Adobe released security updates for ColdFusion and Adobe Campaign Classic to fix seven maximum-severity vulnerabilities that could let attackers run code on affected servers. The ColdFusion issues include CVE-2026-48276, CVE-2026-48277, CVE-2026-48281, CVE-2026-48316, and CVE-2026-48282, affecting versions 2025.9, 2023.20, and earlier; Adobe says they can be exploited by unauthenticated attackers in low-complexity attacks. CVE-2026-48286 affects on-premises Campaign Classic 7.4.3 build 9396 and earlier; Adobe says hosted instances were already patched.
Ionut Arghire
2026.07.14
93% relevant
This is a direct follow-on Adobe security release affecting the same vendor and product line, adding a new batch of ColdFusion flaws two weeks later: 13 more ColdFusion issues, including eight critical bugs (CVE-2026-48318, CVE-2026-48322, CVE-2026-48284, CVE-2026-48321, CVE-2026-48325, CVE-2026-48319, CVE-2026-48324, CVE-2026-48327) fixed in ColdFusion 2025 Update 11 and 2023 Update 22.
Sergiu Gatlan
2026.07.06
97% relevant
This updates the same Adobe ColdFusion patch cycle by adding the key new development that one of the patched flaws, CVE-2026-48282, is now being actively exploited in the wild according to CCCS.
info@thehackernews.com (The Hacker News)
2026.07.01
99% relevant
This is the same Adobe July 2026 security update event covering seven CVSS 10.0 vulnerabilities in ColdFusion and Campaign Classic, adding another report of the vendor advisory and patch details.
Ionut Arghire
2026.07.01
99% relevant
This article is a direct report on the same Adobe July 2026 security release, adding the specific CVE list, affected versions and builds, vulnerability classes, and Adobe's note that no public exploitation is known yet but the updates carry priority 1.
Sergiu Gatlan
2026.07.01
100% relevant
This article establishes a new patching event centered on Adobe's July 2026 security updates for ColdFusion and Campaign Classic, with specific CVEs, affected versions, and deployment scope.