ON
← Back to feed
Patched by Adobe: Campaign Classic and ColdFusion are threatened by malware loopholes
Germany💻 Technology12 days ago

Patched by Adobe: Campaign Classic and ColdFusion are threatened by malware loopholes

Adobe has released security patches for several of its products, including Adobe Campaign Classic, ColdFusion, Commerce, Content Credentials SDK, and Lightroom Classic, addressing critical vulnerabilities that could allow attackers to execute malicious code on affected systems. The vulnerabilities include CVE-2026-48362 (ColdFusion), CVE-2026-71398 and CVE-2026-27302 (Campaign Classic), CVE-2026-71362 (Commerce/Magento), CVE-2026-48414 (Commerce/Magento), CVE-2026-48441 (Lightroom Classic), and CVE-2026-48439 (Content Credentials SDK). These flaws could enable attackers to gain elevated privileges, execute arbitrary code, or launch denial-of-service attacks. Adobe recommends administrators promptly install the updated versions to mitigate these risks. No evidence suggests that these vulnerabilities have been exploited yet.

Adobe has released critical security patches for several of its software products after discovering multiple vulnerabilities that could allow attackers to compromise systems. The affected products include Adobe Campaign Classic, ColdFusion, Commerce, Content Credentials SDK, and Lightroom Classic. Security researchers have identified high-risk flaws with potential for remote code execution, which could enable unauthorized access to systems. While there are currently no indications that these vulnerabilities have been exploited in the wild, administrators are strongly advised to apply the available updates immediately. The most severe vulnerabilities were found in ColdFusion, where a single flaw (CVE-2026-48362) was rated as critical with a CVSS score of 10 out of 10. This means the vulnerability allows attackers to execute arbitrary code on affected systems. Similarly, two critical flaws were discovered in Adobe Campaign Classic (CVE-2026-71398 and CVE-2026-27302), both with maximum scores. These vulnerabilities could lead to complete system compromise if exploited. To address these issues, Adobe recommends updating to ColdFusion 2023 version 2023.0.23, ColdFusion 2025 version 2025.0.12, and Campaign Classic ACC v7 version 7.4.4 build 9400. In addition to ColdFusion and Campaign Classic, other products such as Adobe Commerce (formerly Magento) and Lightroom Classic were also found to contain exploitable weaknesses. A critical vulnerability (CVE-2026-71362) in Commerce could allow attackers to gain elevated privileges, while another (CVE-2026-48414) enables direct execution of malicious code. These vulnerabilities pose a serious threat to organizations using these platforms. Adobe has issued updated versions to mitigate these risks, including Lightroom Classic 15.5, which addresses a high-severity flaw (CVE-2026-48441). The Content Credentials SDK was also found to contain a high-risk vulnerability (CVE-2026-48439), which could serve as a vector for denial-of-service attacks. However, detailed information on how attackers might exploit these specific flaws is limited, as the descriptions provided by Adobe remain brief. Despite this lack of specifics, the severity ratings suggest that these vulnerabilities should be treated with caution. This latest round of updates comes just weeks after Adobe announced changes to its update schedule, shifting from monthly releases to twice-monthly updates for some products. The change was made to improve response times to emerging threats. Adobe Campaign Classic, one of the more widely used products, had previously received updates less frequently, prompting concerns among users about the speed of patch deployment. The recent adjustments aim to better align with evolving cybersecurity challenges. Administrators are urged to prioritize applying the latest security patches to all affected systems. Given the potential for remote code execution and privilege escalation, delaying updates could expose networks to significant risk. While there is currently no evidence of active exploitation, the high severity of the disclosed vulnerabilities makes prompt action essential. Users should check Adobe’s official resources for detailed instructions on installing the updated versions of their software.

Go to the primary sources (5)

The official sources this coverage is built on. Read them directly to bypass framing.

1 reports

heise online logoheise onlineIndependentCenterFactual 85Objective 7512 days ago
Patched by Adobe: Campaign Classic and ColdFusion are threatened by malware loopholes

Adobe has released security patches for several of its products, including Adobe Campaign Classic, ColdFusion, Commerce, Content Credentials SDK, and Lightroom Classic, addressing critical vulnerabilities that could allow attackers to execute malicious code on affected systems. The vulnerabilities include CVE-2026-48362 (ColdFusion), CVE-2026-71398 and CVE-2026-27302 (Campaign Classic), CVE-2026-71362 (Commerce/Magento), CVE-2026-48414 (Commerce/Magento), CVE-2026-48441 (Lightroom Classic), and CVE-2026-48439 (Content Credentials SDK). These flaws could enable attackers to gain elevated privileges, execute arbitrary code, or launch denial-of-service attacks. Adobe recommends administrators promptly install the updated versions to mitigate these risks. No evidence suggests that these vulnerabilities have been exploited yet.

Bias read (Center): The article discusses technical vulnerabilities in software products and provides information about available security patches. It does not present any political opinions, biases, or framing that would indicate a leaning toward either side of a political spectrum. The content is purely informational

Why factuality (85): The article reports on multiple critical vulnerabilities in Adobe products including Campaign Classic, ColdFusion, Commerce, Content Credentials SDK, and Lightroom Classic. It cites specific CVE identifiers and provides details on the severity ratings (CVSS scores). The information aligns with typic

Why objectivity (75): The tone is informative and technical, focusing on the risks and recommended actions. While it presents the facts neutrally, there is a slight emphasis on urgency ('should not wait') which may lean towards promoting prompt action rather than purely objective reporting.

How each side covered it

The same event, grouped by the political lean of the outlets covering it.

How each side covered it

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Covered around the world

The same event as reported in other countries.

Covered around the world

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Claims check

Key factual claims, and how many sources assert vs dispute each.

Claims check

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Keep the news honest.

ObjectiveNews is reader-funded and ad-free — we show you the bias instead of hiding it. Support independent journalism for €4/month.

Become a Supporter

Related stories