Adobe patched a critical flaw in Campaign Classic, its enterprise marketing automation platform, that can let an attacker run code without any user interaction. Tracked as CVE-2026-48449 and scored 10.0, it is an incorrect authorization issue leading to arbitrary code execution in the context of the current user. The same update fixes a high-severity SQL injection flaw that allows arbitrary file reads. Affected versions are Campaign Classic v7 build 9397 and earlier on Windows and Linux, mostly on-premises and hybrid deployments, with a fix in build 9398. Adobe says it is not aware of exploitation, and separately patched eight critical flaws in Adobe Bridge.
One of the critical ColdFusion vulnerabilities Adobe patched last week is now being exploited in the wild. The flaw, CVE-2026-48282, is a path-traversal issue rated 10.0 that lets an attacker run arbitrary code on a ColdFusion server, and it was among seven top-severity bugs Adobe fixed in ColdFusion 2025 and 2023. Adobe had flagged the update as high priority given ColdFusion's history as an attacker and ransomware target, and exploitation has followed quickly. Organizations that had not yet applied the update are now in an active-threat window, especially any ColdFusion servers reachable from the internet, which are the most exposed to opportunistic attacks.
Adobe has released patches for seven critical, top-rated code execution vulnerabilities in its ColdFusion web application platform and Campaign Classic marketing tool. Six of the flaws affect ColdFusion 2025 and 2023 and stem from unrestricted file uploads, improper input validation, and path traversal, each allowing arbitrary code execution; the seventh, in Campaign Classic, is an authorization flaw with the same impact on on-premises installations. All can be exploited in low-complexity attacks without user interaction. Adobe says it is not aware of any active exploitation but assigned its highest deployment priority, urging admins to patch quickly, since ColdFusion has repeatedly been targeted by attackers and ransomware crews.