Adobe Ships Fixes for 7 Maximum-Severity Flaws in ColdFusion and Campaign Classic

Adobe pushed patches for seven CVSS 10.0 vulnerabilities this week. The bugs hit ColdFusion and Campaign Classic, and they’re all critical.

Six of them are in ColdFusion. The list includes unrestricted file upload flaws, improper input validation bugs, and a path traversal vulnerability — all ranked 10.0. Throw in two more at 9.3 for good measure: one lets an attacker read any file on the system, the other opens the door for privilege escalation.

The fixes land in ColdFusion 2023 Update 21 and ColdFusion 2025 Update 10. If you’re running either version, update now. Researchers Anirudh Anand, Matan Sandori, and 2Bsecure got credit for finding and reporting three of these.

Separately, Adobe Campaign Classic has a bug of its own. CVE-2026-48286 scores 10.0 and is an incorrect authorization issue that could let an attacker execute arbitrary code. It only affects on-premise deployments — fully on-premise or hybrid setups with on-premise components. Adobe-hosted instances were already patched on the back end.

The Campaign fix ships in version ACC v7: 7.4.3 build 9397. If you’re on build 9396 or earlier, you’re exposed.

No exploits in the wild for any of these yet, according to Adobe. That could change fast.

Adobe also announced it’s moving from monthly to twice-monthly security bulletins starting July 14. Chief Security Officer Aanchal Gupta said AI-accelerated vulnerability discovery is compressing the window between disclosure and exploitation “from days to hours.” The takeaway: expect more patches, more often.

References