AI Weekly Malaysia

Back to items Summaries

Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

ID
13466
Status
summarized
Published
12 Aug 2026, 7:13 PM
Fetched
12 Aug 2026, 9:33 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/08/adobe-patches-three-cvss-100-coldfusion.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
4.5
Created
12 Aug 2026, 9:35 PM
Tags
Audience
developers

What happened

Adobe patched three CVSS 10.0 vulnerabilities across ColdFusion and Campaign Classic, including OS command injection (CVE-2026-48362) and eval injection (CVE-2026-48273) in ColdFusion, plus incorrect authorization flaws in Campaign Classic (CVE-2026-71398, CVE-2026-27302). ColdFusion fixes are in versions 2025.0.12 and 2023.0.23; Campaign Classic fixes require ACC v7 7.4.4 build 9400 for on-premise deployments only. Adobe rated these Priority 1 and recommends patching within 72 hours.

Why it matters

If you maintain or inherit ColdFusion or on-premise Campaign Classic instances—common in legacy Malaysian enterprise, GLC, and some government digital service stacks—these are remotely exploitable arbitrary code execution bugs with no current wild exploitation, meaning patching now is cheap insurance before attackers reverse-engineer the fixes. Adobe-hosted Campaign instances are already patched, so only on-premise and hybrid deployments need action.

Discussion angle

ColdFusion is legacy but still powers real production systems in Malaysian enterprise and public sector—ask who in the community still touches it and whether these CVSS 10.0 patches will actually get applied within 72 hours or sit in a backlog.

Top