Adobe security advisory (AV26-647) – Update 2

Serial number: AV26–647
Date: July 2, 2026
Updated: July 7, 2026

On June 30, 2026, Adobe published security advisories to address critical vulnerabilities in the following products:

  • Adobe ColdFusion 2025 – Update 9 and prior
  • Adobe ColdFusion 2023 – Update 20 and prior
  • Adobe Campaign Classic – version ACC v7: 7.4.3 build 9396 and prior

Update 1

Open-source reporting indicates that CVE-2026-48282 is being exploited.

Update 2

On July 7, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-48282 to their Known Exploited Vulnerabilities (KEV) Database.

The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.

Date modified: