Adobe released security updates for Adobe ColdFusion and Adobe Campaign Classic to fix multiple vulnerabilities that could let attackers bypass security controls, manipulate files, gain elevated privileges, or execute arbitrary commands. The most severe issue, CVE-2026-48276, is an unrestricted file upload flaw in ColdFusion with a CVSS 10.0 rating that can lead to remote code execution, while CVE-2026-48315 is an improper input validation bug rated CVSS 9.3 that can enable privilege escalation.
CISA later added the ColdFusion flaw to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild and elevating the issue to an urgent remediation priority for organizations running internet-facing ColdFusion servers. Reporting on the KEV update said the vulnerability can contribute to full server compromise, and urged defenders to patch affected systems quickly, investigate for signs of compromise, and prioritize exposed web applications and related enterprise platforms over CVSS-only risk scoring.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
Adobe released patches on August 11, 2026 for more than 50 vulnerabilities across multiple products, including priority 1 updates for ColdFusion and Campaign Classic. The ColdFusion fixes included critical flaws such as CVE-2026-48362, while Campaign Classic received fixes for three critical arbitrary code execution-related vulnerabilities; Adobe said it was not aware of in-the-wild exploitation.
CISA expanded its Known Exploited Vulnerabilities catalog to include an Adobe ColdFusion vulnerability among newly added flaws confirmed as exploited in the wild. The update elevated the issue as a high-priority remediation target for defenders.
Adobe released security updates for Adobe ColdFusion and Adobe Campaign Classic to remediate multiple vulnerabilities, including flaws that could allow unrestricted file upload, privilege escalation, file manipulation, and arbitrary command execution. The notice specifically highlighted CVE-2026-48276 in ColdFusion as a critical issue that could lead to remote code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
5 references tracked. Mallory keeps watching after this page renders.
securityweek.com
Open sourcethecyberthrone.in
Open sourceegfincirt-wpn.azurewebsites.net
Open sourceegfincirt.org.eg
Open sourcehelpx.adobe.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.