news.mlab.sh
Back to the feed
vulnerability

Adobe Patches Critical ColdFusion Vulnerabilities

High
Summary

Adobe released a substantial security update addressing 88 vulnerabilities across its Creative Cloud suite, including several critical flaws in ColdFusion, Commerce, Experience Manager, and Illustrator. The update focuses on preventing code execution and privilege escalation, and comes after a rapid response to a previously exploited ColdFusion vulnerability.

Adobe released a comprehensive security update on Tuesday, addressing 88 vulnerabilities across its Creative Cloud products. These vulnerabilities span a range of products including ColdFusion, Commerce, Experience Manager, Illustrator, Content Credentials SDK, Animate, Audition, Bridge, Media Encoder, Premiere Pro, After Effects, and Creative Cloud Desktop Application. The update is designed to mitigate risks such as arbitrary code execution and privilege escalation.

Specifically, within ColdFusion, eight critical vulnerabilities were resolved, including CVE-2026-48318, CVE-2026-48322, CVE-2026-48284, CVE-2026-48321, CVE-2026-48325, CVE-2026-48319, CVE-2026-48324, and CVE-2026-48327. These flaws include path traversal, code injection, improper input validation, missing authentication, SQL injection, and incorrect authorization.

Adobe’s update follows a rapid response to a previously exploited ColdFusion vulnerability, where hackers began leveraging a flaw within hours of public disclosure. The update for ColdFusion 2025 update 11 and ColdFusion 2023 update 22 resolves all the bugs.

Beyond ColdFusion, the update also includes fixes for 13 vulnerabilities in Commerce (CVE-2026-48356 and CVE-2026-48358), 13 in Experience Manager (CVE-2026-48259 and CVE-2026-48359), and four in Illustrator (CVE-2026-48334). Adobe states it is currently unaware of any active exploitation of these vulnerabilities.

Users are strongly advised to apply these patches immediately to protect their systems.

Read the full article at SecurityWeek