Adobe shipped emergency patches Tuesday for seven critical vulnerabilities in ColdFusion and Campaign Classic — all rated maximum severity. Every single one can be exploited in low-complexity attacks that require no user interaction. Adobe tagged them priority 1, meaning they expect active targeting soon.
Six of the flaws affect ColdFusion versions 2025.9, 2023.20 and earlier. Tracked as CVE-2026-48276, CVE-2026-48277, CVE-2026-48281, CVE-2026-48316, and CVE-2026-48282, they allow unauthenticated attackers to achieve remote code execution on unpatched systems. Yes, that’s as bad as it sounds.
The seventh bug, CVE-2026-48286, hits Campaign Classic versions 7.4.3 build 9396 and earlier. It can lead to arbitrary code execution in the current user’s context. Important detail: this only affects on-premises deployments and hybrid setups with on-prem components. Adobe-hosted instances are already patched.
Adobe says it’s not aware of active exploitation yet. But with max CVSS scores and no authentication required, you can bet attackers are already working on it. The company recommends installing updates within 72 hours.
Separately, Adobe CSO Aanchal Gupta announced the company is moving to twice-monthly security bulletins starting July 14, aiming to ship fixes faster. Out-of-band response for zero-days stays in place.
Over the last five years, CISA has added 79 Adobe flaws to its Known Exploited Vulnerabilities catalog — 10 of which were abused by ransomware gangs. This is not a vendor that gets the benefit of the doubt on patching timelines.
