Adobe Patches Nine CVSS 10.0/9.3 Flaws in ColdFusion and Campaign Classic Enabling Arbitrary Code Execution (APSB26-68, APSB26-69)

Adobe Patches Nine CVSS 10.0/9.3 Flaws in ColdFusion and (TL-2026-1048), also tracked as APSB26-68, is a critical-severity software vulnerability scored CVSS 10, first published 2026-07-01. It has no confirmed attribution, affects Adobe ColdFusion 2023, references 9 CVEs (CVE-2026-48276, CVE-2026-48283, CVE-2026-48277), maps to 17 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 9 detection rules and 19 indicators of compromise.

Key facts for TL-2026-1048

Threat ID
TL-2026-1048
Also known as
APSB26-68, APSB26-69
Severity
CRITICAL
CVSS
10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
PATCHED
Category
VULNERABILITY
First published
2026-07-01
Last reviewed
2026-07-01
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
technology, government administration, finance, health, education, manufacturing, retail, news - media
Target regions
Global
Detection rules
9
Indicators of compromise
19

Malware and tooling in Adobe Patches Nine CVSS 10.0/9.3 Flaws in ColdFusion and

Malware and tooling: generic web shell, Behinder, China Chopper

Adobe's APSB26-68 and APSB26-69 bulletins (June 30, 2026) patch nine critical vulnerabilities: six CVSS 10.0 unauthenticated RCE flaws in ColdFusion 2023 (≤ Update 20) / 2025 (≤ Update 9) via unrestricted file upload (CWE-434), improper input validation (CWE-20), and path traversal (CWE-22); two CVSS 9.3 ColdFusion flaws for arbitrary file read and privilege escalation; and a CVSS 10.0 incorrect-authorization flaw (CWE-863) in Campaign Classic v7 ≤ 7.4.3 build 9396 enabling arbitrary code execution. Adobe assigned Priority Rating 1 and recommends patching within 72 hours despite finding no evidence of active exploitation.

How Adobe Patches Nine CVSS 10.0/9.3 Flaws in ColdFusion and works

On June 30, 2026, Adobe published two Priority-1 security bulletins covering eleven vulnerabilities across two enterprise products. APSB26-68 addresses Adobe ColdFusion, a widely deployed Java-based (JRun/CFML) web application server, fixing eleven flaws in ColdFusion 2023 (Update 20 and earlier) and ColdFusion 2025 (Update 9 and earlier). Six of these carry the maximum CVSS 3.1 base score of 10.0: CVE-2026-48276 and CVE-2026-48283 (unrestricted upload of dangerous file types, CWE-434) allow an unauthenticated remote attacker to upload and execute arbitrary files; CVE-2026-48277, CVE-2026-48281, and CVE-2026-48316 (improper input validation, CWE-20) and CVE-2026-48282 (path traversal, CWE-22) independently achieve full unauthenticated remote code execution with low attack complexity and no user interaction. Two additional ColdFusion flaws are rated CVSS 9.3: CVE-2026-48313 (path traversal, CWE-22) permits arbitrary file-system read, and CVE-2026-48315 (improper input validation, CWE-20) enables privilege escalation. APSB26-69 addresses Adobe Campaign Classic (ACC), an on-premise marketing-automation platform: CVE-2026-48286, an incorrect authorization flaw (CWE-863) rated CVSS 10.0, allows arbitrary code execution in ACC v7 build 7.4.3.9396 and earlier; the flaw is fixed in build 7.4.3.9397. Only on-premise Campaign Classic deployments require action — Adobe-hosted instances were already patched. Adobe credits researchers Anirudh Anand, Matan Sandori, and the '2Bsecure' team with several of the ColdFusion findings. Adobe states it is not aware of any public proof-of-concept or in-the-wild exploitation of these specific nine CVEs at time of publication, but assigned Priority Rating 1 to both bulletins, its highest urgency tier, reflecting the CVSS 10.0 unauthenticated-RCE nature of six of the flaws and ColdFusion's well-documented history as a high-value target: CISA and the FBI previously issued joint advisory AA23-339A after threat actors exploited CVE-2023-26360 (improper access control) for initial access into a Federal Civilian Executive Branch agency in June 2023, and separate campaigns abused the CVE-2023-29300 Java deserialization flaw to deploy the Behinder web shell against at least 66 ColdFusion servers in Japan across healthcare, education, and manufacturing sectors. Over the past five years CISA has catalogued 79 Adobe product vulnerabilities as actively exploited, ten of them abused by ransomware operations, underscoring the urgency of Adobe's 72-hour patch recommendation for this bulletin. Adobe also announced a shift to a twice-monthly security-bulletin cadence beginning July 14, 2026, intended to accelerate patch delivery for future vulnerabilities.

MITRE ATT&CK techniques used in TL-2026-1048

Collection

T1005 Data from Local System

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information

Execution

T1059 Command and Scripting Interpreter

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Command and Control

T1071 Application Layer Protocol; T1105 Ingress Tool Transfer

Discovery

T1083 File and Directory Discovery

Initial Access

T1190 Exploit Public-Facing Application

Lateral Movement

T1210 Exploitation of Remote Services

Persistence

T1505 Server Software Component

Credential Access

T1552 Unsecured Credentials

Resource Development

T1587 Develop Capabilities; T1588 Obtain Capabilities

Reconnaissance

T1595 Active Scanning; T1596 Search Open Technical Databases

Affected products and versions in Adobe Patches Nine CVSS 10.0/9.3 Flaws in ColdFusion and

  • Adobe — ColdFusion 2023
    Vulnerable versions: Update 20 and earlier
    Fixed in: Update 21
  • Adobe — ColdFusion 2025
    Vulnerable versions: Update 9 and earlier
    Fixed in: Update 10
  • Adobe — Campaign Classic v7
    Vulnerable versions: 7.4.3 build 9396 and earlier (on-premise only)
    Fixed in: 7.4.3 build 9397

Remediation for Adobe Patches Nine CVSS 10.0/9.3 Flaws in ColdFusion and

Patches

  • ColdFusion 2023 Update 21
  • ColdFusion 2025 Update 10
  • Campaign Classic v7 build 7.4.3.9397 (Windows/Linux)

Immediate actions

  • Apply ColdFusion 2023 Update 21 or ColdFusion 2025 Update 10 to all on-premise instances within 72 hours per Adobe's Priority 1 rating
  • Apply Campaign Classic v7 build 7.4.3.9397 to all on-premise ACC deployments (Adobe-hosted ACC instances are already patched)
  • Restrict internet exposure of ColdFusion administrative interfaces (/CFIDE/) and upload-handling endpoints until patched
  • Audit ColdFusion servers for unexpected file uploads, unfamiliar .cfm/.jsp/.war files, and anomalous cfusion.exe/jrun.exe child processes

Workarounds

  • Disable or restrict access to file-upload-capable endpoints and the CFIDE administrator path pending patch deployment
  • Take on-premise Campaign Classic offline or restrict to trusted networks until build 7.4.3.9397 is applied

Longer-term hardening

  • Deploy a WAF or virtual-patching rule set in front of ColdFusion/Campaign Classic until validated patch deployment across the fleet
  • Implement network segmentation so ColdFusion/Campaign Classic servers cannot reach sensitive internal systems directly
  • Enable centralized logging/EDR on ColdFusion hosts given the product's history of webshell-based compromise
  • Establish a recurring patch-management cadence aligned to Adobe's new twice-monthly bulletin schedule (effective 2026-07-14)

CVEs associated with Adobe Patches Nine CVSS 10.0/9.3 Flaws in ColdFusion and

CVE-2026-48276, CVE-2026-48283, CVE-2026-48277, CVE-2026-48281, CVE-2026-48316, CVE-2026-48282, CVE-2026-48313, CVE-2026-48315, CVE-2026-48286

Weaknesses (CWE) in Adobe Patches Nine CVSS 10.0/9.3 Flaws in ColdFusion and

CWE-434, CWE-20, CWE-22, CWE-863

Timeline of Adobe Patches Nine CVSS 10.0/9.3 Flaws in ColdFusion and

  • Rapid7 observed active exploitation attempts against Adobe ColdFusion vulnerabilities in the wild.
  • TeamT5/RH-ISAC reporting attributes exploitation of the CVE-2023-29300 WDDX deserialization flaw to the China-nexus APT group SLIME13 (also tracked as Flax Typhoon), which used unauthenticated CFC endpoint access and JNDI injection to load Behinder web shells.
  • Threat actors exploited CVE-2023-26360 for initial access into a Federal Civilian Executive Branch agency ColdFusion server, per CISA/FBI joint advisory AA23-339A — cited by Adobe/researchers as context for ColdFusion's history as a high-value target.
  • Qualys ThreatPROTECT documents active exploitation of CVE-2023-29298, CVE-2023-29300, and CVE-2023-38203 to drop web shells on Adobe ColdFusion servers.
  • CISA and FBI publish joint Cybersecurity Advisory AA23-339A detailing ColdFusion CVE-2023-26360 exploitation against government servers.
  • Campaign Classic v7 build 7.4.3.9397 released, fixing CVE-2026-48286 for on-premise deployments.
  • ColdFusion 2025 Update 10 released, fixing the same vulnerability set in the 2025 branch.
  • ColdFusion 2023 Update 21 released, fixing all nine tracked ColdFusion/Campaign Classic CVEs in the 2023 branch.
  • Adobe publishes Priority-1 security bulletins APSB26-68 (ColdFusion, 11 CVEs) and APSB26-69 (Campaign Classic, 1 CVE).
  • The Hacker News, BleepingComputer, SecurityWeek, and gbhackers publish coverage of the Adobe bulletins, highlighting the six CVSS 10.0 unauthenticated RCE flaws.
  • Adobe's announced shift to a twice-monthly security bulletin cadence takes effect, intended to accelerate future patch delivery.

Sources cited for Adobe Patches Nine CVSS 10.0/9.3 Flaws in ColdFusion and

Threats related to Adobe Patches Nine CVSS 10.0/9.3 Flaws in ColdFusion and

Detection coverage for TL-2026-1048

As of 2026-07-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1048 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats