Adobe’s August security batch patches three CVSS 10.0 vulnerabilities, spread across ColdFusion and Campaign Classic, and the company is urging fast action. The release carries a Priority 1 rating, which Adobe reserves for bugs with a higher likelihood of being targeted.
Administrators should plan to install within 72 hours, though Adobe says there is no evidence any of these flaws has been exploited in the wild yet.
On the ColdFusion side, CVE-2026-48362 (CVSS 10.0) is an operating system command injection issue that could yield arbitrary code execution. Fixes land in versions 2025.0.12 and 2023.0.23. A second ColdFusion bug, CVE-2026-48273 (CVSS 9.9), is an eval injection flaw with the same consequence, joined by CVE-2026-71384 (CVSS 9.6), an incorrect authorization issue enabling denial of service.
Campaign Classic carries the other two maximum-severity entries. CVE-2026-71398 and CVE-2026-27302, both rated CVSS 10.0, come from incorrect authorization checks that could allow arbitrary code execution. The fix ships in ACC v7 7.4.4 build 9400. Adobe also patched a CVSS 9.0 SQL injection in Campaign Classic and a CVSS 9.1 privilege escalation in Commerce.
Who needs to act? Teams running fully on-premise builds, or the on-premise side of a hybrid, must apply the Campaign Classic patch. Everyone on Adobe-hosted instances is already covered.
This batch lands under two weeks after Adobe’s earlier maximum-severity Campaign Classic fix, CVE-2026-48449, which also rated 10.0.
