Adobe released security updates for Adobe ColdFusion and Adobe Campaign Classic to fix multiple vulnerabilities that could let attackers bypass security controls, manipulate files, gain elevated privileges, or execute arbitrary commands. The most severe issue, CVE-2026-48276, is an unrestricted file upload flaw in ColdFusion with a CVSS 10.0 rating that can lead to remote code execution, while CVE-2026-48315 is an improper input validation bug rated CVSS 9.3 that can enable privilege escalation.
CISA later added the ColdFusion flaw to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild and elevating the issue to an urgent remediation priority for organizations running internet-facing ColdFusion servers. Reporting on the KEV update said the vulnerability can contribute to full server compromise, and urged defenders to patch affected systems quickly, investigate for signs of compromise, and prioritize exposed web applications and related enterprise platforms over CVSS-only risk scoring.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
CISA expanded its Known Exploited Vulnerabilities catalog to include an Adobe ColdFusion vulnerability among newly added flaws confirmed as exploited in the wild. The update elevated the issue as a high-priority remediation target for defenders.
Adobe released security updates for Adobe ColdFusion and Adobe Campaign Classic to remediate multiple vulnerabilities, including flaws that could allow unrestricted file upload, privilege escalation, file manipulation, and arbitrary command execution. The notice specifically highlighted CVE-2026-48276 in ColdFusion as a critical issue that could lead to remote code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
thecyberthrone.in
Open sourceegfincirt.org.eg
Open sourceegfincirt-wpn.azurewebsites.net
Open sourcehelpx.adobe.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.