Adobe Campaign Classic Vulnerabilities Allow Unauthenticated Remote Code Execution
Adobe has released a Priority 1 security update for Adobe Campaign Classic, addressing three critical vulnerabilities that permit unauthenticated remote code execution.

Adobe has issued a critical security update for its Adobe Campaign Classic software, patching three vulnerabilities that could allow unauthenticated attackers to execute arbitrary code remotely. The flaws, detailed in security bulletin APSB26-134 released on August 25, 2026, affect on-premises installations of Adobe Campaign Classic version 7.4.4 build 9400 and earlier, running on both Windows and Linux operating systems.
Tracked as CVE-2026-76197, CVE-2026-76195, and CVE-2026-76193, these vulnerabilities are rated as critical due to their potential for high-impact damage to confidentiality, integrity, and availability. Exploitation can occur remotely over a network without requiring any authentication or user interaction, making them particularly dangerous.
The first two vulnerabilities, CVE-2026-76197 and CVE-2026-76195, are classified as OS command injection flaws. These arise when an application fails to properly sanitize user-supplied input before passing it to an operating system command. Successful exploitation could allow a threat actor to inject malicious commands that would then execute with the same privileges as the Adobe Campaign Classic process.
The third vulnerability, CVE-2026-76193, is a server-side request forgery (SSRF) vulnerability (CWE-918). SSRF flaws enable attackers to trick a server into making unintended requests on their behalf. Depending on the application's configuration and network access, this can lead to the exposure of internal services, access to restricted systems, or serve as a stepping stone for further exploitation, including arbitrary code execution.
Adobe Campaign Classic is a widely used platform for managing and automating cross-channel marketing campaigns. A compromise of an exposed or inadequately secured deployment could have far-reaching consequences, potentially granting attackers access to sensitive campaign data, internal network resources, and credentials used by the application.
Adobe has released version 7.4.4 build 9401 of Adobe Campaign Classic to address these security concerns. Organizations running affected versions are strongly advised to upgrade to the patched build immediately. Adobe has confirmed that its own hosted instances have already been remediated and do not require any action from customers.
While Adobe states it is not aware of any active exploitation of these vulnerabilities in the wild, the critical nature and ease of exploitation necessitate prompt patching. As a precautionary measure until updates can be applied, administrators are recommended to restrict access to Campaign Classic interfaces, limit exposure to trusted networks, and diligently monitor application and host logs for any signs of suspicious activity, such as unusual process execution or unexpected outbound network connections.
This batch of vulnerabilities underscores the ongoing risk associated with complex enterprise software. Regular security updates and vigilant monitoring are crucial for protecting marketing automation platforms and the sensitive data they manage from potential exploitation.