2026-08-28 · view entry permalink →
Adobe August 2026 Patch Day: ColdFusion ships a CVSS 10.0 unauthenticated OS command injection, and Campaign Classic ships two more unauthenticated CVSS 10.0 flaws in the same release
Adobe's 2026-08-11 Security Patch Day carries two bulletins whose headline flaws are unauthenticated, no-interaction paths to arbitrary code execution at CVSS 10.0. APSB26-90 fixes 16 CVEs in ColdFusion 2025 (≤2025.0.11) and 2023 (≤2023.0.22), led by CVE-2026-48362 (CWE-78, OS command injection, CVSS 10.0, AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) — unauthenticated arbitrary code execution — and CVE-2026-48273 (CWE-95, eval injection, 9.9, AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H), which needs low-privileged access rather than none (Adobe, APSB26-90, 2026-08-11). The remaining fourteen span incorrect-authorization application denial-of-service (CVE-2026-71384, 9.6), cross-site scripting escalating to code execution (CVE-2026-71386, 8.8), privilege escalation via input validation (CVE-2026-21273, 8.7), further authorization and hard-coded-key defects down to CVSS 4.9, and a heap-based buffer overflow (CVE-2026-48440, 8.1). Adobe states it is "not aware of any exploits in the wild for any of the issues addressed in this update," and separately recommends keeping the underlying JDK/JRE current and reviewing its serialFilter guidance for insecure deserialization (Adobe, APSB26-90, 2026-08-11).
APSB26-123 covers Adobe Campaign Classic — explicitly scoped to on-premise deployments and the on-premise leg of hybrid deployments, since "Adobe-hosted instances have already been remediated and require no customer action" (Adobe, APSB26-123, 2026-08-11). Two of its three fixed CVEs are unauthenticated CVSS 10.0 incorrect-authorization flaws reaching arbitrary code execution — CVE-2026-71398 and CVE-2026-27302, the same vector under two identifiers — and the third, CVE-2026-48381 (CWE-89, SQL injection, 9.0, AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H), is unauthenticated with high attack complexity. All three are fixed in ACC v7 7.4.4 build 9400 for both Windows and Linux; the earlier 7.4.3 build 9399 and prior are affected. No exploitation is reported for either bulletin, and neither Adobe advisory names a researcher, which is consistent with an internally-found batch.
Detection, in vendor-neutral terms: ColdFusion's command-injection path and Campaign Classic's authorization flaws both reach the underlying host or database with no prior authentication, so the durable telemetry is process-lineage and query-shape anomalies rather than an authentication event — a ColdFusion application-server process spawning an OS shell or interpreter with no corresponding administrative session, and Campaign Classic database queries or file operations issued outside the product's own scheduled and interactive-session patterns. Because no public proof-of-concept or exploitation report exists yet for either bulletin, the defensible position is to treat the patch window itself as the exposure window and close it before a diff-derived exploit appears, rather than waiting for confirmed activity.
Adobe has released a security update for ColdFusion versions 2025 and 2023. This update resolves critical and important vulnerabilities that could result in arbitrary code execution, privilege escalation, security feature bypass, application denial-of-service, and memory exposure.
Adobe is not aware of any exploits in the wild for any of the issues addressed in this update.
This security bulletin applies only to fully on-premise deployments of Adobe Campaign Classic and to the on-premise components of hybrid deployments. Adobe-hosted instances have already been remediated and require no customer action.