Adobe Patches Critical RCE Flaws in ColdFusion, Campaign Classic, and Commerce (CVE-2026-48362, CVSS 10.0) — Threadlinqs Intelligence
As of 2026-08-12, Adobe Patches Critical RCE Flaws in ColdFusion, Campaign Classic, and Commerce (CVE-2026-48362, CVSS 10.0) is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 34 indicators of compromise.
Threat ID: TL-2026-1985 · Severity: CRITICAL · CVSS: 10 · Status: ACTIVE · Category: VULNERABILITY
Updated: 2026-08-12 · 2 updates · revalidated 2× · latest source
Adobe's August 11, 2026 Priority 1 security updates fix 15 ColdFusion defects (3 critical, including CVE-2026-48362, an OS command injection scoring CVSS 10.0), three critical Campaign Classic flaws
On August 11, 2026, Adobe shipped a wave of Priority 1 and Priority 2 security bulletins covering three enterprise products. ColdFusion received fixes for 15 vulnerabilities, three of them critical: CVE-2026-48362 (CVSS 10.0), an unauthenticated OS command injection permitting arbitrary code execution on the underlying server; CVE-2026-48273 (CVSS 9.9), an eval-injection flaw allowing attacker-controlled expressions to be evaluated server-side; and CVE-2026-71384 (CVSS 9.6), an incorrect-authorization defect that lets an attacker bypass access controls to reach privileged functionality. Campaign Classic, Adobe's on-premises marketing-automation/CDP platform, received fixes for three critical flaws: CVE-2026-71398 and CVE-2026-27302 (both CVSS 10.0, incorrect authorization leading to arbitrary code execution) and CVE-2026-48381 (CVSS 9.0, SQL injection). Adobe Commerce (Magento) received a Priority 2 fix for CVE-2026-71362 (CVSS 9.1), an incorrect-authorization flaw enabling privilege escalation.
Adobe states it is not aware of any exploitation in the wild for any of the newly disclosed defects, but assigned Priority 1 to both ColdFusion and Campaign Classic, its internal designation reserved for flaws Adobe judges to carry a higher risk of imminent targeting once technical details or patch diffs become available. This assessment is grounded in recent history: ColdFusion has been the subject of repeated maximum-severity bulletins throughout 2026 (APSB26-68 on 2026-06-30, seven CVSS-10.0 flaws including CVE-2026-48282, a Remote Development Services (RDS) FILEIO path-traversal bug that CISA added to the Known Exploited Vulnerabilities catalog on 2026-07-07 after confirming limited in-the-wild attacks), and Campaign Classic has independently drawn two other maximum-severity authorization-bypass bulletins in the six weeks preceding this one (CVE-2026-48286 in APSB26-69/July 2026; CVE-2026-48331/48323/48330 in APSB26-120 on 2026-08-03). The RDS/CKEditor exploitation chain documented for the actively-exploited CVE-2026-48282 (crafted RDS FILEIO packets against `/CFIDE/main/ide.cfm?ACTION=FILEIO` for arbitrary file read/write, and path-traversal in the CKEditor file-manager upload endpoint) illustrates the class of post-exploitation behavior — arbitrary file write to drop a CFML web shell, executing with NT AUTHORITY\SYSTEM privileges — that the same underlying platform has already suffered, and represents the realistic worst case for this new, not-yet-exploited CVE bundle should a public PoC emerge.
Adobe formalized a twice-monthly security-bulletin cadence effective 2026-07-14, and continues to ship an Isolated Patch mechanism for Commerce/Magento merchants to apply fixes with reduced integration risk. Defenders running any of the three affected products should treat immediate patching as the priority given the Priority 1 rating, even absent confirmed exploitation, because Adobe's own track record this year shows the gap between disclosure and active exploitation of its ColdFusion/Campaign Classic products has been measured in single-digit days.
Weaknesses (CWE)
CWE-78, CWE-95, CWE-863, CWE-89, CWE-79, CWE-122, CWE-321, CWE-327, CWE-20
Target sectors: government administration, finance, health, retail, technology, education
Target regions: Global
Timeline
- CISA advisory AA23-339A documents threat actors exploiting CVE-2023-26360 to breach at least two US federal agency ColdFusion servers, dropping web shells via HTTP POST for initial access and lateral movement.
- Sophos reports a LockBit-derivative ransomware payload being deployed against outdated, unpatched Adobe ColdFusion servers.
- Adobe releases APSB26-68 for ColdFusion, fixing seven CVSS 10.0 RDS/CKEditor RCE flaws including CVE-2026-48282.
- SecurityWeek, BleepingComputer, and The Hacker News report on the APSB26-68/APSB26-69 maximum-severity ColdFusion and Campaign Classic bulletins (Priority 1, CVE-2026-48286 CVSS 10.0 in Campaign Classic).
- Horizon3.ai's NodeZero autonomous penetration-testing platform independently exploits sibling flaw CVE-2026-48283 via the CKEditor filemanager upload.cfm endpoint, confirming full ColdFusion host compromise in 1 minute 27 seconds.
- watchTowr Labs publishes technical analysis of the ColdFusion RDS-abuse RCE (CVE-2026-48282); KEVIntel honeypot sensors record live exploitation attempts within roughly two hours of publication.
- CISA adds CVE-2026-48282 (ColdFusion RDS path traversal) to the Known Exploited Vulnerabilities catalog after confirming limited in-the-wild attacks; remediation due 2026-07-10.
- CISA-mandated federal remediation deadline for CVE-2026-48282 passes.
- Adobe formalizes a twice-monthly security-bulletin cadence and releases APSB26-73 (Commerce, Priority 2) and further ColdFusion fixes (APSB26-82).
- Adobe published APSB26-114 for Campaign Classic, fixing CVE-2026-48449 (Incorrect Authorization, CVSS 10.0) and CVE-2026-48448 (SQL Injection, CVSS 8.6); fix shipped as v7.4.3 build 9398 — the first of three critical ACC bulletins in an 11-day window culminating in APSB26-123.
- Adobe releases APSB26-120 for Campaign Classic, fixing three more CVSS 10.0 unauthenticated RCE flaws (CVE-2026-48331, CVE-2026-48323, CVE-2026-48330).
- Adobe's APSB26-120 bulletin was revised a day after publication; independent technical breakdowns of its seven CVEs were published around this time.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 34 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-48362, CVE-2026-48273, CVE-2026-71384, CVE-2026-71398, CVE-2026-27302, CVE-2026-48381, CVE-2026-71362, CVE-2026-71387, CVE-2026-71386, CVE-2026-48440, T1588.005, T1190, T1059, T1505.003, T1082, T1005, T1213, T1595.002, T1592.002, T1596.005