Skip to content
Critical Vulnerabilities in Adobe Products Allow Arbitrary Code Execution

Critical Vulnerabilities in Adobe Products Allow Arbitrary Code Execution

First seen 12 Aug 2026, 13:08 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •August 13, 2026 at 12:50 UTC
  • •Adobe released critical patches for ColdFusion and Campaign Classic to address severe vulnerabilities.
  • •Multiple CVEs, including CVE-2026-48362 and CVE-2026-71398, allow arbitrary code execution.
  • •No active exploitation has been reported, but immediate patching is recommended for all users.

Adobe has issued urgent security updates for multiple products, including ColdFusion, Campaign Classic, and others, addressing critical vulnerabilities that could allow arbitrary code execution. The vulnerabilities, identified as CVE-2026-48362, CVE-2026-71398, CVE-2026-27302, and CVE-2026-48441, pose significant risks as they may enable attackers to execute malicious code on affected systems. Adobe has confirmed that there are currently no known exploits in the wild, but the potential impact is severe, especially for users with administrative privileges. The updates are available for ColdFusion 2023 and 2025, and Campaign Classic. Administrators are strongly advised to apply these patches immediately to mitigate risks. The vulnerabilities could lead to unauthorized access, data manipulation, and system compromise.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 53d ago How this analysis works

Timeline

2026-08-11
CVE-2026-48441 published
A high-severity vulnerability in Lightroom Classic allows malicious code execution.
Cisecurity
2026-08-11
CVE-2026-71398 published
A critical vulnerability in Campaign Classic could lead to arbitrary code execution.
Cisecurity
2026-08-11
CVE-2026-27302 published
Another critical vulnerability in Campaign Classic poses risks of code execution.
Cisecurity
2026-08-11
CVE-2026-48362 published
Critical vulnerability in ColdFusion could allow attackers to execute arbitrary code.
Cisecurity
2026-08-11
CVE-2026-48439 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-12
Adobe issues security updates
Adobe released security updates for ColdFusion and Campaign Classic to address critical vulnerabilities.
Helpx.Adobe

More articles in this cluster (10)

Following this threat?

Track CVE-2026-27302 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed