Adobe Just Shipped Seven Patches and Three of Them Score a Perfect 10
Cybersecurity

Adobe Just Shipped Seven Patches and Three of Them Score a Perfect 10

ColdFusion and Campaign Classic, two platforms that still run enterprise back offices and marketing operations, picked up three maximum-severity code execution flaws in one release. Adobe's own 72-hour patch guidance shows how seriously it takes the exposure.

PublishedAugust 13, 2026
Read time6 min read
Share

Three CVSS 10s in one bulletin is not routine

Adobe's August security bulletin covers seven vulnerabilities spread across ColdFusion, Commerce, and Campaign Classic. Three of them, CVE-2026-48362 and two Campaign Classic flaws, score the maximum possible 10.0 on the CVSS scale. That concentration is unusual even by the standards of a company whose products have a long history of critical findings over the years, and it is a strong signal that these particular platforms deserve attention well beyond the standard monthly patch cycle most teams default to for vendor updates.

The severity here comes from what each flaw actually enables, not merely from the number attached to it. Every one of the top-tier vulnerabilities in this release leads directly to arbitrary code execution, either through command or eval injection outright, or indirectly through an authorization bypass that hands an attacker the access needed to execute code immediately afterward. There is no partial-credit vulnerability anywhere in this batch, which is unusual for a single bulletin covering three separate product lines.

ColdFusion is still running more of the enterprise than people assume

CVE-2026-48362, an OS command injection flaw, and CVE-2026-48273, an eval injection bug rated 9.9, both live in ColdFusion, a platform many organizations associate with the early 2000s but which still underpins a meaningful share of internal enterprise applications, government portals, and legacy back-office systems that never received a modernization budget large enough to replace them. A third ColdFusion flaw, CVE-2026-71384, is an authorization issue causing denial of service, rounding out a genuinely rough release for a platform many assumed was fading from active enterprise use.

That legacy footprint drives the real risk here. ColdFusion deployments tend to run older, receive less active monitoring, and get staffed by teams carrying less current security tooling than a greenfield application would typically get from day one. Command injection against that kind of environment has repeatedly driven real ColdFusion exploitation campaigns in prior years, and attackers have learned these systems stay under-defended relative to how business-critical they often quietly remain.

Campaign Classic gets the Priority 1 treatment for a reason

Campaign Classic, Adobe's marketing automation platform, picked up two CVSS 10.0 authorization flaws, CVE-2026-71398 and CVE-2026-27302, plus a SQL injection bug rated 9.0 that also facilitates arbitrary code execution against affected instances. Adobe marked the Campaign Classic update Priority 1, its designation reserved for updates addressing vulnerabilities carrying a materially higher risk of exploitation, a rating the company does not hand out casually across its broader product portfolio. Two perfect scores landing on the same platform in one release is a strong indicator of how attackers could chain these flaws together against a single target rather than needing to exploit them in isolation.

Marketing platforms remain an underrated attack surface precisely because security teams tend to prioritize systems that obviously touch core infrastructure or customer payment data over the CRM-adjacent tooling marketing operates semi-independently, often with its own budget and its own vendor relationships. Campaign Classic frequently holds customer contact data, campaign credentials, and integration tokens tied into other enterprise systems, which makes it a genuinely useful pivot point for an attacker even when it was never the ultimate target, and that pivot risk rarely shows up on a marketing team's own vendor risk assessment or gets flagged in a central asset inventory anyone in security actually reviews on a regular basis.

Commerce did not escape either

CVE-2026-71362, rated 9.1, is an authorization vulnerability in Adobe Commerce that enables privilege escalation for an attacker who gains initial access. It ranks as the least severe vulnerability in this bulletin only relative to the perfect-10 flaws sitting next to it in the same release, and privilege escalation inside a commerce platform still opens a direct path to fraud, unauthorized order manipulation, and payment data exposure if the underlying flaw goes unpatched for long.

Commerce platforms have been a recurring target throughout this year across multiple vendors, not Adobe alone, and the pattern holds again here: authorization logic, rather than the core transaction processing itself, is consistently where the exploitable gaps keep turning up. That is a useful signal for any security team deciding where to focus limited review effort on an e-commerce stack, whether it is in-house built or fully vendor-supplied software, and it argues for prioritizing access control audits over the payment logic reviews that usually get the bigger budget.

The exploitation clock is already ticking

Adobe states there is no evidence of these flaws being exploited in the wild as of the bulletin's release, which is worth taking at face value while also treating it as a temporary state of affairs rather than a durable one. ColdFusion in particular carries a track record of moving from disclosure to active exploitation within days once proof-of-concept details start circulating publicly, largely because affected installations tend to sit internet-facing and under-patched relative to how quickly opportunistic attackers scan the internet for them.

Adobe's own guidance reflects that risk calculus directly: install within 72 hours of release. That is an aggressive timeline relative to most change management processes built around monthly or quarterly windows, and it is the appropriate one given exactly what these vulnerabilities enable and how these specific product lines have behaved historically once technical details make it into public view. Teams that cannot hit 72 hours should at minimum isolate internet-facing instances from general network access until the patch lands.

The action list

ColdFusion should move to 2025.0.12 or 2023.0.23 immediately, treating any internet-facing instance as the highest priority regardless of how business-critical it currently appears on paper. Campaign Classic on-premise deployments need a manual update to ACC v7 7.4.4 build 9400, since Adobe-hosted instances are already remediated on Adobe's own side, a distinction worth confirming explicitly with whichever team owns the Campaign Classic relationship rather than simply assuming coverage. Adobe Commerce customers should apply the CVE-2026-71362 fix on the same 72-hour clock rather than treating it as the lower priority item in the bulletin.

Beyond this specific bulletin, use it as a prompt to inventory every ColdFusion and Campaign Classic instance your organization runs anywhere, including ones a business unit or marketing team stood up outside central IT's visibility entirely. Perfect-10 vulnerabilities in platforms nobody is actively watching are exactly the gap a release like this one exposes, and closing it starts with an honest accounting of what your organization actually has running today, followed by a recurring quarterly sweep rather than a one-time cleanup that quietly goes stale within a year.

Tagged#news#security#cybersecurity#breach#cisa#ransomware#zero-day#supply-chain#ai-security#adobe#coldfusion#campaign-classic#adobe-commerce#cve-2026-48362#code-execution#patch-management#enterprise-software-security