Adobe's 50-Flaw Patch Drop Puts Critical Fixes First
Adobe's latest security update addresses over 50 vulnerabilities, with critical fixes for ColdFusion and Campaign Classic rated as top priority.
Adobe's Tuesday security update is a large one, addressing more than 50 vulnerabilities across its product line. The company is urging users to prioritize patching critical flaws in ColdFusion and Campaign Classic, which have been given the highest urgency rating due to the risk of exploitation.
Priority 1 for ColdFusion
The ColdFusion update, tagged with a priority 1 rating, resolves 15 security defects. Three of these are classified as critical and could lead to arbitrary code execution and application denial-of-service (DoS).
Among the most severe is an OS command injection vulnerability tracked as CVE-2026-48362, which carries a CVSS score of 10/10. Another critical flaw, CVE-2026-48273, is an eval injection issue with a CVSS score of 9.9/10. A third flaw, CVE-2026-71384, involves incorrect authorization and has a CVSS score of 9.6/10.
Campaign Classic Also Critical
The update for Campaign Classic also receives a priority 1 rating. It addresses three critical vulnerabilities that could lead to arbitrary code execution. Two are incorrect authorization issues: CVE-2026-71398 and CVE-2026-27302, both with CVSS scores of 10/10. The third is an SQL injection bug, CVE-2026-48381, with a CVSS score of 9.0/10.
Adobe's priority rating system indicates that these vulnerabilities are at higher risk of being targeted in the wild. The company advises users to apply the patches for both products immediately.
Commerce Patched with Priority 2
Adobe also resolved seven vulnerabilities in Commerce, including CVE-2026-71362, an incorrect authorization issue that could lead to privilege escalation. This flaw has a CVSS score of 9.1/10. The update also addresses high-severity code execution and security feature bypass bugs.
The Commerce update has a priority 2 rating because the product has been targeted in attacks previously. Adobe recommends users apply this update within the next 30 days.
Lightroom and Content Credentials
On the same day, Adobe rolled out patches for 11 high-severity defects in Lightroom and 15 high- and medium-severity bugs in Content Credentials. Both updates have a priority 3 rating.
According to Adobe, it is not aware of any exploits in the wild for the newly addressed vulnerabilities. More details are available on Adobe's security updates page.
Why This Matters
The sheer number of vulnerabilities patched, combined with the maximum severity scores for some flaws, suggests that organizations running these products face significant risk if they delay updates. The priority 1 rating for ColdFusion and Campaign Classic indicates that Adobe considers these the most likely to be weaponized, so immediate action is critical. For businesses relying on these platforms, the window for patching is narrow, and failure to act promptly could expose them to serious attacks.
Sources
- SecurityWeek Original source
- security updates Also reporting
Continue Reading
Cloudflare Vows Quantum-Proof TLS Shift
Cloudflare says it will issue post-quantum TLS certificates using Merkle Tree Certificates, targeting Q1 2027 after acquiring a GlobalSign root.
AI-Discovered Flaws Skew Toward RCE
Google's threat intelligence unit reports AI-found vulnerabilities are far more likely to enable remote code execution than other disclosed flaws.
Teen's Auth Flaw Opened Titan's Data Vault
A 16-year-old researcher bypassed Microsoft's Titan analytics by exploiting an unverified JWT and was paid a $5,000 bounty.