HomeUpdatesAdobe: Urgent security updates for ColdFusion and Campaign Classic

Adobe: Urgent security updates for ColdFusion and Campaign Classic

Adobe has released new security updates for two of its most important business platforms, ColdFusion and Campaign Classic , fixing a total of seven maximum severity vulnerabilities that could be exploited by cybercriminals to compromise corporate systems.

Adobe ColdFusion and Campaign Classic

The vulnerabilities have been rated Priority 1, the highest severity rating Adobe uses, meaning they are considered a potential target for immediate exploitation. Most worryingly, the attacks can be carried out without any user interaction and with relatively low complexity, significantly increasing the risk for organizations that have not installed the latest patches.

Adobe asks for patches to be installed within 72 hours

In the relevant announcement , Adobe urges system administrators to proceed with the installation of the updates as soon as possible, ideally within the next 72 hours.

See also: Citrix NetScaler: 6 vulnerabilities allow file read and DoS

As the company points out, these fixes concern vulnerabilities that are either already a potential target for exploit tools or have a particularly high probability of being exploited soon by attackers.

Although Adobe states that it has not identified any active attacks exploiting these vulnerabilities, experience shows that cybercriminals are usually very quick to analyze patches to develop exploits for systems that remain unpatched.

ColdFusion is back in the spotlight

Six of the seven vulnerabilities concern Adobe ColdFusion, one of the most popular web application development platforms widely used by businesses and government organizations. The vulnerabilities affect versions 2025.9, 2023.20 and earlier, and could lead to Remote Code Execution (RCE). In other words, a remote attacker without special privileges could execute arbitrary code on the server, essentially gaining complete control of the system.

Adobe: Urgent security updates for ColdFusion and Campaign Classic

The ability to execute remote code is considered one of the most dangerous categories of vulnerabilities, as it is often the first step to installing ransomware, stealing data, or moving laterally within corporate networks.

Vulnerability also in Adobe Campaign Classic

A security update has also been released for Adobe Campaign Classic, the platform used by many businesses to manage marketing campaigns and communicate with customers.

The vulnerability, CVE-2026-48286, affects versions up to 7.4.3 build 9396 and could allow arbitrary code execution in the context of the user running the application. Adobe clarifies that this issue only affects on-premises, as Adobe-hosted versions have already been updated and are not affected.

For many large enterprises that still maintain their applications on proprietary infrastructure, immediate installation of the update is considered absolutely essential.

Why business applications are now a key target

Attacks on enterprise applications have increased significantly in recent years. Instead of targeting individual users' computers, cybercriminals are now focusing on application servers and enterprise platforms, where a single successful breach can provide access to thousands of files, databases, and critical services.

See also: Langflow RCE exploit for Monero Miner development

ColdFusion is a prime example. Because it is used to develop and host enterprise applications, a vulnerable server can act as an entry point into an organization's entire infrastructure.

For this reason, security administrators are now placing particular emphasis on rapid patching, as the time between the publication of a vulnerability and the first attack is constantly decreasing.

New update policy from Adobe

Along with the new fixes, Adobe announced significant changes to its security bulletin distribution process.

The company's Chief Security Officer, Aanchal Gupta, announced that starting July 14, 2026, Adobe will be abandoning its monthly update cycle and adopting a new twice-monthly. The change is intended to reduce the time it takes for a vulnerability to be discovered and a corresponding fix to be released.

Adobe: Urgent security updates for ColdFusion and Campaign Classic

However, in cases of particularly serious zero-day attacks or when active vulnerability exploitation is identified, the company clarifies that it will continue to release emergency updates outside of the predetermined schedule.

Attacks on Adobe applications continue

Adobe's decision comes at a time when its products are frequently targeted by cybercriminals. Just a few months ago, the company released an emergency update for a zero-day vulnerability in Acrobat Reader, which was actively exploited in real-world attacks as early as December 2025.

See also: SimpleHelp Vulnerability: TaskWeaver and Djinn Stealer Attacks

At the same time, data from the American organization CISA reflects the seriousness of the situation. In the last five years 79 vulnerabilities in Adobe products to the list of Known Exploited Vulnerabilities, that is, security gaps that have been used in real cyberattacks. Of these, at least ten have been exploited by ransomware groups, confirming that Adobe platforms have long been one of the most important targets for attackers.

For organizations using ColdFusion or Campaign Classic, the message is clear: promptly installing the latest updates is no longer just a good practice, but a critical measure of protection against an ever-evolving threat.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS