Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

Summary

Adobe has released patches for critical security vulnerabilities affecting ColdFusion, Commerce, and Campaign Classic. The most severe of these flaws, CVE-2026-48362, is an operating system command injection vulnerability in ColdFusion that has a CVSS score of 10.0 and could lead to arbitrary code execution.

IFF Assessment

FOE

The article details critical vulnerabilities that could allow for arbitrary code execution and privilege escalation, posing a significant threat to users and systems.

Severity

10.0 Critical

Defender Context

This article highlights critical vulnerabilities in widely used Adobe products, emphasizing the need for prompt patching to prevent potential exploitation. Defenders should prioritize updating ColdFusion, Commerce, and Campaign Classic instances to mitigate risks of arbitrary code execution and privilege escalation.

Read Full Story →