CuraSec

Plan active

Adobe Patches Three CVSS 10.0 Flaws in ColdFusion, Commerce, Campaign Classic

2026-08-12 11:57 UTC · The Hacker News · read the source ↗ #adobe#critical-vulnerability#coldfusion
  • Engineer — Plan: CVSS 10.0 OS command injection in ColdFusion and companion critical flaws in Commerce and Campaign Classic warrant prioritized patching this sprint. No KEV listing or public PoC yet, but severity justifies treating this ahead of routine patch cycles — apply Adobe’s August updates to all three products immediately.
  • SOC/IR — Skip
  • Leader — Skip
  • Signals: CVE-2026-48362 — CISA KEV: not listed, EPSS n/a, no public PoC found
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.