🔴 Critical  |  Source: The Hacker News


Adobe has released emergency patches for three CVSS 10.0 vulnerabilities across ColdFusion, Commerce, and Campaign Classic. The most critical flaw (CVE-2026-48362) is an OS command injection vulnerability in ColdFusion that could allow a remote attacker to execute arbitrary commands on the underlying system. These are the highest possible severity ratings and represent serious risk to any organisation running affected Adobe products.

Security Architect’s Take: Prioritise patching ColdFusion instances immediately, particularly any internet-facing deployments — CVSS 10.0 OS command injection flaws are frequently weaponised within days of disclosure. If ColdFusion or Campaign Classic runs in your cloud environment, verify patch status now and consider temporarily restricting public access or placing a WAF rule in front of affected services until patching is confirmed.

Original advisory: Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws