ctipilot.ch
← Back to the live brief
HIGHCVE-2026-48362 +5NATOA2vulnerability

Adobe August 2026 Patch Day: ColdFusion ships a CVSS 10.0 unauthenticated OS command injection, and Campaign Classic ships two more unauthenticated CVSS 10.0 flaws in the same release

first published 2026-08-28 05:15 UTCrun 2026-08-28T0409Z-intel2 sourcessingle-source

Adobe's 2026-08-11 Security Patch Day carries two bulletins whose headline flaws are unauthenticated, no-interaction paths to arbitrary code execution at CVSS 10.0. APSB26-90 fixes 16 CVEs in ColdFusion 2025 (≤2025.0.11) and 2023 (≤2023.0.22), led by CVE-2026-48362 (CWE-78, OS command injection, CVSS 10.0, AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) — unauthenticated arbitrary code execution — and CVE-2026-48273 (CWE-95, eval injection, 9.9, AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H), which needs low-privileged access rather than none (Adobe, APSB26-90, 2026-08-11). The remaining fourteen span incorrect-authorization application denial-of-service (CVE-2026-71384, 9.6), cross-site scripting escalating to code execution (CVE-2026-71386, 8.8), privilege escalation via input validation (CVE-2026-21273, 8.7), further authorization and hard-coded-key defects down to CVSS 4.9, and a heap-based buffer overflow (CVE-2026-48440, 8.1). Adobe states it is "not aware of any exploits in the wild for any of the issues addressed in this update," and separately recommends keeping the underlying JDK/JRE current and reviewing its serialFilter guidance for insecure deserialization (Adobe, APSB26-90, 2026-08-11).

APSB26-123 covers Adobe Campaign Classic — explicitly scoped to on-premise deployments and the on-premise leg of hybrid deployments, since "Adobe-hosted instances have already been remediated and require no customer action" (Adobe, APSB26-123, 2026-08-11). Two of its three fixed CVEs are unauthenticated CVSS 10.0 incorrect-authorization flaws reaching arbitrary code execution — CVE-2026-71398 and CVE-2026-27302, the same vector under two identifiers — and the third, CVE-2026-48381 (CWE-89, SQL injection, 9.0, AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H), is unauthenticated with high attack complexity. All three are fixed in ACC v7 7.4.4 build 9400 for both Windows and Linux; the earlier 7.4.3 build 9399 and prior are affected. No exploitation is reported for either bulletin, and neither Adobe advisory names a researcher, which is consistent with an internally-found batch.

Detection, in vendor-neutral terms: ColdFusion's command-injection path and Campaign Classic's authorization flaws both reach the underlying host or database with no prior authentication, so the durable telemetry is process-lineage and query-shape anomalies rather than an authentication event — a ColdFusion application-server process spawning an OS shell or interpreter with no corresponding administrative session, and Campaign Classic database queries or file operations issued outside the product's own scheduled and interactive-session patterns. Because no public proof-of-concept or exploitation report exists yet for either bulletin, the defensible position is to treat the patch window itself as the exposure window and close it before a diff-derived exploit appears, rather than waiting for confirmed activity.

Adobe has released a security update for ColdFusion versions 2025 and 2023. This update resolves critical and important vulnerabilities that could result in arbitrary code execution, privilege escalation, security feature bypass, application denial-of-service, and memory exposure.

Adobe is not aware of any exploits in the wild for any of the issues addressed in this update.

Adobe (APSB26-90) 2026-08-11

This security bulletin applies only to fully on-premise deployments of Adobe Campaign Classic and to the on-premise components of hybrid deployments. Adobe-hosted instances have already been remediated and require no customer action.

Adobe (APSB26-123) 2026-08-11

Defender actions

  • Patch internet-facing ColdFusion 2025/2023 instances to 2025.0.12 / 2023.0.23 now — CVE-2026-48362 is an unauthenticated OS command injection at CVSS 10.0, the class of flaw that gets weaponised within days of a patch diff being published, and Adobe reports no exploitation yet, which is the window to close before one exists.
  • For any on-premise or hybrid Adobe Campaign Classic ACC v7 deployment, upgrade to 7.4.4 build 9400 now — two of the three fixed flaws (CVE-2026-71398, CVE-2026-27302) are unauthenticated CVSS 10.0 code-execution paths; Adobe-hosted instances are already remediated and need no action.

ATT&CK mapping

1 technique mapped from the cited reporting · MITRE ATT&CK v19.2

Initial Access TA0001
T1190Exploit Public-Facing Application

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

overlap matrix · ATT&CK page ↗

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.