{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aadobecampaign7.4.39398classic/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:adobe:campaign:*:*:*:*:classic:*:*:*","cpe:2.3:a:adobe:campaign:7.4.3:9394:*:*:classic:*:*:*","cpe:2.3:a:adobe:campaign:7.4.3:9396:*:*:classic:*:*:*","cpe:2.3:a:adobe:campaign:7.4.3:9397:*:*:classic:*:*:*","cpe:2.3:a:adobe:campaign:7.4.3:9398:*:*:classic:*:*:*"],"_cs_cves":[{"cvss":10,"id":"CVE-2026-48362"},{"cvss":9.6,"id":"CVE-2026-71384"},{"cvss":8.7,"id":"CVE-2026-21273"},{"cvss":8.2,"id":"CVE-2026-21279"},{"cvss":7.8,"id":"CVE-2026-25652"},{"cvss":8.4,"id":"CVE-2026-34635"},{"cvss":7.7,"id":"CVE-2026-48385"},{"cvss":7.5,"id":"CVE-2026-48386"},{"cvss":7.5,"id":"CVE-2026-48439"},{"cvss":7.1,"id":"CVE-2026-48442"},{"cvss":10,"id":"CVE-2026-27302"},{"cvss":9.1,"id":"CVE-2026-71362"},{"cvss":10,"id":"CVE-2026-71398"},{"cvss":7.8,"id":"CVE-2026-47940"},{"cvss":8.6,"id":"CVE-2026-48397"},{"cvss":7.8,"id":"CVE-2026-48405"},{"cvss":7.8,"id":"CVE-2026-48410"},{"cvss":9.6,"id":"CVE-2026-48317"},{"cvss":10,"id":"CVE-2026-48331"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["high"],"_cs_tags":["roundup"],"_cs_type":"threat","_cs_vendors":["Adobe"],"content_html":"\u003cp\u003eThis roundup covers 24 Adobe security vulnerabilities. CVSS base scores range from 7.1 to 10.0. None are reported as actively exploited at the time of release. The issues affect Adobe Campaign Classic, Adobe Commerce, ColdFusion, ColdFusion 2025, Content Credentials Rust SDK, Lightroom Classic.\u003c/p\u003e\n\u003ch2 id=\"summary\"\u003eSummary\u003c/h2\u003e\n\u003ctable\u003e\n\t\u003cthead\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003cth\u003eCVE\u003c/th\u003e\n\t\t\t\t\t\u003cth\u003eProduct\u003c/th\u003e\n\t\t\t\t\t\u003cth\u003eSeverity\u003c/th\u003e\n\t\t\t\t\t\u003cth\u003eCVSS\u003c/th\u003e\n\t\t\t\t\t\u003cth\u003eEPSS\u003c/th\u003e\n\t\t\t\t\t\u003cth\u003eKEV\u003c/th\u003e\n\t\t\t\t\t\u003cth\u003eSource\u003c/th\u003e\n\t\t\t\u003c/tr\u003e\n\t\u003c/thead\u003e\n\t\u003ctbody\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"#cve-2026-48362\"\u003eCVE-2026-48362\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eColdFusion 2025 (\u0026lt;= 2025.0.11)\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eCritical\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e10.0\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eno\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-48362\"\u003eNVD\u003c/a\u003e (authoritative)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"#cve-2026-71384\"\u003eCVE-2026-71384\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003en/a\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eCritical\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e9.6\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eno\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-71384\"\u003eNVD\u003c/a\u003e (authoritative)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"#cve-2026-21273\"\u003eCVE-2026-21273\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eColdFusion 2025 (\u0026lt;= 2025.0.11)\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eHigh\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e8.7\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eno\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-21273\"\u003eNVD\u003c/a\u003e (authoritative)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"#cve-2026-21279\"\u003eCVE-2026-21279\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003en/a\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eHigh\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e8.2\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eno\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-21279\"\u003eNVD\u003c/a\u003e (authoritative)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"#cve-2026-25652\"\u003eCVE-2026-25652\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003en/a\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eHigh\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e7.8\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eno\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-25652\"\u003eNVD\u003c/a\u003e (authoritative)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"#cve-2026-34635\"\u003eCVE-2026-34635\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003en/a\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eHigh\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e8.4\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eno\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-34635\"\u003eNVD\u003c/a\u003e (authoritative)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"#cve-2026-48385\"\u003eCVE-2026-48385\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eColdFusion (\u0026lt;= 2025.0.11)\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eHigh\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e7.7\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eno\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-48385\"\u003eNVD\u003c/a\u003e (authoritative)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"#cve-2026-48386\"\u003eCVE-2026-48386\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eColdFusion 2025 (\u0026lt;= 2025.0.11)\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eHigh\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e7.5\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eno\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-48386\"\u003eNVD\u003c/a\u003e (authoritative)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"#cve-2026-48439\"\u003eCVE-2026-48439\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eContent Credentials Rust SDK (\u0026lt;= c2pa-v0.90.5)\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eHigh\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e7.5\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eno\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-48439\"\u003eNVD\u003c/a\u003e (authoritative)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"#cve-2026-48440\"\u003eCVE-2026-48440\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003en/a\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eno\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-48440\"\u003eNVD\u003c/a\u003e (authoritative)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"#cve-2026-48442\"\u003eCVE-2026-48442\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eContent Credentials Rust SDK (\u0026lt;= c2pa-v0.90.5)\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eHigh\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e7.1\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eno\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-48442\"\u003eNVD\u003c/a\u003e (authoritative)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"#cve-2026-27302\"\u003eCVE-2026-27302\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eAdobe Campaign Classic (\u0026lt;= 7.4.3 build 9399)\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eCritical\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e10.0\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eno\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-27302\"\u003eNVD\u003c/a\u003e (authoritative)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"#cve-2026-71362\"\u003eCVE-2026-71362\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003en/a\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eCritical\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e9.1\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eno\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-71362\"\u003eNVD\u003c/a\u003e (authoritative)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"#cve-2026-71398\"\u003eCVE-2026-71398\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eAdobe Campaign Classic (\u0026lt;= 7.4.3 build 9399)\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eCritical\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e10.0\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eno\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-71398\"\u003eNVD\u003c/a\u003e (authoritative)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"#cve-2026-47940\"\u003eCVE-2026-47940\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003en/a\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eHigh\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e7.8\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eno\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-47940\"\u003eNVD\u003c/a\u003e (authoritative)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"#cve-2026-48397\"\u003eCVE-2026-48397\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003en/a\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eno\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-48397\"\u003eNVD\u003c/a\u003e (authoritative)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"#cve-2026-48405\"\u003eCVE-2026-48405\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003en/a\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eHigh\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e7.8\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eno\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-48405\"\u003eNVD\u003c/a\u003e (authoritative)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"#cve-2026-48406\"\u003eCVE-2026-48406\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003en/a\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eno\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-48406\"\u003eNVD\u003c/a\u003e (authoritative)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"#cve-2026-48407\"\u003eCVE-2026-48407\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003en/a\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eno\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-48407\"\u003eNVD\u003c/a\u003e (authoritative)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"#cve-2026-48408\"\u003eCVE-2026-48408\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eLightroom Classic (\u0026lt;= 15.4)\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eno\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-48408\"\u003eNVD\u003c/a\u003e (authoritative)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"#cve-2026-48410\"\u003eCVE-2026-48410\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003en/a\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eHigh\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e7.8\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eno\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-48410\"\u003eNVD\u003c/a\u003e (authoritative)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"#cve-2026-48413\"\u003eCVE-2026-48413\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eAdobe Commerce (\u0026lt;= 2026-07-31)\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eno\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-48413\"\u003eNVD\u003c/a\u003e (authoritative)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"#cve-2026-48415\"\u003eCVE-2026-48415\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003en/a\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eno\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-48415\"\u003eNVD\u003c/a\u003e (authoritative)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"#cve-2026-48416\"\u003eCVE-2026-48416\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003en/a\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eno\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-48416\"\u003eNVD\u003c/a\u003e (authoritative)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch2 id=\"cve-2026-48362\"\u003eCVE-2026-48362\u003c/h2\u003e\n\u003cp\u003eCVE-2026-48362 is a critical OS command injection vulnerability in Adobe ColdFusion 2023 and 2025 that allows unauthenticated, remote attackers to achieve arbitrary code execution. The vulnerability does not require user interaction and impacts the scope of the application, posing a significant risk to affected environments.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eColdFusion 2025 (\u0026lt;= 2025.0.11)\u003c/li\u003e\n\u003cli\u003eColdFusion 2023 (\u0026lt;= 2023.0.22)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-48362\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-48362\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eRelated in this roundup: \u003ca href=\"#cve-2026-21273\"\u003eCVE-2026-21273\u003c/a\u003e, \u003ca href=\"#cve-2026-48386\"\u003eCVE-2026-48386\u003c/a\u003e.\u003c/p\u003e\n\u003ch2 id=\"cve-2026-71384\"\u003eCVE-2026-71384\u003c/h2\u003e\n\u003cp\u003eCVE-2026-71384 is an incorrect authorization vulnerability in Adobe ColdFusion 2023 and 2025. The flaw allows an unauthenticated, adjacent attacker to bypass security features, resulting in unauthorized read and write access, and potentially a denial-of-service condition. Although the vulnerable component is restricted to an administrative network zone by default, successful exploitation does not require user interaction.\u003c/p\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-71384\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-71384\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"cve-2026-21273\"\u003eCVE-2026-21273\u003c/h2\u003e\n\u003cp\u003eCVE-2026-21273 describes an improper input validation vulnerability in Adobe ColdFusion 2025 and 2023. A low-privileged attacker can exploit this flaw by enticing a user to open a malicious file, leading to unauthorized read and write access and privilege escalation on the affected system.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eColdFusion 2025 (\u0026lt;= 2025.0.11)\u003c/li\u003e\n\u003cli\u003eColdFusion 2023 (\u0026lt;= 2023.0.22)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-21273\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-21273\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eRelated in this roundup: \u003ca href=\"#cve-2026-48362\"\u003eCVE-2026-48362\u003c/a\u003e, \u003ca href=\"#cve-2026-48386\"\u003eCVE-2026-48386\u003c/a\u003e.\u003c/p\u003e\n\u003ch2 id=\"cve-2026-21279\"\u003eCVE-2026-21279\u003c/h2\u003e\n\u003cp\u003eAdobe ColdFusion versions 2025 (\u0026lt;= 2025.0.11) and 2023 (\u0026lt;= 2023.0.22) are vulnerable to an improper input validation flaw that allows for a security feature bypass. An unauthenticated remote attacker can exploit this vulnerability to gain unauthorized read and limited write access to the affected system without requiring user interaction.\u003c/p\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-21279\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-21279\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"cve-2026-25652\"\u003eCVE-2026-25652\u003c/h2\u003e\n\u003cp\u003eCVE-2026-25652 is an Incorrect Authorization vulnerability in Adobe ColdFusion 2025 and 2023 versions. A low-privileged attacker can exploit this flaw to escalate privileges and gain unauthorized read and write access to the system. Exploitation is local and does not require user interaction.\u003c/p\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-25652\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-25652\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"cve-2026-34635\"\u003eCVE-2026-34635\u003c/h2\u003e\n\u003cp\u003eAdobe ColdFusion versions 2025 (\u0026lt;= 2025.0.11) and 2023 (\u0026lt;= 2023.0.22) contain a Use of Hard-coded Cryptographic Key vulnerability. A low-privileged attacker can exploit this issue to bypass security features and obtain unauthorized read and write access without user interaction. The vulnerability results in a scope change, potentially allowing for cross-security-domain impact.\u003c/p\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-34635\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-34635\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"cve-2026-48385\"\u003eCVE-2026-48385\u003c/h2\u003e\n\u003cp\u003eAdobe ColdFusion is vulnerable to an OS command injection flaw (CVE-2026-48385) that allows low-privileged, remote attackers to bypass security features and gain unauthorized write access to the system. The vulnerability does not require user interaction and impacts the system scope.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eColdFusion (\u0026lt;= 2025.0.11)\u003c/li\u003e\n\u003cli\u003eColdFusion (\u0026lt;= 2023.0.22)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-48385\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-48385\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"cve-2026-48386\"\u003eCVE-2026-48386\u003c/h2\u003e\n\u003cp\u003eAdobe ColdFusion is vulnerable to a broken or risky cryptographic algorithm (CWE-327), which can be exploited by a remote, unauthenticated attacker to disclose sensitive memory contents. Successful exploitation allows for the unauthorized access to sensitive information without requiring user interaction.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eColdFusion 2025 (\u0026lt;= 2025.0.11)\u003c/li\u003e\n\u003cli\u003eColdFusion 2023 (\u0026lt;= 2023.0.22)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-48386\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-48386\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eRelated in this roundup: \u003ca href=\"#cve-2026-48362\"\u003eCVE-2026-48362\u003c/a\u003e, \u003ca href=\"#cve-2026-21273\"\u003eCVE-2026-21273\u003c/a\u003e.\u003c/p\u003e\n\u003ch2 id=\"cve-2026-48439\"\u003eCVE-2026-48439\u003c/h2\u003e\n\u003cp\u003eThe CAI Content Credentials SDKs and command-line tool are vulnerable to an uncontrolled resource consumption issue (CWE-400). A remote, unauthenticated attacker can exploit this vulnerability to exhaust system resources, leading to a denial-of-service (DoS) condition. No user interaction is required for successful exploitation.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eContent Credentials Rust SDK (\u0026lt;= c2pa-v0.90.5)\u003c/li\u003e\n\u003cli\u003eContent Credentials Command-Line Tool (\u0026lt;= c2patool-v0.27.5)\u003c/li\u003e\n\u003cli\u003eContent Credentials JS SDK (\u0026lt;= @contentauth/c2pa@0.14.2)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-48439\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-48439\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eRelated in this roundup: \u003ca href=\"#cve-2026-48442\"\u003eCVE-2026-48442\u003c/a\u003e.\u003c/p\u003e\n\u003ch2 id=\"cve-2026-48440\"\u003eCVE-2026-48440\u003c/h2\u003e\n\u003cp\u003eAdobe ColdFusion versions 2025 (\u0026lt;= 2025.0.11) and 2023 (\u0026lt;= 2023.0.22) are vulnerable to a heap-based buffer overflow. This vulnerability allows an unauthenticated, remote attacker to execute arbitrary code in the context of the current user without requiring user interaction. The exploitation process is non-deterministic, relying on specific environmental conditions.\u003c/p\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-48440\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-48440\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"cve-2026-48442\"\u003eCVE-2026-48442\u003c/h2\u003e\n\u003cp\u003eThe Adobe Content Credentials SDK and associated tooling are vulnerable to a path traversal vulnerability (CWE-22) which allows an attacker to perform arbitrary file system reads. The vulnerability does not require user interaction and impacts multiple language-specific SDKs and the CLI tool.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eContent Credentials Rust SDK (\u0026lt;= c2pa-v0.90.5)\u003c/li\u003e\n\u003cli\u003eContent Credentials Command-Line Tool (\u0026lt;= c2patool-v0.27.5)\u003c/li\u003e\n\u003cli\u003eContent Credentials JS SDK (\u0026lt;= @contentauth/c2pa-v0.27.5)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-48442\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-48442\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eRelated in this roundup: \u003ca href=\"#cve-2026-48439\"\u003eCVE-2026-48439\u003c/a\u003e.\u003c/p\u003e\n\u003ch2 id=\"cve-2026-27302\"\u003eCVE-2026-27302\u003c/h2\u003e\n\u003cp\u003eAdobe Campaign Classic is vulnerable to an incorrect authorization flaw (CWE-863) that allows an unauthenticated remote attacker to execute arbitrary code. The vulnerability has a CVSS v3.1 base score of 10.0 and does not require user interaction to exploit.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdobe Campaign Classic (\u0026lt;= 7.4.3 build 9399)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-27302\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-27302\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eRelated in this roundup: \u003ca href=\"#cve-2026-71398\"\u003eCVE-2026-71398\u003c/a\u003e.\u003c/p\u003e\n\u003ch2 id=\"cve-2026-71362\"\u003eCVE-2026-71362\u003c/h2\u003e\n\u003cp\u003eAdobe Commerce and Magento Open Source are vulnerable to an Incorrect Authorization flaw (CWE-863) that allows an unauthenticated, remote attacker to perform privilege escalation. The vulnerability does not require user interaction and can be exploited to gain unauthorized access to sensitive resources.\u003c/p\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-71362\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-71362\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"cve-2026-71398\"\u003eCVE-2026-71398\u003c/h2\u003e\n\u003cp\u003eAdobe Campaign Classic (ACC) is vulnerable to an incorrect authorization flaw (CWE-863) that allows an unauthenticated remote attacker to execute arbitrary code. The vulnerability has a CVSS base score of 10.0 and does not require user interaction for exploitation.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdobe Campaign Classic (\u0026lt;= 7.4.3 build 9399)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-71398\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-71398\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eRelated in this roundup: \u003ca href=\"#cve-2026-27302\"\u003eCVE-2026-27302\u003c/a\u003e.\u003c/p\u003e\n\u003ch2 id=\"cve-2026-47940\"\u003eCVE-2026-47940\u003c/h2\u003e\n\u003cp\u003eAdobe Lightroom Classic is vulnerable to an integer overflow or wraparound condition that can lead to arbitrary code execution. The vulnerability is triggered when a user is enticed to open a maliciously crafted file, allowing an attacker to execute code within the context of the current user session.\u003c/p\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-47940\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-47940\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"cve-2026-48397\"\u003eCVE-2026-48397\u003c/h2\u003e\n\u003cp\u003eAdobe Lightroom Classic is vulnerable to a deserialization of untrusted data issue that allows an attacker to achieve arbitrary code execution. The vulnerability requires user interaction, specifically the opening of a malicious file by the victim, which triggers the flaw within the application context.\u003c/p\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-48397\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-48397\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"cve-2026-48405\"\u003eCVE-2026-48405\u003c/h2\u003e\n\u003cp\u003eAdobe Lightroom Classic is vulnerable to an out-of-bounds write (CWE-787) flaw that allows an attacker to achieve arbitrary code execution. Successful exploitation requires a user to open a specially crafted malicious file, which triggers the memory corruption within the application context.\u003c/p\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-48405\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-48405\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"cve-2026-48406\"\u003eCVE-2026-48406\u003c/h2\u003e\n\u003cp\u003eAdobe Lightroom Classic is vulnerable to an out-of-bounds write (CWE-787) that allows for arbitrary code execution. A local attacker can exploit this by convincing a user to open a specially crafted malicious file within the application.\u003c/p\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-48406\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-48406\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"cve-2026-48407\"\u003eCVE-2026-48407\u003c/h2\u003e\n\u003cp\u003eAdobe Lightroom Classic is susceptible to an out-of-bounds write vulnerability that can be exploited by an attacker to achieve arbitrary code execution. Successful exploitation requires a user to open a specially crafted malicious file, which triggers the memory corruption issue within the application's process context.\u003c/p\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-48407\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-48407\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"cve-2026-48408\"\u003eCVE-2026-48408\u003c/h2\u003e\n\u003cp\u003eAdobe Lightroom Classic is vulnerable to an out-of-bounds write (CWE-787) that allows for arbitrary code execution. Successful exploitation requires a user to open a specially crafted malicious file, which triggers the vulnerability in the context of the logged-in user.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eLightroom Classic (\u0026lt;= 15.4)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-48408\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-48408\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"cve-2026-48410\"\u003eCVE-2026-48410\u003c/h2\u003e\n\u003cp\u003eAdobe Lightroom Classic is vulnerable to an out-of-bounds write, which can be exploited by an attacker to achieve arbitrary code execution. Successful exploitation requires the user to open a malicious file, making it a client-side execution risk.\u003c/p\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-48410\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-48410\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"cve-2026-48413\"\u003eCVE-2026-48413\u003c/h2\u003e\n\u003cp\u003eAdobe Commerce and Magento Open Source are vulnerable to a stored Cross-Site Scripting (XSS) attack via malicious input in form fields. A low-privileged attacker can inject scripts that execute in a victim's browser, potentially leading to unauthorized account or session control. This vulnerability involves a change in security scope.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdobe Commerce (\u0026lt;= 2026-07-31)\u003c/li\u003e\n\u003cli\u003eAdobe Commerce B2B (\u0026lt;= 2026-07-31)\u003c/li\u003e\n\u003cli\u003eMagento Open Source (\u0026lt;= 2026-07-31)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-48413\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-48413\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"cve-2026-48415\"\u003eCVE-2026-48415\u003c/h2\u003e\n\u003cp\u003eAdobe Commerce and Magento Open Source are vulnerable to an Incorrect Authorization flaw (CWE-863) that allows a low-privileged, remote attacker to bypass security controls. Successful exploitation grants unauthorized read and write access without requiring user interaction, potentially impacting data integrity and availability.\u003c/p\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-48415\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-48415\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"cve-2026-48416\"\u003eCVE-2026-48416\u003c/h2\u003e\n\u003cp\u003eCVE-2026-48416 is an incorrect authorization vulnerability in Adobe Commerce and Magento Open Source that allows remote, unauthenticated attackers to bypass security measures and gain unauthorized read access to sensitive data. The vulnerability does not require user interaction and is exploitable over the network.\u003c/p\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-48416\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-48416\u003c/a\u003e\u003c/p\u003e\n","date_modified":"2026-08-11T21:50:36Z","date_published":"2026-08-03T23:42:20Z","id":"https://feed.craftedsignal.io/briefs/2026-08-adobe-security-updates/","summary":"Roundup of Adobe security advisories published in August 2026.","title":"Adobe Security Updates — August 2026","url":"https://feed.craftedsignal.io/briefs/2026-08-adobe-security-updates/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:adobe:campaign:7.4.3:9398:*:*:classic:*:*:*","version":"https://jsonfeed.org/version/1.1"}