Adobe is fixing a cluster of input-handling failures that can turn untrusted requests into server-side actions. The standard response is to treat this as a web bug, but the exposure sits deeper: uploads, paths, URL input, SSRF, and authorization checks can all become code execution, file access, or privilege escalation if they are trusted too early.
The patches cover ColdFusion 2025 Update 10 and ColdFusion 2023 Update 21, plus Adobe Campaign Classic v7.4.3 build 9397. Adobe’s advisory and national CSIRT notices map the issues across multiple CVE classes, including unrestricted file upload, improper input validation, path traversal, reflected XSS, SSRF, and incorrect authorization, with seven flaws rated at maximum severity.
There is no public exploit signal in the sources, so this is a remediation story, not an incident response one. The forward risk is straightforward: any unpatched on-prem web app or admin backend that accepts files, paths, or server-side fetches can still be pushed from input parsing into control of the application tier.
We’re back, melting - we’ve tried shouting, screaming, and throwing things at the Sun, and it is just not working. Before we begin our analysis, we want to be clear - given the number of vulnerabilities fixed (and some not mentioned..), we’ve struggled to have confidence in our attribution
Adobe ha rilasciato aggiornamenti di sicurezza per risolvere molteplici vulnerabilità, di cui 11 con gravità “critica”, nei prodotti Campaign Classic, ColdFusion
Adobe has released security patches for seven maximum-severity vulnerabilities in the ColdFusion web app development platform and the Campaign Classic marketing automation platform.