Back Heise.De Adobe Patch: Malicious code loopholes threaten Campaign Classic and ColdFusion
Adobe Campaign Classic, ColdFusion, Commerce, Content Credentials SDK and Lightroom Classic are vulnerable. In some cases, attackers can compromise entire PCs after executing malicious code. Security patches are available for download. Currently, there are no indications that attackers are already exploiting the security vulnerabilities. Nevertheless, admins should not delay installing the bug-fixed versions.
In ColdFusion , a vulnerability (CVE-2026-48362) and in Campaign Classic , two vulnerabilities (CVE-2026-71398, CVE-2026-27302) are classified with the threat level “ critical ” and the highest possible CVSS score of 10 out of 10. In all cases, malicious code can get onto systems. Therefore, admins should promptly install the secured versions ColdFusion 2023 2023.0.23, ColdFusion 2025 2025.0.12 and Campaign Classic ACC v7 7.4.4 build 9400 .
Vulnerabilities in Lightroom Classic can also allow malicious code to slip onto systems (e.g., CVE-2026-48441 “ high ”). Lightroom Classic 15.5 provides a remedy.
Content Credentials SDK can serve as a starting point for DoS attacks, among others (CVE-2026-48439 “ high ”). How attackers can specifically exploit the described security vulnerabilities is not clear from the brief descriptions of the software vulnerabilities.
Adobe Campaign Classic was recently patched . Since July of this year, the software manufacturer has been releasing security updates twice a month instead of once.
This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
