2026-07-02HIGHexploitedCVE-2026-48276, -48277, -48281, -48282, -48283, -48316, Adobe ColdFusion: six CVSS 10.0 unauthenticated RCE paths
Adobe ColdFusion/Campaign APSB26-68/69
trend · trend:adobe-coldfusion-campaign-apsb26-68-69
Seven CVSS 10.0 RCE flaws across Adobe ColdFusion and Campaign Classic (APSB26-68/69).
Coverage
2
first 2026-07-02 → last 2026-08-07
Latest activity
2026-08-07
Adobe ships a second Campaign Classic emergency fix in five days; build 9398 was the patch, and build 9398 is…
Peak priority
high
2 high
Targets
public-sector
sectors: public-sector, finance, telco · regions: europe
Sources cited
9
4 hosts
Action items (3)
Do-now tasks recorded on the entries about Adobe ColdFusion/Campaign APSB26-68/69, newest first. Check the date before acting on an older one.
- Upgrade on-premise Adobe Campaign Classic to ACC v7 7.4.3 build 9399, build 9398, applied as the fix for APSB26-114 on 2026-07-29, is inside the affected range for all seven of these flaws.2026-08-07CVE-2026-48331 +6
- Confirm every internet-facing ColdFusion 2025/2023 instance is on 2025 Update 10 / 2023 Update 21; treat any unpatched instance as compromised and hunt before patching.2026-07-02CVE-2026-48276 +5
- Review ColdFusion upload/writable paths (cf_scripts, CFIDE, admin upload directories) for newly written .jsp/.cfm/.cfc files outside deployment windows.2026-07-02CVE-2026-48276 +5
Defender insights
What each entry about Adobe ColdFusion/Campaign APSB26-68/69 tells a defender to do, newest first.
Story timeline
- 2026-08-07Adobe Campaign Classic APSB26-120, three more unauthenticated CVSS 10.0 code-execution flaws, and last week's build 9398 is the version they affect
- 2026-07-02CVE-2026-48276, -48277, -48281, -48282, -48283, -48316, Adobe ColdFusion: six CVSS 10.0 unauthenticated RCE paths
Hunting pivots
CVEs (exploited first)
Affected products
ATT&CK techniques (2 across 2 tactics)
2 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
- ExecutionCommand and Scripting Interpreter
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-08-07/adobe-campaign-classic-apsb26-120-second-wave-unauth-rce · ATT&CK page ↗
Execution TA0002
T1059Command and Scripting Interpreter×1
Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell.
Evidence: 2026-08-07/adobe-campaign-classic-apsb26-120-second-wave-unauth-rce · ATT&CK page ↗
Entries about Adobe ColdFusion/Campaign APSB26-68/69 (2)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Adobe Campaign Classic×1
- Adobe Campaign Classic (on-premise), authenticated eval injection (CWE-95) reaching arbitrary code execution, CVSS 9.6; APSB26-120, fixed in ACC v7 7.4.3 build 9399×1
- Adobe Campaign Classic (on-premise), authenticated SQL injection (CWE-89) reaching arbitrary code execution, CVSS 9.9; APSB26-120, fixed in ACC v7 7.4.3 build 9399×1
- Adobe Campaign Classic (on-premise), unauthenticated incorrect authorization (CWE-863) giving privilege escalation, CVSS 9.8; APSB26-120, fixed in ACC v7 7.4.3 build 9399×1
- Adobe Campaign Classic (on-premise), unauthenticated SQL injection (CWE-89) reaching arbitrary code execution, CVSS 10.0, scope changed; APSB26-120, fixed in ACC v7 7.4.3 build 9399×1
- Adobe Campaign Classic (on-premise), unauthenticated SSRF (CWE-918) reaching arbitrary code execution, CVSS 10.0, scope changed; APSB26-120, fixed in ACC v7 7.4.3 build 9399×1
- Adobe Campaign Classic (on-premise), unauthenticated template-engine injection (CWE-1336) reaching arbitrary code execution, CVSS 10.0, scope changed; APSB26-120, fixed in ACC v7 7.4.3 build 9399×1
- Adobe Campaign Classic (on-premise), violation of secure design principles (CWE-657) giving a security-feature bypass, CVSS 7.5; APSB26-120, fixed in ACC v7 7.4.3 build 9399×1
Where this entity is cited
Source distribution
- helpx.adobe.com4 (44%)
- bleepingcomputer.com3 (33%)
- advisories.ncsc.nl1 (11%)
- cisa.gov1 (11%)
All cited sources (9)
- advisories.ncsc.nlNCSC-NLhttps://advisories.ncsc.nl/2026/ncsc-2026-0278.html
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/adobe-patches-seven-max-severity-coldfusion-campaign-flaws/
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-max-severity-coldfusion-flaw-by-friday/
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/max-severity-adobe-coldfusion-flaw-now-exploited-in-attacks/
- cisa.govCISA Known Exploited Vulnerabilities Cataloghttps://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
- helpx.adobe.comAdobe PSIRT (APSB26-114)https://helpx.adobe.com/security/products/campaign/apsb26-114.html
- helpx.adobe.comAdobe PSIRThttps://helpx.adobe.com/security/products/campaign/apsb26-120.html
- helpx.adobe.comAdobe PSIRT APSB26-69https://helpx.adobe.com/security/products/campaign/apsb26-69.html
- helpx.adobe.comAdobe PSIRT APSB26-68https://helpx.adobe.com/security/products/coldfusion/apsb26-68.html