Adobe Patches Critical CVE‑2026‑48362 OS Command Injection in ColdFusion, Commerce & Campaign Classic
What It Is — Adobe released emergency updates for three CVSS 10.0 flaws in ColdFusion, Adobe Commerce, and Campaign Classic. The most severe, CVE‑2026‑48362, is an operating‑system command injection that can lead to arbitrary code execution and privilege escalation.
Exploitability — Public proof‑of‑concept code has been observed in the wild; the vulnerability is actively exploitable on unpatched installations. CVSS 3.1 base score 10.0 (Critical).
Affected Products — Adobe ColdFusion (all supported versions), Adobe Commerce, Adobe Campaign Classic.
Why It Matters for Compliance & Audit Readiness
- SOC 2 Change Management (CC6.1) and System Operations (CC7.1) require documented, timely patching of critical vulnerabilities.
- Demonstrating patch‑deployment evidence in a continuous‑compliance platform provides audit‑ready proof of due diligence.
- Unpatched high‑severity flaws can invalidate the “Security” principle of SOC 2, exposing organizations to breach liability and loss of customer trust.
Recommended Actions
- Inventory all ColdFusion, Commerce, and Campaign Classic instances across your environment.
- Verify that the Adobe patches are applied; if not, remediate immediately.
- Map the remediation to SOC 2 CC6.1/CC7.1 controls and capture patch‑install logs as immutable evidence.
- Enable continuous monitoring to alert on any future critical CVE releases for Adobe products.
Source: The Hacker News