Critical Adobe Flaws: ColdFusion, Campaign Classic and Commerce Hit

Step by step
How the attack unfolded
Click a phase for details – or let the animation play through.
PHASE 1/5 · Initial Access

The attacker reaches the vulnerable Adobe application directly over the internet, without login or user interaction.

T1190 – Exploit Public-Facing Application
  • Attack vector AV:N/AC:L/PR:N/UI:N – network, low complexity, no privileges, no click
  • Affected: ColdFusion 2025 (≤2025.0.11) and 2023 (≤2023.0.22)
  • Campaign Classic v7 (≤7.4.3 Build 9399), on-premise/hybrid only
  • Adobe Commerce/Magento in versions before the August 2026 patch
PHASE 2/5 · Execution

Via OS command or code injection the attacker executes arbitrary commands at the operating system level.

T1059 – Command and Scripting Interpreter T1190 – Exploit Public-Facing Application
  • CVE-2026-48362 (ColdFusion): OS command injection, CVSS 10.0
  • CVE-2026-71398 & CVE-2026-27302 (Campaign Classic): arbitrary code execution, CVSS 10.0 each
  • CVE-2026-48273 (ColdFusion): eval injection, requires low privileges
  • CVE-2026-48381 (Campaign): SQL injection with possible code execution
PHASE 3/5 · Privilege Escalation

Through improper authorization the attacker gains elevated privileges or hijacks other sessions.

T1068 – Exploitation for Privilege Escalation T1548 – Abuse Elevation Control Mechanism
  • CVE-2026-71362 (Commerce/Magento): improper authorization, privilege escalation without login, CVSS 9.1
  • Sansec confirmed: switching a customer session to another customer account
  • CVE-2026-71384 (ColdFusion): improper authorization (DoS, adjacent network only)
PHASE 4/5 · Collection & Exfiltration

The attacker accesses private customer data of the hijacked account.

T1213 – Data from Information Repositories
  • Access to the victim's account and their private customer data (Sansec)
  • High confidentiality impact (C:H) in the critical flaws
  • GDPR Art. 32–34 relevance in case of data leakage
PHASE 5/5 · Impact

In the worst case the attacker gains full server control or disrupts availability.

T1496 – Resource Hijacking T1499 – Endpoint Denial of Service
  • Full control over the server possible without password, login or click
  • High impact on integrity and availability (I:H/A:H)
  • Scope Changed (S:C) in CVE-2026-48362 – breakout beyond the application
  • Adobe priority 1, patch recommended within 72 hours
Short & clear answers
Frequently asked questions about this incident
Am I affected by these Adobe vulnerabilities?
Only Adobe ColdFusion (2025.0.11 and older, 2023.0.22 and older), Adobe Campaign Classic v7 (7.4.3 Build 9399 and older, only on-premise and hybrid installations), and Adobe Commerce/Magento Open Source at the -2026-jul level or older are affected. If you run a regular WordPress, TYPO3, or Shopware website, this advisory does not affect you. What matters is whether one of these Adobe products runs on your own servers or on servers managed by a service provider.
What do I need to do now?
Treat ColdFusion and Campaign Classic as an emergency patch, since Adobe rates them Priority 1 and recommends installing within 72 hours. Update ColdFusion to 2025.0.12 or 2023.0.23, Campaign Classic to 7.4.4 Build 9400, and Commerce/Magento according to bulletin APSB26-92 (Priority 2, within 30 days). Back up your systems before making any changes and verify functionality afterward.
How dangerous is the ColdFusion flaw CVE-2026-48362 really?
This flaw reaches the maximum score of CVSS 10.0 and is an OS command injection that lets an attacker execute operating system commands directly on your server. The attack is carried out over the network, is technically simple, and requires neither authentication nor user interaction. This means an attacker can take full control of the server without a password and without anyone clicking a link.
Are these vulnerabilities already being actively exploited?
At the time of publication, neither Adobe nor the Center for Internet Security (CIS/MS-ISAC) was aware of any active attacks on these seven new flaws. However, this is no all-clear: the maximum CVSS 10.0 score and Priority 1 rating indicate a particularly high risk of attack. Furthermore, another ColdFusion flaw (CVE-2026-48282) was actively exploited as recently as June 30, 2026, showing that attackers are watching ColdFusion closely.
What does the Magento/Commerce flaw mean for my shop and customer data?
According to the Sansec research team, the flaw CVE-2026-71362 (CVSS 9.1) allows attackers to switch a customer session to another customer account and thereby access private customer data—without login or admin rights. Although Commerce is rated Priority 2 (within 30 days), this is highly relevant for shop operators because of the access to customer data. Update your shop according to bulletin APSB26-92.
More security news
You might also be interested in
Critical Elementor Pro Flaw: Attackers Can Fully Take Over WordPress Sites
A file upload bug in Elementor Pro up to 4.2.1 allows RCE without login. Version 4.2.2 fixes the flaw – update now!
Pods Plugin: Critical Flaw Enables Admin Takeover, No Login
A critical flaw in the WordPress plugin Pods lets attackers overwrite admin passwords without login. Over 100,000 sites are affected.
miniOrange SAML SSO: Critical Bypass Turns Attackers Into Admins
Two critical auth bypasses in the miniOrange SAML SSO plugin allow forged SAML assertions—up to full WordPress admin access.