VORANT. Threat Intelligence Sign in Get the full feed

Adobe Patches ColdFusion, Campaign Classic Flaws

medium vulnerability government-national

Adobe ColdFusion and Campaign Classic contain multiple vulnerabilities, including ones enabling arbitrary code execution, with no known exploitation yet.

CIS/MS-ISAC issued an advisory covering multiple vulnerabilities in Adobe Campaign Classic and Adobe ColdFusion. The most severe flaws could allow arbitrary code execution in the context of the logged-on user, potentially enabling installation of programs, data manipulation, or creation of new accounts, with impact scaling based on the victim's account privileges.

Affected products include Adobe Campaign Classic ACC v7 (7.4.3 build 9396 and earlier), ColdFusion 2025 (Update 9 and earlier), and ColdFusion 2023 (Update 20 and earlier). The vulnerabilities span incorrect authorization, unrestricted file upload, improper input validation, path traversal, reflected XSS, and SSRF. There are currently no reports of in-the-wild exploitation. Organizations are advised to apply Adobe's stable channel updates promptly and implement standard mitigations such as least privilege, application allowlisting, and vulnerability management processes.

Mentioned in this report

Vulnerabilities CVE-2026-48276CVE-2026-48277CVE-2026-48281CVE-2026-48282KEVCVE-2026-48283CVE-2026-48285CVE-2026-48286CVE-2026-48307CVE-2026-48313templatedCVE-2026-48314CVE-2026-48315CVE-2026-48316

Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-adobe-products-could-allow-for-arbitrary-code-execution_2026-066

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free