Adobe patches twelve vulnerabilities in ColdFusion and Campaign Classic
Adobe has issued security updates for ColdFusion and Adobe Campaign Classic covering twelve CVEs in total. The ColdFusion update fixes eleven critical and important flaws in ColdFusion 2025 Update 9 and earlier and ColdFusion 2023 Update 20 and earlier, allowing arbitrary code execution, privilege escalation, arbitrary file system read or security feature bypass. Adobe Campaign Classic ACC v7 7.4.3 build 9396 and earlier carries a critical incorrect authorisation flaw, CVE-2026-48286, that could allow arbitrary code execution. The advisory applies to on-premises deployments and on-premises components in hybrid deployments, while Adobe-hosted instances have already been remediated.
What this means for your organisation
None of the flaws are known to be exploited yet, but several carry a high CVSS score, and ColdFusion has historically been an early target once fixes go public. Responsibility for patching rests with whoever runs the software, and on-premises ColdFusion servers are exactly the kind of asset with unclear ownership in many organisations. Campaign Classic additionally handles customer data, with the privacy consequences that follow from a compromise.
Berigo recommends
- Patch on-premises ColdFusion and Campaign Classic installations now, without waiting for exploitation to be observed.
- Establish who owns each installation, including those inherited from earlier projects or suppliers.
- Check which installations are reachable from the Internet and restrict access where possible.
- Assess the privacy implications of the customer data held in Campaign Classic and document the assessment.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch