Adobe shipped patches this week for ColdFusion and Campaign Classic that fix seven vulnerabilities rated a perfect 10 out of 10 on the CVSS scale. Seven. Not one outlier bug that some overworked researcher found while poking at a legacy codebase, but seven separate paths to arbitrary code execution, all maxed out on severity, all in software that’s still running in production at banks, universities, government agencies, and marketing departments around the world. If you’re building out a cybersecurity program and you don’t have ColdFusion and Campaign Classic on your asset inventory, this is the week to find out if you’re wrong about that.

Adobe logo representing the company's security patch releases
Adobe’s latest patch batch includes seven maximum-severity flaws across ColdFusion and Campaign Classic.

The Vulnerability Count: Seven Flaws, Maximum Severity

Let’s be precise about what “10/10” means here, because the number gets thrown around loosely. A CVSS 10 means the flaw is remotely exploitable, requires no authentication, needs no user interaction, and grants the attacker complete control over confidentiality, integrity, and availability. There’s no asterisk on that score. When Adobe’s advisory lists seven of them across two products in a single release, that’s not a routine patch cycle. That’s a platform with structural problems.

ColdFusion has a long, unflattering history here. It’s been a favorite target for years precisely because it tends to run on servers that were stood up once, configured by someone who’s long since left the company, and never touched again except to keep the lights on. Campaign Classic showing up in the same advisory batch is the more interesting wrinkle, because it’s not the kind of system most security teams think about when they’re doing threat modeling. It’s marketing software. But “marketing software” running server-side with database access and the ability to execute arbitrary code is, functionally, just as dangerous as anything sitting in your DMZ.

Why Legacy Platforms Keep Failing the Same Way

There’s a pattern with software like ColdFusion that’s worth naming directly: it survives because it works, and it keeps getting breached because “it works” is treated as a substitute for “it’s maintained.” Nobody budgets time to modernize a system that’s quietly doing its job. The application team that owns it moves on to newer projects. The security team, if they even know the server exists, deprioritizes it because touching it might break something nobody remembers how to fix.

That’s how you end up with maximum-severity, unauthenticated remote code execution bugs sitting in production for years before someone finds them, whether that someone is a researcher doing responsible disclosure or an attacker running mass internet scans. Security hardening isn’t a one-time project you complete and check off. It’s an ongoing discipline, and legacy platforms are exactly where that discipline tends to erode first, because they’re unglamorous and nobody wants to own them.

The same logic applies to Campaign Classic. Marketing platforms hold customer data, integrate with CRM systems, and often have service accounts with broader access than they need. A perfect-10 flaw there isn’t a “marketing problem.” It’s a foothold into everything that platform touches, and depending on your network segmentation, that could be a lot more than you’d like.

What This Means For Your Cybersecurity Program This Week

If you run either of these products, the patch itself is the easy part. The harder question is whether you actually know where every instance lives, who’s exposed to the internet, and whether you’d notice exploitation if it happened before you patched. That’s the gap between “we deployed a fix” and genuine threat protection, and it’s the gap attackers count on.

A few things worth doing immediately, and a few worth building into your ongoing process:

  • Patch ColdFusion and Campaign Classic now, not on the next scheduled maintenance window. Maximum-severity RCEs get reverse-engineered into working exploits fast once the advisory is public.
  • Inventory every internet-facing instance of both platforms, including ones your app teams “forgot” to mention. Shadow IT loves legacy software precisely because nobody’s watching it.
  • Put a firewall or reverse proxy in front of any instance that doesn’t strictly need direct internet exposure, and restrict admin interfaces to known IP ranges.
  • Enable and centralize logging for these servers off-host. If an attacker gets in before you patch, your only chance at catching it is threat detection built on logs they can’t delete after the fact.
  • Rate-limit and monitor login and admin endpoints. Brute-force attempts against management consoles are a common precursor to exploitation attempts on exactly this kind of platform.
  • Treat any pre-patch exposure window as a potential incident. Have your incident response plan ready to pull evidence and isolate the host, not improvised after the fact.

None of this is exotic. It’s defense in depth applied to the boring parts of your environment, which is usually where it matters most, because the boring parts are the ones nobody’s watching.

The Broader Lesson: Old Software Doesn’t Retire on Its Own

The uncomfortable truth is that most organizations don’t decide to keep running vulnerable legacy platforms. They just never decide to stop. ColdFusion and Campaign Classic will get patched this week by teams that are paying attention, and they’ll stay exposed for months at organizations that aren’t, not because anyone made a bad call, but because nobody made a call at all. That’s the actual risk here: not the seven CVEs themselves, but the organizational blind spot that let seven maximum-severity bugs accumulate in software nobody was actively managing.

If this patch cycle prompts you to do anything beyond applying the update, let it be a genuine audit of what “legacy but load-bearing” software you’re still running, who owns it, and whether your monitoring would actually catch someone using it against you.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.