Adobe Patches Critical RCE Flaws in ColdFusion, Campaign Classic, and Commerce (CVE-2026-48362, CVSS 10.0)
Adobe Patches Critical RCE Flaws in ColdFusion, Campaign (TL-2026-1985) is a critical-severity software vulnerability scored CVSS 10, first published 2026-08-11 and last reviewed 2026-08-12. It has no confirmed attribution, affects Adobe ColdFusion, references 13 CVEs (CVE-2026-48362, CVE-2026-48273, CVE-2026-71384), maps to 20 MITRE ATT&CK techniques (T1005, T1059, T1068), and is covered by 9 detection rules and 34 indicators of compromise.
Key facts for TL-2026-1985
- Threat ID
- TL-2026-1985
- Severity
- CRITICAL
- CVSS
- 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-08-11
- Last reviewed
- 2026-08-12
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- government administration, finance, health, retail, technology, education
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 34
- Updates
- 2026-08-12 · 2 updates · revalidated 2× · latest source
Adobe's August 11, 2026 Priority 1 security updates fix 15 ColdFusion defects (3 critical, including CVE-2026-48362, an OS command injection scoring CVSS 10.0), three critical Campaign Classic flaws (two CVSS 10.0 authorization bypasses and one CVSS 9.0 SQL injection), and one CVSS 9.1 Commerce privilege-escalation flaw, all leading to arbitrary code execution or unauthorized access. Adobe reports no known in-the-wild exploitation of this specific CVE bundle, but assigns it the same Priority 1 designation it gave the actively-exploited ColdFusion RDS flaw (CVE-2026-48282, added to CISA KEV on 2026-07-07) six weeks earlier, reflecting the platform's established pattern of rapid n-day weaponization.
How Adobe Patches Critical RCE Flaws in ColdFusion, Campaign works
On August 11, 2026, Adobe shipped a wave of Priority 1 and Priority 2 security bulletins covering three enterprise products. ColdFusion received fixes for 15 vulnerabilities, three of them critical: CVE-2026-48362 (CVSS 10.0), an unauthenticated OS command injection permitting arbitrary code execution on the underlying server; CVE-2026-48273 (CVSS 9.9), an eval-injection flaw allowing attacker-controlled expressions to be evaluated server-side; and CVE-2026-71384 (CVSS 9.6), an incorrect-authorization defect that lets an attacker bypass access controls to reach privileged functionality. Campaign Classic, Adobe's on-premises marketing-automation/CDP platform, received fixes for three critical flaws: CVE-2026-71398 and CVE-2026-27302 (both CVSS 10.0, incorrect authorization leading to arbitrary code execution) and CVE-2026-48381 (CVSS 9.0, SQL injection). Adobe Commerce (Magento) received a Priority 2 fix for CVE-2026-71362 (CVSS 9.1), an incorrect-authorization flaw enabling privilege escalation.
Adobe states it is not aware of any exploitation in the wild for any of the newly disclosed defects, but assigned Priority 1 to both ColdFusion and Campaign Classic, its internal designation reserved for flaws Adobe judges to carry a higher risk of imminent targeting once technical details or patch diffs become available. This assessment is grounded in recent history: ColdFusion has been the subject of repeated maximum-severity bulletins throughout 2026 (APSB26-68 on 2026-06-30, seven CVSS-10.0 flaws including CVE-2026-48282, a Remote Development Services (RDS) FILEIO path-traversal bug that CISA added to the Known Exploited Vulnerabilities catalog on 2026-07-07 after confirming limited in-the-wild attacks), and Campaign Classic has independently drawn two other maximum-severity authorization-bypass bulletins in the six weeks preceding this one (CVE-2026-48286 in APSB26-69/July 2026; CVE-2026-48331/48323/48330 in APSB26-120 on 2026-08-03). The RDS/CKEditor exploitation chain documented for the actively-exploited CVE-2026-48282 (crafted RDS FILEIO packets against `/CFIDE/main/ide.cfm?ACTION=FILEIO` for arbitrary file read/write, and path-traversal in the CKEditor file-manager upload endpoint) illustrates the class of post-exploitation behavior — arbitrary file write to drop a CFML web shell, executing with NT AUTHORITY\SYSTEM privileges — that the same underlying platform has already suffered, and represents the realistic worst case for this new, not-yet-exploited CVE bundle should a public PoC emerge.
Adobe formalized a twice-monthly security-bulletin cadence effective 2026-07-14, and continues to ship an Isolated Patch mechanism for Commerce/Magento merchants to apply fixes with reduced integration risk. Defenders running any of the three affected products should treat immediate patching as the priority given the Priority 1 rating, even absent confirmed exploitation, because Adobe's own track record this year shows the gap between disclosure and active exploitation of its ColdFusion/Campaign Classic products has been measured in single-digit days.
MITRE ATT&CK techniques used in TL-2026-1985
Collection
T1005 Data from Local System; T1213 Data from Information Repositories; T1213.004 Data from Information Repositories
Execution
T1059 Command and Scripting Interpreter; T1204.001 User Execution: Malicious Link
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Discovery
T1082 System Information Discovery
Initial Access
T1190 Exploit Public-Facing Application
Lateral Movement
T1210 Exploitation of Remote Services
Defense Evasion
T1211 Exploitation for Defense Evasion
Impact
T1486 Data Encrypted for Impact; T1499 Endpoint Denial of Service; T1499.004 Endpoint Denial of Service
Persistence
T1505.003 Server Software Component: Web Shell
Credential Access
T1552.001 Unsecured Credentials: Credentials In Files
Resource Development
T1588.005 Obtain Capabilities: Exploits; T1588.006 Obtain Capabilities
Reconnaissance
T1592.002 Gather Victim Host Information; T1595.002 Active Scanning; T1596.005 Search Open Technical Databases
Affected products and versions in Adobe Patches Critical RCE Flaws in ColdFusion, Campaign
- Adobe — ColdFusion
Vulnerable versions: 2025 Update 9 and earlier; 2023 Update 20 and earlier
Fixed in: 2025 Update 10; 2023 Update 21 - Adobe — Campaign Classic
Vulnerable versions: 7.4.3 build 9398 and earlier
Fixed in: 7.4.3 post-9398 fixed build - Adobe — Commerce / Magento Open Source
Vulnerable versions: pre-August 2026 security patch
Fixed in: August 2026 security patch / Isolated Patch
Remediation for Adobe Patches Critical RCE Flaws in ColdFusion, Campaign
Patches
- ColdFusion 2025 Update 10
- ColdFusion 2023 Update 21
- Adobe Campaign Classic 7.4.3 fixed build (post build 9398)
- Adobe Commerce / Magento Open Source August 2026 security patch
Immediate actions
- Apply ColdFusion 2025 Update 10 or ColdFusion 2023 Update 21 immediately (Priority 1 — 72-hour Adobe guidance).
- Apply the Adobe Campaign Classic 7.4.3 fixed build addressing CVE-2026-71398, CVE-2026-27302, and CVE-2026-48381.
- Apply the Adobe Commerce/Magento Open Source patch or Isolated Patch resolving CVE-2026-71362 within Adobe's 30-day Priority 2 window.
- If RDS (Remote Development Services) is enabled on any ColdFusion instance, disable it in production unless strictly required.
- Restrict network exposure of ColdFusion admin, RDS, and CKEditor file-manager endpoints (`/CFIDE/*`, `/cf_scripts/scripts/ajax/ckeditor/*`) to trusted management networks.
Workarounds
- Disable RDS on internet-facing ColdFusion servers where patching cannot be completed immediately.
- Disable file uploads in the ColdFusion CKEditor integration where not required.
Longer-term hardening
- Adopt Adobe's twice-monthly security-bulletin cadence into patch-management SLAs for ColdFusion, Campaign Classic, and Commerce.
- Deploy file-integrity monitoring on ColdFusion webroot directories to detect unauthorized CFML file writes (web shell deployment).
- Deploy WAF/RASP rules for OS command-injection and eval-injection payload patterns on ColdFusion-fronted applications.
- Review Campaign Classic and Commerce admin-role assignments for least-privilege compliance given the recurring incorrect-authorization vulnerability class.
CVEs associated with Adobe Patches Critical RCE Flaws in ColdFusion, Campaign
CVE-2026-48362CVE-2026-48273CVE-2026-71384CVE-2026-71398CVE-2026-27302CVE-2026-48381CVE-2026-71362CVE-2026-71387CVE-2026-71386CVE-2026-48440CVE-2026-34635CVE-2026-48386CVE-2026-21279
Weaknesses (CWE) in Adobe Patches Critical RCE Flaws in ColdFusion, Campaign
CWE-78, CWE-95, CWE-863, CWE-89, CWE-79, CWE-122, CWE-321, CWE-327, CWE-20
Timeline of Adobe Patches Critical RCE Flaws in ColdFusion, Campaign
Showing the 20 most recent tracked events.
- CISA advisory AA23-339A documents threat actors exploiting CVE-2023-26360 to breach at least two US federal agency ColdFusion servers, dropping web shells via HTTP POST for initial access and lateral movement.
- Sophos reports a LockBit-derivative ransomware payload being deployed against outdated, unpatched Adobe ColdFusion servers.
- Adobe releases APSB26-68 for ColdFusion, fixing seven CVSS 10.0 RDS/CKEditor RCE flaws including CVE-2026-48282.
- Horizon3.ai's NodeZero autonomous penetration-testing platform independently exploits sibling flaw CVE-2026-48283 via the CKEditor filemanager upload.cfm endpoint, confirming full ColdFusion host compromise in 1 minute 27 seconds.
- SecurityWeek, BleepingComputer, and The Hacker News report on the APSB26-68/APSB26-69 maximum-severity ColdFusion and Campaign Classic bulletins (Priority 1, CVE-2026-48286 CVSS 10.0 in Campaign Classic).
- watchTowr Labs publishes technical analysis of the ColdFusion RDS-abuse RCE (CVE-2026-48282); KEVIntel honeypot sensors record live exploitation attempts within roughly two hours of publication.
- CISA adds CVE-2026-48282 (ColdFusion RDS path traversal) to the Known Exploited Vulnerabilities catalog after confirming limited in-the-wild attacks; remediation due 2026-07-10.
- CISA-mandated federal remediation deadline for CVE-2026-48282 passes.
- Adobe formalizes a twice-monthly security-bulletin cadence and releases APSB26-73 (Commerce, Priority 2) and further ColdFusion fixes (APSB26-82).
- Adobe published APSB26-114 for Campaign Classic, fixing CVE-2026-48449 (Incorrect Authorization, CVSS 10.0) and CVE-2026-48448 (SQL Injection, CVSS 8.6); fix shipped as v7.4.3 build 9398 — the first of three critical ACC bulletins in an 11-day window culminating in APSB26-123.
- Adobe releases APSB26-120 for Campaign Classic, fixing three more CVSS 10.0 unauthenticated RCE flaws (CVE-2026-48331, CVE-2026-48323, CVE-2026-48330).
- Adobe's APSB26-120 bulletin was revised a day after publication; independent technical breakdowns of its seven CVEs were published around this time.
- Adobe publishes Security Bulletin APSB26-90 disclosing nine ColdFusion CVEs (CVE-2026-48362, CVE-2026-48273, CVE-2026-71384, CVE-2026-71387, CVE-2026-71386, CVE-2026-48440, CVE-2026-34635, CVE-2026-48386, CVE-2026-21279), Priority 1, released alongside the separate Campaign Classic bulletin.
- Zero Day Initiative's August 2026 Security Update Review flagged APSB26-123 as containing two CVSS 10.0 bugs, carrying Priority 1 alongside ColdFusion's APSB26-90, and explicitly superseding the August 3 APSB26-120 patch.
- NVD published CVE-2026-27302, CVE-2026-71398, and CVE-2026-48381 citing APSB26-123 specifically as the source advisory, distinct from the earlier APSB26-120 bulletin covering the same CVE numbers' predecessor build.
- SecurityWeek publishes 'Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws,' urging immediate remediation given the Priority 1 rating.
- Adobe releases Priority 1 bulletins for ColdFusion (15 flaws, 3 critical incl. CVE-2026-48362 CVSS 10.0 OS command injection) and Campaign Classic (3 critical incl. two CVSS 10.0 authorization bypasses), plus a Priority 2 Commerce bulletin (CVE-2026-71362 CVSS 9.1 privilege escalation); Adobe states no known in-the-wild exploitation.
- None of the nine APSB26-90 CVEs (including CVE-2026-48362 and CVE-2026-48273) appear in the CISA Known Exploited Vulnerabilities catalog as of this date.
- AUSCERT published ESB-2026.9366 citing APSB26-123, corroborating the bulletin's existence and Priority 1 status (technical CVE-level detail member-gated).
- Adobe's APSB26-123 bulletin is confirmed to supersede APSB26-120; the correct fixed release for CVE-2026-27302, CVE-2026-71398, and CVE-2026-48381 is ACC v7.4.4 build 9400, not the build 9398/9399 fix originally recorded — organizations that fully remediated APSB26-120 remain exposed until upgrading again.
Update history for TL-2026-1985
- 2026-08-12 — Adobe ColdFusion Multiple Vulnerabilities Including Critical Unauthenticated RCE (CVE-2026-48362, CVSS 10.0): What changed No severity/exploitability/status change — both reports independently assess CRITICAL/THEORETICAL/no confirmed in-the-wild exploitation. This report identifies the ColdFusion bulletin by its official ID (APSB26-90) and expands
- 2026-08-12 — Adobe Campaign Classic Critical Vulnerabilities (APSB26-123, CVSS 10.0) Supersede August 3 Patch: What changed No severity/exploitability/status escalation — both reports independently rate CVE-2026-27302, CVE-2026-71398, and CVE-2026-48381 CRITICAL/CVSS 10.0-9.0/THEORETICAL exploitability. What changed is remediation precision: the tru
Sources cited for Adobe Patches Critical RCE Flaws in ColdFusion, Campaign
- Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws
- APSB26-68 - Adobe Security Bulletin (ColdFusion, RDS/CKEditor RCE incl. actively-exploited CVE-2026-48282)
- It's 37oC, And All We Can Think About Is ColdFusion (APSB26-68 CVE Bonanza)
- Vulnerability Summary for the Week of June 29, 2026
- CVE-2026-48282: Adobe ColdFusion RCE Actively Exploited
- Attackers exploit critical Adobe ColdFusion vulnerability (CVE-2026-48282)
- Adobe patches seven max severity ColdFusion, Campaign flaws
- Adobe Patches 7 CVSS 10.0 Flaws in ColdFusion and Campaign Classic
- Security updates available for Adobe Campaign Classic | APSB26-120
- APSB26-73: Adobe Commerce July 2026 Security Update
Threats related to Adobe Patches Critical RCE Flaws in ColdFusion, Campaign
- Adobe ColdFusion & Campaign Classic Priority 1 Patches for 12 Vulnerabilities Including Six Maximum-Severity RCE Flaws (APSB26-68, APSB26-69)
- Multiple Critical Adobe ColdFusion Vulnerabilities (CVE-2026-48276 et al., APSB26-68) Enable Unauthenticated Remote Code Execution
- Adobe ColdFusion Critical Path Traversal in RDS FILEIO Handler Enables Unauthenticated RCE (CVE-2026-48282)
- CVE-2026-32746: Pre-Auth BSS Buffer Overflow in GNU inetutils telnetd LINEMODE SLC Handling
- CVE-2026-23918 — Apache HTTP Server mod_http2 Double Free Enabling Unauthenticated DoS and Possible RCE
- Google Chrome 151 Update Fixes 41 Security Vulnerabilities, Including 6 Critical Flaws
Detection coverage for TL-2026-1985
As of 2026-08-12, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1985 across Splunk SPL, Microsoft KQL and Sigma, covering 34 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.