
ADOBE has released security updates that fix three critical flaws in ColdFusion and Campaign Classic, each earning a CVSS score of 10.0, as detailed in the company's security bulletin. The bulletin urges administrators to apply the patches without delay to prevent potential compromise. The flaws affect core functionality and could allow an attacker to take full control of vulnerable systems.
The vulnerabilities allow arbitrary code execution and privilege escalation when malicious requests are processed by the affected servers, a point highlighted by The Hacker News. Successful exploitation does not require authentication, which raises the risk for internet‑facing installations. Adobe notes that the issues reside in components handling file uploads and template rendering.
The same security bulletin includes fixes for 88 vulnerabilities across twelve Adobe products, covering Commerce, Experience Manager and Illustrator among others, according to SecurityWeek. Updates for Commerce and Experience Manager each address thirteen issues, with several marked critical. Illustrator also receives patches for flaws that could lead to code execution when opening specially crafted files.
To date there have been no public reports of these ColdFusion or Campaign Classic flaws being exploited in the wild, and no threat actor has been linked to the vulnerabilities. However, the maximum CVSS rating makes them attractive targets for automated scanning tools that seek unpatched services.
Defenders should start by downloading the latest updates from Adobe's security bulletin and applying them to all affected servers. Prioritise ColdFusion and Campaign Classic installations, then proceed to the other products listed in the advisory. After patching, review logs for any signs of attempted exploitation and verify that service versions have been updated correctly.
Maintaining an accurate asset inventory helps ensure that no instance is overlooked during the update process. Where possible enable automatic notifications for future Adobe releases and consider temporary network restrictions or web application firewall rules as a stopgap if immediate patching cannot be completed.