Breaking
SecurityDeveloping Story

Adobe's 50-Flaw Patch Drop Puts Critical Fixes First

Adobe's latest security update addresses over 50 vulnerabilities, with critical fixes for ColdFusion and Campaign Classic rated as top priority.

··3 hours ago·2 min read
monitor showing dialog boxes
Photo by Skye Studios on Unsplash

Adobe's Tuesday security update is a large one, addressing more than 50 vulnerabilities across its product line. The company is urging users to prioritize patching critical flaws in ColdFusion and Campaign Classic, which have been given the highest urgency rating due to the risk of exploitation.

Priority 1 for ColdFusion

The ColdFusion update, tagged with a priority 1 rating, resolves 15 security defects. Three of these are classified as critical and could lead to arbitrary code execution and application denial-of-service (DoS).

Among the most severe is an OS command injection vulnerability tracked as CVE-2026-48362, which carries a CVSS score of 10/10. Another critical flaw, CVE-2026-48273, is an eval injection issue with a CVSS score of 9.9/10. A third flaw, CVE-2026-71384, involves incorrect authorization and has a CVSS score of 9.6/10.

Campaign Classic Also Critical

The update for Campaign Classic also receives a priority 1 rating. It addresses three critical vulnerabilities that could lead to arbitrary code execution. Two are incorrect authorization issues: CVE-2026-71398 and CVE-2026-27302, both with CVSS scores of 10/10. The third is an SQL injection bug, CVE-2026-48381, with a CVSS score of 9.0/10.

Adobe's priority rating system indicates that these vulnerabilities are at higher risk of being targeted in the wild. The company advises users to apply the patches for both products immediately.

Commerce Patched with Priority 2

Adobe also resolved seven vulnerabilities in Commerce, including CVE-2026-71362, an incorrect authorization issue that could lead to privilege escalation. This flaw has a CVSS score of 9.1/10. The update also addresses high-severity code execution and security feature bypass bugs.

The Commerce update has a priority 2 rating because the product has been targeted in attacks previously. Adobe recommends users apply this update within the next 30 days.

Lightroom and Content Credentials

On the same day, Adobe rolled out patches for 11 high-severity defects in Lightroom and 15 high- and medium-severity bugs in Content Credentials. Both updates have a priority 3 rating.

According to Adobe, it is not aware of any exploits in the wild for the newly addressed vulnerabilities. More details are available on Adobe's security updates page.

Why This Matters

The sheer number of vulnerabilities patched, combined with the maximum severity scores for some flaws, suggests that organizations running these products face significant risk if they delay updates. The priority 1 rating for ColdFusion and Campaign Classic indicates that Adobe considers these the most likely to be weaponized, so immediate action is critical. For businesses relying on these platforms, the window for patching is narrow, and failure to act promptly could expose them to serious attacks.

#adobe#coldfusion#campaign classic#commerce#critical vulnerabilities#patching

Sources

Iliyas

Editor, Xploitwire

This article was researched and drafted through our automated editorial pipeline from the sources listed above, then checked against those sources through our automated fact-check process, under the editorial policies set by Iliyas. Our Automation Policy →

← Back to all stories