Adobe julkaisi 11. elokuuta 2026 viisi tietoturvatiedotetta, jotka kattavat 51 haavoittuvuutta ColdFusionissa, Commercessa, Campaign Classicissa, Lightroom Classicissa ja Content Credentials SDK:ssa.
Research answer

Create a landscape editorial hero image for this Studio Global article: What critical vulnerabilities were disclosed by Adobe on August 11, 2026, in Commerce and ColdFusion, and what are the key details, exploita. Article summary: Here are the critical vulnerabilities disclosed by Adobe on August 11, 2026, across ColdFusion and Commerce.. Topic tags: general, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers, clickbait thumbnails, icons, and tiny thumbnail layouts. Make it useful as an illustrative visual, n
On August 11, 2026, Adobe released security updates addressing over 50 vulnerabilities across its product line. The most urgent fixes target ColdFusion and Adobe Commerce, both widely deployed in enterprise environments. While Adobe reported no active exploitation at the time of disclosure, the severity of certain flaws — including a CVSS 10.0 remote code execution (RCE) vulnerability in ColdFusion — demands immediate attention from security teams .
Adobe patched 15 security defects in ColdFusion 2025 and 2023. Three were rated critical :
| CVE | Type | CVSS | Impact |
|---|---|---|---|
| CVE-2026-48362 | OS command injection | 10.0 | Remote code execution |
| CVE-2026-48273 | Eval injection | 9.9 | Remote code execution |
| CVE-2026-71384 | Incorrect authorization | 9.6 | Security control bypass, administrative access |
CVE-2026-48362, the most severe ColdFusion flaw, allows an unauthenticated attacker to execute arbitrary operating system commands via a crafted request . This can lead to full server compromise. The eval injection (CVE-2026-48273) and incorrect authorization (CVE-2026-71384) bugs similarly open the door for code execution and privilege escalation
.
Adobe resolved 7 vulnerabilities in Commerce and Magento Open Source .
| CVE | Type | CVSS | Impact |
|---|---|---|---|
| CVE-2026-71362 | Incorrect authorization | 9.1 | Privilege escalation (unauthenticated, no user interaction) |
| Other patched CVEs | Various (high severity) | — | Arbitrary code execution, security feature bypass |
The Commerce flaw CVE-2026-71362 is particularly dangerous because it requires no authentication and no user interaction, allowing an unauthenticated attacker to escalate privileges over the network . This could expose sensitive customer data and enable unauthorized system modifications
.
Adobe released five security bulletins on August 11, addressing a total of 51 CVEs across :
Of the 51 vulnerabilities, 33 were rated critical . The highest-severity items across the entire release were the ColdFusion OS command injection (CVSS 10.0) and Campaign Classic's two CVSS 10.0 flaws
.
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
Adobe julkaisi 11. elokuuta 2026 viisi tietoturvatiedotetta, jotka kattavat 51 haavoittuvuutta ColdFusionissa, Commercessa, Campaign Classicissa, Lightroom Classicissa ja Content Credentials SDK:ssa.
Adobe julkaisi 11. elokuuta 2026 viisi tietoturvatiedotetta, jotka kattavat 51 haavoittuvuutta ColdFusionissa, Commercessa, Campaign Classicissa, Lightroom Classicissa ja Content Credentials SDK:ssa. ColdFusionin APSB26 90 on luokiteltu Prioriteetti 1 tasolle (päivitettävä välittömästi).
Commerce verkkokauppa alustan APSB26 92 on Prioriteetti 2 (päivitettävä 30 päivän kuluessa).