Particle.news
Download on the App Store

Adobe Issues Urgent Patches for Seven Maximum‑Severity ColdFusion and Campaign Flaws

Adobe urged immediate installation of the fixes to reduce the risk that fast, AI‑assisted attacks could exploit the newly disclosed defects.

Overview

  • Adobe released patches Wednesday for ColdFusion (2025 Update 10 and 2023 Update 21) and Campaign Classic (ACC v7 7.4.3 build 9397) to address seven vulnerabilities rated CVSS 10.0.
  • The bugs include unrestricted dangerous file uploads, improper input validation, path traversal and incorrect authorization that can enable remote code execution, privilege escalation, arbitrary file reads, or security bypasses.
  • Adobe assigned a priority‑1 rating to the updates, said it has no evidence of active in‑the‑wild exploitation for these CVEs, and recommended administrators install the fixes as soon as possible, for example within 72 hours.
  • Campaign Classic’s highest‑severity flaw affects only on‑premises and hybrid on‑prem components while Adobe‑hosted Campaign instances have already been updated; Adobe credited external researchers Anirudh Anand, Matan Sandori and 2Bsecure for several reports.
  • To shorten the window between disclosure and patching, Adobe will publish security bulletins twice monthly starting July 14 and customers and security teams should expect faster, recurring advisories because AI is accelerating vulnerability discovery.