CRITICAL: Adobe ColdFusion CVE-2026-48362 Rated CVSS 10.0 for Command Injection
Adobe's August update fixes three CVSS 10.0 flaws across ColdFusion and Campaign Classic, including an unauthenticated OS command injection bug in ColdFusion tracked as CVE-2026-48362. A separate Adobe Commerce privilege escalation flaw came under active attack within hours of disclosure.