Adobe Patches Nine CVSS 10.0/9.3 Flaws in ColdFusion and Campaign Classic Enabling Arbitrary Code Execution (APSB26-68, APSB26-69)
Adobe Patches Nine CVSS 10.0/9.3 Flaws in ColdFusion and (TL-2026-1048), also tracked as APSB26-68, is a critical-severity software vulnerability scored CVSS 10, first published 2026-07-01. It has no confirmed attribution, affects Adobe ColdFusion 2023, references 9 CVEs (CVE-2026-48276, CVE-2026-48283, CVE-2026-48277), maps to 17 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 9 detection rules and 19 indicators of compromise.
Key facts for TL-2026-1048
- Threat ID
- TL-2026-1048
- Also known as
- APSB26-68, APSB26-69
- Severity
- CRITICAL
- CVSS
- 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- 2026-07-01
- Last reviewed
- 2026-07-01
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- technology, government administration, finance, health, education, manufacturing, retail, news - media
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 19
Malware and tooling in Adobe Patches Nine CVSS 10.0/9.3 Flaws in ColdFusion and
Malware and tooling: generic web shell, Behinder, China Chopper
Adobe's APSB26-68 and APSB26-69 bulletins (June 30, 2026) patch nine critical vulnerabilities: six CVSS 10.0 unauthenticated RCE flaws in ColdFusion 2023 (≤ Update 20) / 2025 (≤ Update 9) via unrestricted file upload (CWE-434), improper input validation (CWE-20), and path traversal (CWE-22); two CVSS 9.3 ColdFusion flaws for arbitrary file read and privilege escalation; and a CVSS 10.0 incorrect-authorization flaw (CWE-863) in Campaign Classic v7 ≤ 7.4.3 build 9396 enabling arbitrary code execution. Adobe assigned Priority Rating 1 and recommends patching within 72 hours despite finding no evidence of active exploitation.
How Adobe Patches Nine CVSS 10.0/9.3 Flaws in ColdFusion and works
On June 30, 2026, Adobe published two Priority-1 security bulletins covering eleven vulnerabilities across two enterprise products. APSB26-68 addresses Adobe ColdFusion, a widely deployed Java-based (JRun/CFML) web application server, fixing eleven flaws in ColdFusion 2023 (Update 20 and earlier) and ColdFusion 2025 (Update 9 and earlier). Six of these carry the maximum CVSS 3.1 base score of 10.0: CVE-2026-48276 and CVE-2026-48283 (unrestricted upload of dangerous file types, CWE-434) allow an unauthenticated remote attacker to upload and execute arbitrary files; CVE-2026-48277, CVE-2026-48281, and CVE-2026-48316 (improper input validation, CWE-20) and CVE-2026-48282 (path traversal, CWE-22) independently achieve full unauthenticated remote code execution with low attack complexity and no user interaction. Two additional ColdFusion flaws are rated CVSS 9.3: CVE-2026-48313 (path traversal, CWE-22) permits arbitrary file-system read, and CVE-2026-48315 (improper input validation, CWE-20) enables privilege escalation. APSB26-69 addresses Adobe Campaign Classic (ACC), an on-premise marketing-automation platform: CVE-2026-48286, an incorrect authorization flaw (CWE-863) rated CVSS 10.0, allows arbitrary code execution in ACC v7 build 7.4.3.9396 and earlier; the flaw is fixed in build 7.4.3.9397. Only on-premise Campaign Classic deployments require action — Adobe-hosted instances were already patched. Adobe credits researchers Anirudh Anand, Matan Sandori, and the '2Bsecure' team with several of the ColdFusion findings. Adobe states it is not aware of any public proof-of-concept or in-the-wild exploitation of these specific nine CVEs at time of publication, but assigned Priority Rating 1 to both bulletins, its highest urgency tier, reflecting the CVSS 10.0 unauthenticated-RCE nature of six of the flaws and ColdFusion's well-documented history as a high-value target: CISA and the FBI previously issued joint advisory AA23-339A after threat actors exploited CVE-2023-26360 (improper access control) for initial access into a Federal Civilian Executive Branch agency in June 2023, and separate campaigns abused the CVE-2023-29300 Java deserialization flaw to deploy the Behinder web shell against at least 66 ColdFusion servers in Japan across healthcare, education, and manufacturing sectors. Over the past five years CISA has catalogued 79 Adobe product vulnerabilities as actively exploited, ten of them abused by ransomware operations, underscoring the urgency of Adobe's 72-hour patch recommendation for this bulletin. Adobe also announced a shift to a twice-monthly security-bulletin cadence beginning July 14, 2026, intended to accelerate patch delivery for future vulnerabilities.
MITRE ATT&CK techniques used in TL-2026-1048
Collection
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information
Execution
T1059 Command and Scripting Interpreter
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Command and Control
T1071 Application Layer Protocol; T1105 Ingress Tool Transfer
Discovery
T1083 File and Directory Discovery
Initial Access
T1190 Exploit Public-Facing Application
Lateral Movement
T1210 Exploitation of Remote Services
Persistence
T1505 Server Software Component
Credential Access
Resource Development
T1587 Develop Capabilities; T1588 Obtain Capabilities
Reconnaissance
T1595 Active Scanning; T1596 Search Open Technical Databases
Affected products and versions in Adobe Patches Nine CVSS 10.0/9.3 Flaws in ColdFusion and
- Adobe — ColdFusion 2023
Vulnerable versions: Update 20 and earlier
Fixed in: Update 21 - Adobe — ColdFusion 2025
Vulnerable versions: Update 9 and earlier
Fixed in: Update 10 - Adobe — Campaign Classic v7
Vulnerable versions: 7.4.3 build 9396 and earlier (on-premise only)
Fixed in: 7.4.3 build 9397
Remediation for Adobe Patches Nine CVSS 10.0/9.3 Flaws in ColdFusion and
Patches
- ColdFusion 2023 Update 21
- ColdFusion 2025 Update 10
- Campaign Classic v7 build 7.4.3.9397 (Windows/Linux)
Immediate actions
- Apply ColdFusion 2023 Update 21 or ColdFusion 2025 Update 10 to all on-premise instances within 72 hours per Adobe's Priority 1 rating
- Apply Campaign Classic v7 build 7.4.3.9397 to all on-premise ACC deployments (Adobe-hosted ACC instances are already patched)
- Restrict internet exposure of ColdFusion administrative interfaces (/CFIDE/) and upload-handling endpoints until patched
- Audit ColdFusion servers for unexpected file uploads, unfamiliar .cfm/.jsp/.war files, and anomalous cfusion.exe/jrun.exe child processes
Workarounds
- Disable or restrict access to file-upload-capable endpoints and the CFIDE administrator path pending patch deployment
- Take on-premise Campaign Classic offline or restrict to trusted networks until build 7.4.3.9397 is applied
Longer-term hardening
- Deploy a WAF or virtual-patching rule set in front of ColdFusion/Campaign Classic until validated patch deployment across the fleet
- Implement network segmentation so ColdFusion/Campaign Classic servers cannot reach sensitive internal systems directly
- Enable centralized logging/EDR on ColdFusion hosts given the product's history of webshell-based compromise
- Establish a recurring patch-management cadence aligned to Adobe's new twice-monthly bulletin schedule (effective 2026-07-14)
CVEs associated with Adobe Patches Nine CVSS 10.0/9.3 Flaws in ColdFusion and
CVE-2026-48276, CVE-2026-48283, CVE-2026-48277, CVE-2026-48281, CVE-2026-48316, CVE-2026-48282, CVE-2026-48313, CVE-2026-48315, CVE-2026-48286
Weaknesses (CWE) in Adobe Patches Nine CVSS 10.0/9.3 Flaws in ColdFusion and
CWE-434, CWE-20, CWE-22, CWE-863
Timeline of Adobe Patches Nine CVSS 10.0/9.3 Flaws in ColdFusion and
- Rapid7 observed active exploitation attempts against Adobe ColdFusion vulnerabilities in the wild.
- TeamT5/RH-ISAC reporting attributes exploitation of the CVE-2023-29300 WDDX deserialization flaw to the China-nexus APT group SLIME13 (also tracked as Flax Typhoon), which used unauthenticated CFC endpoint access and JNDI injection to load Behinder web shells.
- Threat actors exploited CVE-2023-26360 for initial access into a Federal Civilian Executive Branch agency ColdFusion server, per CISA/FBI joint advisory AA23-339A — cited by Adobe/researchers as context for ColdFusion's history as a high-value target.
- Qualys ThreatPROTECT documents active exploitation of CVE-2023-29298, CVE-2023-29300, and CVE-2023-38203 to drop web shells on Adobe ColdFusion servers.
- CISA and FBI publish joint Cybersecurity Advisory AA23-339A detailing ColdFusion CVE-2023-26360 exploitation against government servers.
- Campaign Classic v7 build 7.4.3.9397 released, fixing CVE-2026-48286 for on-premise deployments.
- ColdFusion 2025 Update 10 released, fixing the same vulnerability set in the 2025 branch.
- ColdFusion 2023 Update 21 released, fixing all nine tracked ColdFusion/Campaign Classic CVEs in the 2023 branch.
- Adobe publishes Priority-1 security bulletins APSB26-68 (ColdFusion, 11 CVEs) and APSB26-69 (Campaign Classic, 1 CVE).
- The Hacker News, BleepingComputer, SecurityWeek, and gbhackers publish coverage of the Adobe bulletins, highlighting the six CVSS 10.0 unauthenticated RCE flaws.
- Adobe's announced shift to a twice-monthly security bulletin cadence takes effect, intended to accelerate future patch delivery.
Sources cited for Adobe Patches Nine CVSS 10.0/9.3 Flaws in ColdFusion and
- Adobe Patches 7 CVSS 10.0 Flaws in ColdFusion, Campaign Classic
- Adobe Security Bulletin APSB26-68 (ColdFusion)
- Adobe Security Bulletin APSB26-69 (Campaign Classic)
- Adobe patches seven max severity ColdFusion, Campaign flaws
- Adobe Patches Critical ColdFusion, Campaign Classic Vulnerabilities
- Adobe ColdFusion Critical Vulnerabilities Let Attackers Execute Arbitrary Code
- Threat Actors Exploit Adobe ColdFusion CVE-2023-26360 for Initial Access to Government Servers (AA23-339A)
- CVE-2023-29300: Adobe ColdFusion Vulnerability
- Rapid7 Observed Exploitation of Adobe ColdFusion
- Adobe ColdFusion Vulnerabilities Exploited in the Attacks in Dropping Webshell (CVE-2023-29298, CVE-2023-29300, CVE-2023-38203)
- TeamT5 Releases Latest Developments on Active Exploitation of Adobe ColdFusion Vulnerability (RH-ISAC)
Threats related to Adobe Patches Nine CVSS 10.0/9.3 Flaws in ColdFusion and
- Adobe ColdFusion & Campaign Classic Priority 1 Patches for 12 Vulnerabilities Including Six Maximum-Severity RCE Flaws (APSB26-68, APSB26-69)
- Multiple Critical Adobe ColdFusion Vulnerabilities (CVE-2026-48276 et al., APSB26-68) Enable Unauthenticated Remote Code Execution
- Adobe Patches Seven Priority-1 ColdFusion and Campaign Classic Flaws (CVE-2026-48276, CVE-2026-48277, CVE-2026-48281, CVE-2026-48282, CVE-2026-48316, CVE-2026-48286)
- Adobe ColdFusion Critical Path Traversal in RDS FILEIO Handler Enables Unauthenticated RCE (CVE-2026-48282)
- Multi-Vendor Critical Patch Roundup: Firefox 152.0.6, Chrome 150, Adobe ColdFusion/Commerce/AEM (APSB26-68/73/74), and VMware Avi Load Balancer (VMSA-2026-0005)
- Adobe Campaign Classic Critical Incorrect Authorization Flaw Enables Unauthenticated Remote Code Execution (CVE-2026-48449) Paired With SQL Injection Memory/File Disclosure (CVE-2026-48448)
Detection coverage for TL-2026-1048
As of 2026-07-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1048 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.