Adobe Priority 1 Patches Flag ColdFusion, Campaign Classic

Adobe on Tuesday released Priority 1 fixes for Adobe ColdFusion and Adobe Campaign Classic, closing multiple critical flaws including three in each product, while saying it is not aware of any in-the-wild exploitation. The ColdFusion bugs include command injection, eval injection, and incorrect authorization; the Campaign Classic set includes two incorrect-authorization flaws and an SQL injection issue. In plain terms, a crafted request or input can make the server run attacker-controlled code or mishandle access checks, which can turn a web app into server-side code execution or denial of service. If these products sit on internet-facing application tiers, the exposed surface is the server itself, not just a broken feature in the app. Adobe’s Priority 1 label is the signal here: it treats these fixes as especially likely targets even before public exploitation appears.

Part of the PlainSec briefing for 2026-08-12

Editions

Sources