Adobe Broadens Fixes Across Three Product Lines

Adobe and NCSC have published fixes for seven CVEs across ColdFusion, Commerce, and Campaign Classic, broadening the remediation set beyond the earlier Campaign Classic-only advisories. The confirmed fixed builds include ColdFusion 2025.0.12 and 2023.0.23, and ACC v7 7.4.4 build 9400 for Campaign Classic. The issues span incorrect authorization, SQL injection, eval injection, and command-injection style flaws. In plain terms, that means a request can bypass intended checks or reach code paths the product should never trust, which can lead to code execution, privilege escalation, or service disruption depending on the product and flaw. For teams running Adobe on-premises or hybrid components, the important change is scope: this is now a coordinated patch cycle across several admin-facing estates, not a single ACC cleanup. Adobe-hosted Campaign Classic instances were already remediated, so the remaining exposure sits with customer-managed deployments.

Part of the PlainSec briefing for 2026-08-12

Every edition of this story: Adobe Broadens Fixes Across Three Product Lines

Sources