Dettaglio notizia
| Data | 01/07/2026 |
| Titolo | Adobe Patches Critical ColdFusion RCE Flaws and Campaign Classic Bug |
| Contesto | Adobe has released Priority 1 security updates for ColdFusion and Adobe Campaign Classic to fix multiple high-severity vulnerabilities, including seven flaws rated CVSS 10.0. In ColdFusion, the patched issues affect versions 2025.9, 2023.20, and earlier, and include improper input validation (CVE-2026-48281, CVE-2026-48277), unrestricted file upload (CVE-2026-48276, CVE-2026-48283), and path traversal (CVE-2026-48282) bugs that could allow unauthenticated remote code execution without user interaction. Additional ColdFusion flaws include a path traversal issue with arbitrary file read and limited write access (CVE-2026-48313), an SSRF bug (CVE-2026-48285), and user-interaction issues such as reflected XSS (CVE-2026-48307) and improper input validation tied to malicious files (CVE-2026-48315).Adobe also patched CVE-2026-48286 in Adobe Campaign Classic, an incorrect authorization flaw affecting version 7.4.3 and earlier that can lead to arbitrary code execution on on-premises instances. Adobe said it is not aware of in-the-wild exploitation of the specific vulnerabilities, but assigned the updates a Priority 1 rating, indicating they are being targeted or are at high risk of being targeted, and urged administrators to patch within 72 hours. Recommended versions include ColdFusion 2025 Update 10, ColdFusion 2023 Update 21, and Campaign Classic 7.4.4 / build 9397 or later. |
| Fonte | https://mallory.ai/stories/019f1cba-dbec-7d13-84af-d33305908eb0 |
| Discussione? | Parliamone sul Forum |