VYPR
patchPublished Aug 1, 2026· 1 source

Critical Adobe Campaign Classic Flaw Allows Remote Code Execution

Adobe has patched a CVSS 10.0 vulnerability in its Campaign Classic platform that enables arbitrary code execution without user interaction.

Adobe has issued critical security updates to address a severe vulnerability in its enterprise marketing automation platform, Adobe Campaign Classic (ACC). The flaw, identified as CVE-2026-48449, carries the highest possible CVSS score of 10.0, indicating a critical risk to affected systems.

This critical vulnerability stems from an authorization flaw, allowing attackers to execute arbitrary code on a target system. Crucially, the exploit requires no user interaction, meaning a successful attack could occur silently and remotely, posing a significant threat to organizations relying on ACC for their marketing operations.

In addition to the remote code execution flaw, Adobe also addressed a high-severity SQL injection vulnerability, CVE-2026-48448, which has a CVSS score of 8.6. This secondary vulnerability could be exploited to read arbitrary files from the system, potentially exposing sensitive data.

Adobe stated in its advisory that it is not aware of any active exploitation of these vulnerabilities in the wild. However, given the severity of CVE-2026-48449, prompt patching is strongly advised to prevent potential future attacks.

The fixes are available in Adobe Campaign Classic version 7.4.3 build 9398 for both Windows and Linux environments. Organizations using ACC are urged to apply these updates immediately to mitigate the risks associated with these critical security defects.

Separately, Adobe also released updates for Adobe Bridge, resolving eight critical vulnerabilities. These include flaws leading to privilege escalation and arbitrary code execution, with CVSS scores ranging from 7.8 to 8.6. Several security researchers, including Kieran ("kaiksi") and "yjdfy," were credited for discovering and reporting these issues.

The vulnerabilities in Adobe Bridge include untrusted search path issues, incorrect authorization, path traversal, and out-of-bounds write vulnerabilities. The combination of these patches underscores Adobe's ongoing efforts to secure its product suite against a wide range of threats.

Users and administrators of Adobe Campaign Classic and Adobe Bridge should prioritize applying the latest security updates to protect their environments from potential exploitation. Staying current with vendor patches remains a fundamental aspect of robust cybersecurity hygiene.

Synthesized by Vypr AI