Affected Systems

Adobe ColdFusion 2025.0.x (prior to 2025.0.12) and 2023.0.x (prior to 2023.0.23); Adobe Campaign Classic v7 (prior to 7.4.4 build 9400) on-premise and hybrid deployments; Adobe Commerce (version not specified). CVE-2026-48362 (OS command injection), CVE-2026-71398, and CVE-2026-27302 all rated CVSS 10.0.

Exploitation Status

No evidence of active exploitation in the wild at time of disclosure. Adobe rates ColdFusion and Campaign Classic updates as Priority 1, indicating higher risk of future targeting.

Business Impact

Critical risk for organizations running on-premise or hybrid Adobe ColdFusion and Campaign Classic deployments. CVE-2026-48362 enables unauthenticated OS command injection leading to full system compromise. Campaign Classic flaws (CVE-2026-71398, CVE-2026-27302) allow arbitrary code execution via authorization bypass. Adobe Commerce flaw enables privilege escalation. Adobe-hosted Campaign Classic instances already patched. Exploitation could result in complete server takeover, data exfiltration, and lateral movement.

Urgency

🟠 Within 24 hours

Recommended Actions

  • Update Adobe ColdFusion to version 2025.0.12 or 2023.0.23 within 72 hours per Adobe Priority 1 guidance
  • Update Adobe Campaign Classic v7 on-premise and hybrid deployments to version 7.4.4 build 9400 immediately
  • Apply available patches for Adobe Commerce to address CVE-2026-71362 privilege escalation flaw
  • Verify Adobe-hosted Campaign Classic instances are on patched builds (no customer action required)
  • Monitor ColdFusion and Campaign Classic logs for suspicious command execution, SQL injection attempts, or unauthorized privilege changes
  • Restrict network access to ColdFusion and Campaign Classic administrative interfaces to trusted IP ranges