Adobe's 50-Flaw Patch Drop Puts Critical Fixes First
Adobe's latest security update addresses over 50 vulnerabilities, with critical fixes for ColdFusion and Campaign Classic rated as top priority.
Adobe's Tuesday security update is a large one, addressing more than 50 vulnerabilities across its product line. The company is urging users to prioritize patching critical flaws in ColdFusion and Campaign Classic, which have been given the highest urgency rating due to the risk of exploitation.
Priority 1 for ColdFusion
The ColdFusion update, tagged with a priority 1 rating, resolves 15 security defects. Three of these are classified as critical and could lead to arbitrary code execution and application denial-of-service (DoS).
Among the most severe is an OS command injection vulnerability tracked as CVE-2026-48362, which carries a CVSS score of 10/10. Another critical flaw, CVE-2026-48273, is an eval injection issue with a CVSS score of 9.9/10. A third flaw, CVE-2026-71384, involves incorrect authorization and has a CVSS score of 9.6/10.
Campaign Classic Also Critical
The update for Campaign Classic also receives a priority 1 rating. It addresses three critical vulnerabilities that could lead to arbitrary code execution. Two are incorrect authorization issues: CVE-2026-71398 and CVE-2026-27302, both with CVSS scores of 10/10. The third is an SQL injection bug, CVE-2026-48381, with a CVSS score of 9.0/10.
Adobe's priority rating system indicates that these vulnerabilities are at higher risk of being targeted in the wild. The company advises users to apply the patches for both products immediately.
Commerce Patched with Priority 2
Adobe also resolved seven vulnerabilities in Commerce, including CVE-2026-71362, an incorrect authorization issue that could lead to privilege escalation. This flaw has a CVSS score of 9.1/10. The update also addresses high-severity code execution and security feature bypass bugs.
The Commerce update has a priority 2 rating because the product has been targeted in attacks previously. Adobe recommends users apply this update within the next 30 days.
Lightroom and Content Credentials
On the same day, Adobe rolled out patches for 11 high-severity defects in Lightroom and 15 high- and medium-severity bugs in Content Credentials. Both updates have a priority 3 rating.
According to Adobe, it is not aware of any exploits in the wild for the newly addressed vulnerabilities. More details are available on Adobe's security updates page.
Why This Matters
The sheer number of vulnerabilities patched, combined with the maximum severity scores for some flaws, suggests that organizations running these products face significant risk if they delay updates. The priority 1 rating for ColdFusion and Campaign Classic indicates that Adobe considers these the most likely to be weaponized, so immediate action is critical. For businesses relying on these platforms, the window for patching is narrow, and failure to act promptly could expose them to serious attacks.
Sources
- SecurityWeek Original source
- security updates Also reporting
Continue Reading
Zero-Day in Windows Winsock Kernel Driver Exploited in Attacks
Microsoft's August Patch Tuesday fixes 421 CVEs, including one exploited zero-day and two publicly disclosed flaws.
AI-Assisted SharePoint Exploit Reaches Unauthenticated RCE
Researchers chain AI-found flaws to gain admin on SharePoint servers, bypassing authentication entirely.
Malware Uses Ethereum Wallet as C2 Dead Drop
Sonatype finds six npm packages reading C2 addresses from an Ethereum wallet transaction linked to DPRK.