Protect.Computer
NEWS

Adobe Patches Critical Flaws in ColdFusion and Campaign

· 1 min read · Malicious byte
Adobe Patches Critical Flaws in ColdFusion and Campaign

Adobe has released emergency security patches for seven critical flaws across two server-side products: ColdFusion (a web application platform used by thousands of business websites) and Campaign Classic (its on-premises email marketing software). All seven vulnerabilities earned Adobe’s most serious “Priority 1” rating, meaning the company considers exploitation highly likely.

Six of the flaws — tracked as CVE-2026-48276, CVE-2026-48277, CVE-2026-48281, CVE-2026-48282, and CVE-2026-48316 — affect ColdFusion and allow an attacker to execute code on a vulnerable web server without any login credentials. The seventh flaw (CVE-2026-48286) affects on-premises Campaign Classic instances and lets attackers run arbitrary code in the context of the application. Adobe says it is not aware of active exploits yet, but is recommending installation within 72 hours given the severity.

How to check if you’re affected

Affected versions include ColdFusion 2025 before update 9 (i.e., update 8 and earlier) and ColdFusion 2023 before update 20. For Campaign Classic, affected versions are 7.4.3 build 9396 and older. If you manage a website or server running either product, check your version number in the product’s administration console and apply the latest available update immediately. Campaign Classic users on Adobe-managed cloud instances are already patched automatically.

Sources

Related reading