Adobe on Tuesday rolled out patches for over 50 vulnerabilities across its products, including critical-severity bugs in ColdFusion, Campaign Classic, and Commerce.
With a priority 1 rating, the ColdFusion update fixes 15 security defects, including three flagged as critical that could lead to arbitrary code execution and application denial-of-service (DoS).
These include an OS command injection tracked as CVE-2026-48362 (CVSS score of 10/10), an eval injection tracked as CVE-2026-48273 (CVSS score of 9.9/10), and an incorrect authorization tracked as CVE-2026-71384 (CVSS score of 9.6/10).
The update for Campaign Classic also has a priority 1 rating, as it resolves three critical flaws leading to arbitrary code execution: two incorrect authorization issues, CVE-2026-71398 and CVE-2026-27302 (CVSS score of 10/10), and an SQL injection bug, CVE-2026-48381 (CVSS score of 9.0/10).
Per Adobe’s priority rating system, these security defects have a higher risk of being targeted in the wild, and users should apply the patches for both products immediately.
Adobe resolved seven vulnerabilities in Commerce, including CVE-2026-71362 (CVSS score of 9.1/10), an incorrect authorization issue leading to privilege escalation. High-severity code execution and security feature bypass bugs were also addressed.
The security refresh for Commerce has a priority 2 rating, as the product is known to have been targeted in attacks before. Users are advised to apply the update within the next 30 days.
On Tuesday, Adobe also rolled out patches for 11 high-severity defects in Lightroom and 15 high- and medium-severity bugs in Content Credentials. Both updates have a priority 3 rating.
Adobe says it is not aware of any exploits in the wild for the newly addressed vulnerabilities. Additional information can be found on Adobe’s security updates page.
Related: Zoom Patches Zero-Click Code Execution Vulnerability
Related: SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities
Related: Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC
Related: Metabase Patches Vulnerability Exploited as Zero-Day

