Adobe Fixes Seven Critical ColdFusion and Campaign Vulnerabilities

www.news4hackers.com-adobe-fixes-seven-critical-coldfusion-and-campaign-vulnerabilities-adobe-fixes-seven-critical-coldfusion-and-campaign-vulnerabilities

Adobe issues urgent patches for seven high-severity flaws in ColdFusion and Campaign Classic, with six affecting ColdFusion versions and one impacting Campaign Classic.

Adobe Addresses Critical Vulnerabilities

Adobe addresses seven critical vulnerabilities across ColdFusion and Campaign Classic platforms. The company has issued updates to resolve seven high-severity flaws impacting the ColdFusion web application development framework and the Campaign Classic marketing automation tool. These vulnerabilities can be exploited through low-complexity attacks requiring no user interaction, with all identified issues classified as priority 1 due to their elevated risk of being targeted.

Urgency of Patches

Adobe emphasized the urgency of applying the patches, stating that the updates address vulnerabilities actively under exploitation or with a significant likelihood of being targeted in real-world scenarios. The firm advised administrators to implement the fixes promptly, ideally within 72 hours of release. No confirmed instances of in-the-wild exploitation have been reported for any of the vulnerabilities addressed in the latest updates.

Adobe emphasized the urgency of applying the patches, stating that the updates address vulnerabilities actively under exploitation or with a significant likelihood of being targeted in real-world scenarios. The firm advised administrators to implement the fixes promptly, ideally within 72 hours of release.

Vulnerability Details

Six of the critical flaws affect ColdFusion versions 2025.9, 2023.20, and earlier, allowing unprivileged attackers to achieve remote code execution on systems lacking the patches. The Campaign Classic vulnerability, designated CVE-2026-48286, impacts versions 7.4.3 build 9396 and earlier, enabling arbitrary code execution within the context of the current user following successful exploitation.

Scope of Impact

The advisory clarified that this specific flaw only affects on-premises Adobe Campaign deployments, including hybrid environments with on-premises components, as Adobe-hosted instances have already been remediated.

Adobe’s Chief Security Officer, Aanchal Gupta, announced a shift to a biweekly release schedule for security bulletins starting July 14, 2026, with updates published on the second and fourth Tuesdays of each month. The company reiterated its existing out-of-band response process for zero-day vulnerabilities discovered externally or actively exploited.

Historical Context and Security Trends

This follows Adobe’s earlier emergency patches in April to address a zero-day flaw in Acrobat Reader (CVE-2026-34621) that had been leveraged in attacks since December. Over the past five years, CISA has documented 79 Adobe-related vulnerabilities in its actively exploited flaws catalog, with 10 of these also linked to ransomware groups.

Security Detection Challenges

Security teams report detecting 54% of successful breaches but only flagging 14% of incidents, leaving the majority undetected. A whitepaper highlights how breach and attack simulation tools validate detection capabilities to prevent threats from bypassing security measures.

Additional Coverage

Additional coverage includes a critical SimpleHelp vulnerability used to deploy new stealer malware, ongoing exploits targeting Oracle E-Business flaws, and urgent CISA warnings about max-severity Ubiquiti vulnerabilities. Recent advisories also note active exploitation of Cisco and Adobe-specific flaws, including the Cisco Unified CM vulnerability CVE-2026-20230.



About Author

en_USEnglish