Published on 13 August 2026
An attacker can take full control of your server without a password, without logging in, and without anyone clicking a link. That is precisely what one of the security vulnerabilities Adobe closed on 11 August 2026 makes possible. The affected flaw in Adobe ColdFusion reaches the maximum possible severity score of CVSS 10.0 – the scale goes no higher. Anyone running ColdFusion, Adobe Campaign Classic, or an Adobe Commerce/Magento shop should therefore not put this article off until tomorrow.
On 11 August 2026, Adobe published three security bulletins, closing several serious vulnerabilities across three products at once:
Adobe classifies ColdFusion and Campaign Classic as Priority 1 – the vendor's highest urgency level. For these, Adobe recommends installation "as soon as possible, for example within 72 hours." Commerce is rated Priority 2 (recommendation: within 30 days).
An important note up front: at the time of publication, according to Adobe and the Center for Internet Security (CIS/MS-ISAC), no active attacks against these seven new vulnerabilities were known. Adobe states verbatim in APSB26-90:
"Adobe is not aware of any exploits in the wild for any of the issues addressed in this update." (Adobe, Bulletin APSB26-90)
However, this is no reason to relax. The maximum CVSS 10.0 score and the Priority 1 classification mean these are vulnerabilities with a particularly high attack risk. And ColdFusion has a relevant track record – as recently as 30 June 2026, Adobe confirmed for a different ColdFusion vulnerability (CVE-2026-48282) that it was being actively exploited in limited attacks. That earlier flaw is not part of the current patch cycle, but it shows that attackers have ColdFusion firmly in their sights.
The most dangerous vulnerability is a so-called OS command injection – in plain terms, the injection of operating-system commands. Put simply: if an application does not properly filter inputs, an attacker can manipulate those inputs so that the server executes unwanted commands directly at the operating-system level.
The technical attack vector reads AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. Translated, this means the attack is carried out over the network (AV:N), is technically simple (AC:L), requires no prior privileges (PR:N) and no user interaction (UI:N). The impacts on confidentiality, integrity, and availability are all high. It is precisely this combination – reachable from the internet, no login required, no victim click needed – that makes the vulnerability so explosive.
Two further ColdFusion vulnerabilities are eval injection (CVE-2026-48273, requires low privileges) and an improper authorization (CVE-2026-71384, impact denial-of-service, exploitable only from an adjacent network).
In Adobe Campaign Classic – the marketing automation and campaign solution – two vulnerabilities (CVE-2026-71398 and CVE-2026-27302) lead, according to Adobe, to arbitrary code execution. Both likewise carry the vector AV:N/AC:L/PR:N/UI:N, making them exploitable over the network without login and without user interaction. A third vulnerability (CVE-2026-48381) is a SQL injection with possible code execution, but of high attack complexity.
Important: only fully on-premise installations as well as the local components of hybrid installations are affected. Adobe-hosted Campaign instances have, according to the vendor, already been corrected and require no customer action.
In Adobe Commerce and Magento Open Source, CVE-2026-71362 is officially an "improper authorization" with the impact of privilege escalation – and specifically without login and without administration rights. The independent research team at Sansec analysed the patch and describes a concrete practical impact:
"Sansec reviewed the patch and confirmed that the vulnerability lets attackers switch a customer session to another customer account. This gives them access to the victim's account and private customer data." (Sansec Forensics Team)
An attacker can therefore switch a customer's session to another customer account and thereby gain access to private customer data. For shop operators, this is highly relevant despite the lower Priority 2 rating.
Specifically, the following version levels are affected:
A very important clarification for SMEs: if you run an ordinary WordPress, TYPO3, or Shopware website, you are not affected simply because of this report. The vulnerabilities concern exclusively the Adobe products named. The central question is therefore not what your public website looks like, but whether ColdFusion, Campaign Classic (on-premise/hybrid), or Adobe Commerce/Magento is running at an affected level on your own servers or those operated by a service provider.
Adobe does not publish any figure on affected installations or data records. That expressly means "not published" – not "no affected systems."
composer.lock file, check the product line and monthly patch level against APSB26-92. A "-2026-jul" level or older is affected. With the Commerce Version Tool installed, vendor/bin/patch-status delivers a machine-readable report on missing patches and CVE coverage.nlserver – only then is the fix active. Afterwards, check whether campaigns, web forms, database access, and interfaces are working.An unpatched vulnerability is not automatically a reportable data breach. But if an exploitation exposes, alters, destroys, or grants unauthorised access to personal data, then a personal data breach has occurred. Particularly with Campaign Classic (extensive contact and communication data) and Commerce/Magento (customer accounts, order and payment data), this scenario is tangible.
Art. 32 GDPR requires risk-oriented, appropriate technical and organisational measures. Promptly applying critical vendor updates is an essential building block here – but it does not replace a complete security concept. If your investigation after an incident is likely to reveal a risk to the rights and freedoms of natural persons, you must inform the competent supervisory authority without undue delay, if possible within 72 hours of becoming aware (Art. 33 GDPR). Where a high risk is likely, the data subjects must also be notified (Art. 34 GDPR). And even if you do not report: the assessment, including its reasoning, must be documented (Art. 33(5) GDPR).
How seriously supervisory authorities take Art. 32 is shown by a German comparable case: in 2019, the Federal Data Protection Commissioner (BfDI) imposed a fine of EUR 9.55 million on 1&1 Telecom for inadequate technical and organisational measures in customer authentication.
"The fines imposed are a clear signal that we will enforce this protection of fundamental rights." (BfDI, press release 2019)
This case does not concern an Adobe vulnerability and is not a blanket benchmark for fines. But it illustrates the practical relevance of Art. 32. Violations of it fall within the fine framework of Art. 83(4) GDPR: up to EUR 10 million or 2% of the previous year's total worldwide annual turnover – whichever is higher. This article cannot replace a case-by-case decision on the reporting obligation; in the event of an incident, immediately involve your data protection officer, legal counsel, and, where applicable, your processor.
Three Adobe products, seven new CVEs, three of them with the maximum CVSS 10.0 score: the situation is serious, even though no active attacks against these specific vulnerabilities are known at this time. For operators of ColdFusion and Campaign Classic (on-premise/hybrid), the rule is: treat the update as an emergency and apply it within the 72-hour window. For Commerce/Magento shops, the possible account takeover described by Sansec is reason enough to schedule the August patch promptly.
First check whether you are affected at all – plain WordPress or Shopware sites are not. And don't let service providers fob you off with a blanket "patched" – have them confirm specific version numbers and dates. The patch is here. What counts now is how quickly it lands on your servers.