lead to compromise of applications running on the server, exposure of sensitive business data, and access to resources available to the affected application. CVE-2026-71384, rated CVSS 9.6, is an incorrect authorization vulnerability that could enable denial-of-service conditions, disrupting customer-facing applications, APIs, and business services.
The Adobe ColdFusion vulnerability affects ColdFusion 2025.0.11 and earlier, and ColdFusion 2023.0.22 and earlier. Adobe released fixes in ColdFusion 2025 Update 12 (version 2025.0.12) and ColdFusion 2023 Update 23 (version 2023.0.23). The Hacker News confirmed that these updates have a Priority 1 rating, referring to vulnerabilities with a higher risk of being targeted by malicious cyber attacks.
The Campaign Classic CVSS 10.0 Pair
Beyond the Adobe ColdFusion vulnerability, Adobe addressed three critical vulnerabilities in Campaign Classic. CVE-2026-71398 (CVSS 10.0) is an incorrect authorization vulnerability that could result in arbitrary code execution, providing unauthorized access to customer communications workflows, marketing operations, and associated data. CVE-2026-27302 (CVSS 10.0) is another incorrect authorization vulnerability with similar impact, including unauthorized access to application functionality, customer information, and systems integrated with Campaign Classic.
CVE-2026-48381 (CVSS 9.0) is a structured query language (SQL) injection vulnerability that could result in arbitrary code execution. Exploitation could expose or alter customer data stored within Campaign Classic and potentially lead to compromise of the underlying application server. The Campaign Classic vulnerabilities affect Adobe Campaign Classic v7 version 7.4.3 build 9399 and earlier, with fixes available in version 7.4.4 build 9400.
Importantly, the Campaign Classic advisory applies only to fully on-premises deployments and the on-premises components of hybrid deployments. Adobe-hosted instances were remediated before public disclosure and require no customer action. This distinction matters because organizations running on-premises Campaign Classic are the only ones exposed — but they are the ones with the least vendor support for rapid patching.
The Commerce Flaw Already Being Exploited
While the Adobe ColdFusion vulnerability has not yet been confirmed as exploited, a related flaw in Adobe Commerce and Magento Open Source is actively under attack. The Hacker News reported that Sansec, the Dutch e-commerce security company, identified exploitation of CVE-2026-71362 (CVSS 9.1), an incorrect authorization vulnerability in Commerce. “The vulnerability lets attackers switch a customer session to another customer account,” Sansec said. “This gives them access to the victim’s account and private customer data.”
This active exploitation demonstrates the pattern that Field Effect highlighted: recent ColdFusion activity shows continued threat actor interest in exposed Adobe deployments and highlights how quickly newly disclosed vulnerabilities can attract attention. The Adobe Commerce account takeover we previously reported is the same advisory chain — CVE-2026-71362 was patched in the same August release as the ColdFusion and Campaign Classic flaws.
Why ColdFusion Is a High-Value Target
ColdFusion is widely used to host customer portals, line-of-business applications, APIs, and internal web services. According to Field Effect, because both ColdFusion and Campaign Classic often process sensitive business and customer information, vulnerabilities affecting these platforms can have consequences beyond the affected server, including disruption of business operations and exposure of sensitive data.
The August Patch Tuesday data from Microsoft showed that severity ratings do not always predict exploitation — the one actively exploited Microsoft bug was rated Important, not Critical. But CVSS 10.0 vulnerabilities like the Adobe ColdFusion vulnerability are different. A CVSS 10.0 rating means the vulnerability is network-exploitable, requires no privileges, requires no user interaction, and can compromise confidentiality, integrity, and availability simultaneously. These are the flaws that attackers prioritize because the exploitation path is the most straightforward.
The threat landscape has also evolved. Field Effect noted that advances in AI-assisted code analysis and vulnerability research have reduced the time required to analyze vulnerability disclosures and develop proof-of-concept code. This means the window between patch release and active exploitation is shrinking. Organizations that delay patching CVSS 10.0 flaws are betting that attackers will not figure out the exploit — a bet that AI-assisted research is increasingly making a losing proposition.
What Organizations Running ColdFusion Must Do Now
Adobe’s guidance is specific: apply the updates as soon as possible, preferably within 72 hours. Field Effect recommends three additional steps beyond patching:
1. Identify all internet-facing ColdFusion deployments. Many organizations lose track of ColdFusion instances that were deployed years ago for a specific project and never decommissioned. These orphaned instances are the most likely to be unpatched and the most attractive to attackers scanning the internet for exposed targets. Use asset inventory tools or network scanning to find every instance.
2. Update Campaign Classic on-premises deployments. Only on-premises Campaign Classic instances are affected — Adobe-hosted instances were remediated before disclosure. But on-premises deployments are often the ones with the least automated patching processes. Organizations running Campaign Classic v7 must update to version 7.4.4 build 9400 immediately.
3. Review monitoring coverage for business-critical systems. The SonicWall zero-day exploitation demonstrated that attackers do not just breach the initial device — they use it as a pivot point. Similarly, a compromised ColdFusion server provides access to every application, database, and connected system that the server can reach. Organizations must ensure that monitoring covers not just the ColdFusion instance but the systems it connects to.
The Bigger Pattern: Adobe’s Patch Cadence Under Pressure
The August 2026 Adobe ColdFusion vulnerability disclosure is the second major Adobe security update in two weeks. On July 31, Adobe patched CVE-2026-48449 (CVSS 10.0), a maximum-severity Campaign Classic flaw. On August 11, the company released the current batch addressing three more CVSS 10.0 flaws. The AI patch deployment conversation at Black Hat 2026 is directly relevant here: when vendors release critical patches every two weeks, organizations that rely on manual patch cycles cannot keep up.
The Crimson Collective breach of Brightspeed demonstrated what happens when patching falls behind — the four-month gap between initial attacker claim and vendor confirmation left customers exposed. Adobe’s Priority 1 rating and 72-hour recommendation is designed to prevent that gap. But the recommendation only works if organizations follow it.
For security teams, the Adobe ColdFusion vulnerability is a test of whether the patching process can handle CVSS 10.0 flaws within the recommended window. If the answer is no, the process needs to change — because the next CVSS 10.0 flaw is already on the way.
The AI Acceleration Factor in Vulnerability Exploitation
Field Effect’s analysis highlighted a critical observation about the current threat environment: advances in AI-assisted code analysis and vulnerability research have reduced the time required to analyze vulnerability disclosures and develop proof-of-concept code. This is not a theoretical concern. The AI acceleration of attack development means that the 72-hour patching window Adobe recommends is not conservative — it may already be too generous.
The CrowdStrike 2026 Global Threat Report documented an 89% increase in attacks by AI-enabled adversaries year over year. When attackers can use AI to analyze a vulnerability advisory, understand the affected code paths, and generate exploit code within hours rather than weeks, the traditional patch cycle becomes the weakest link. The Adobe ColdFusion vulnerability is a case study in this new dynamic: the flaw was disclosed on August 11, the technical details are public, and AI-assisted attackers are already analyzing the patch to identify the underlying vulnerability and reverse-engineer an exploit.
This is why the zero-day exploitation gap is shrinking. When the SonicWall zero-day was exploited for three weeks before disclosure, that gap represented the time between attacker discovery and vendor patch. But the post-disclosure gap — the time between patch release and widespread exploitation — is also compressing. Organizations that treat the 72-hour window as a suggestion rather than a deadline are the ones most likely to find their ColdFusion servers compromised before the week is over.
The Supply Chain Dimension
The Adobe ColdFusion vulnerability does not exist in isolation. ColdFusion servers often connect to databases, authentication systems, API gateways, and customer-facing applications. A compromise of the ColdFusion server is not the end of the attack — it is the beginning. The attacker gains a foothold inside the network perimeter, with access to every system the ColdFusion server can reach. This is the same supply chain exploitation pattern seen in the VMware vCenter and SonicWall attacks: the initial device is the entry point, and the real damage is done through lateral movement.
The Crimson Collective breach demonstrated this principle in the data theft context. The group did not just steal Brightspeed’s customer data — it exploited Brightspeed’s infrastructure to reach Nissan through the Red Hat supply chain. Adobe ColdFusion servers are similar infrastructure nodes: they connect to customer databases, payment processing systems, and business application APIs. Compromising one ColdFusion server can cascade to every system it integrates with.
For organizations, this means that patching the Adobe ColdFusion vulnerability is necessary but not sufficient. Security teams must also review the connections between ColdFusion servers and other systems, ensure that database credentials used by ColdFusion applications are scoped to the minimum necessary access, and monitor for unusual data access patterns that could indicate post-compromise lateral movement.
Frequently Asked Questions About the Adobe ColdFusion Vulnerability
What is the Adobe ColdFusion vulnerability?
The Adobe ColdFusion vulnerability refers to CVE-2026-48362, a CVSS 10.0 operating system command injection flaw that could allow a threat actor to execute commands on the affected ColdFusion server. Adobe patched it on August 11, 2026, alongside two additional ColdFusion flaws (CVE-2026-48273 at CVSS 9.9 and CVE-2026-71384 at CVSS 9.6).
Which Adobe products are affected by the August 2026 patches?
The patches cover Adobe ColdFusion (versions 2025.0.11 and earlier, 2023.0.22 and earlier), Adobe Campaign Classic v7 (version 7.4.3 build 9399 and earlier), and Adobe Commerce and Magento Open Source. The Campaign Classic advisory applies only to on-premises deployments — Adobe-hosted instances were already remediated.
What is CVSS 10.0 and why does it matter?
CVSS 10.0 is the maximum score on the Common Vulnerability Scoring System. It means the vulnerability is network-exploitable, requires no privileges or user interaction, and can compromise confidentiality, integrity, and availability simultaneously. The Adobe ColdFusion vulnerability rated CVSS 10.0 represents the highest possible exploitation risk.
Is the Adobe ColdFusion vulnerability being exploited in the wild?
As of August 12, 2026, Adobe reported no known exploitation of the ColdFusion or Campaign Classic flaws. However, CVE-2026-71362 in Adobe Commerce is actively being exploited according to Sansec, allowing attackers to switch customer sessions and access victim accounts.
How quickly should organizations patch?
Adobe recommends installing the update as soon as possible, preferably within 72 hours. Both the ColdFusion and Campaign Classic advisories carry Priority 1 rating, indicating a higher risk of being targeted by malicious cyber attacks. The previous ColdFusion flaw (CVE-2026-48282) was confirmed exploited after technical details became public.
How do I update ColdFusion and Campaign Classic?
Update ColdFusion to version 2025.0.12 (ColdFusion 2025 Update 12) or version 2023.0.23 (ColdFusion 2023 Update 23). Update Campaign Classic to v7 version 7.4.4 build 9400. Patches are available through Adobe’s security bulletins at helpx.adobe.com/security.html.
What happens if a ColdFusion server is compromised?
A compromised ColdFusion server gives the attacker access to hosted applications, customer data, APIs, and any connected systems the server can reach. Because ColdFusion often hosts customer-facing portals and business-critical applications, the impact extends beyond the server itself to every service and data source it touches.
Cybersecurity Disclaimer: This article discusses the Adobe ColdFusion vulnerability based on publicly reported information from Adobe, The Hacker News, Field Effect, and Sansec. It does not constitute professional cybersecurity advice. Organizations should consult Adobe’s official security bulletins and their security teams for specific patch deployment guidance.