Adobe’s release of emergency security updates for ColdFusion and Campaign Classic highlights the risk posed by critical vulnerabilities in internet-facing application and marketing platforms.
Six ColdFusion vulnerabilities carry the maximum severity score and can allow unauthenticated attackers to execute arbitrary code through file uploads, input-validation weaknesses, and path-traversal flaws. A separate critical vulnerability in on-premises Adobe Campaign Classic can also lead to code execution without requiring user interaction.
Affected organizations should upgrade ColdFusion 2025 to Update 10, ColdFusion 2023 to Update 21, and on-premises Campaign Classic to build 9397 or later. Adobe-hosted Campaign environments have already been remediated.
Although Adobe has not reported active exploitation, the updates are classified as priority one because the vulnerabilities are considered at high risk of being targeted. Administrators should therefore patch within the recommended 72-hour period rather than waiting for exploitation to become tomorrow’s headline.
Internet access to administrative interfaces should be restricted, and organizations should review logs for unusual uploads, unexpected files, new processes, configuration changes, and outbound connections.
The key lesson is that application platforms capable of executing server-side code are highly attractive targets. A single unauthenticated flaw can turn a public-facing application server into an attacker-controlled entry point to the wider enterprise network.
Adobe has released security patches for seven maximum-severity vulnerabilities in the ColdFusion web app development platform and the Campaign Classic marketing automation platform. [...]
Source: Adobe patches seven max severity ColdFusion, Campaign flaws via Bleeping Computer — published 01 Jul 2026.
Was this article helpful?
Your feedback helps us improve the knowledge base.