adobe just patched THREE perfect 10/10 security bugs on the same day — and that many at once isn't normal

CVE-2026-48362, CVE-2026-71398 and CVE-2026-27302 all score a maximum 10.0 — unauthenticated, no clicks needed, full remote takeover. Here's exactly…

Aliteq
Priya Nair · Software & Systems Editor

Three vulnerabilities score a maximum CVSS 10.0: CVE-2026-48362 (ColdFusion OS command injection) and CVE-2026-71398 plus CVE-2026-27302 (both Campaign Classic, incorrect authorization → full remote…

ColdFusion 2025 through 2025.0.11 and 2023 through 2023.0.22 are affected; the fix ships in 2025.0.12 and 2023.0.23.

On-premise Campaign Classic installs need ACC v7 build 9400 — Adobe-hosted instances were already patched server-side.

Adobe rates all six flaws Priority 1 and recommends patching within 72 hours, though there's no confirmed exploitation of these three specific bugs yet.

A separate, already-exploited Adobe Commerce flaw shipped the same day — don't mistake fixing one Adobe product for covering the other.

Patch priority

Treat this as an emergency patch, not a routine one. Any internet-exposed ColdFusion or on-prem Campaign Classic server should be updated within the next 72 hours regardless of whether you've seen…

Aliteq

Read the full story

adobe just patched THREE perfect 10/10 security bugs on the same day — and that many at once isn't normal

Read the full story on Aliteq