VYPR
patchPublished Aug 1, 2026· Updated Aug 12, 2026· 4 sources

Critical Adobe Campaign Classic Flaw Allows Remote Code Execution

Adobe has patched a CVSS 10.0 vulnerability in its Campaign Classic platform that enables arbitrary code execution without user interaction.

Adobe has issued critical security updates to address a severe vulnerability in its enterprise marketing automation platform, Adobe Campaign Classic (ACC). The flaw, identified as CVE-2026-48449, carries the highest possible CVSS score of 10.0, indicating a critical risk to affected systems.

This critical vulnerability stems from an authorization flaw, allowing attackers to execute arbitrary code on a target system. Crucially, the exploit requires no user interaction, meaning a successful attack could occur silently and remotely, posing a significant threat to organizations relying on ACC for their marketing operations.

In addition to the remote code execution flaw, Adobe also addressed a high-severity SQL injection vulnerability, CVE-2026-48448, which has a CVSS score of 8.6. This secondary vulnerability could be exploited to read arbitrary files from the system, potentially exposing sensitive data.

Adobe stated in its advisory that it is not aware of any active exploitation of these vulnerabilities in the wild. However, given the severity of CVE-2026-48449, prompt patching is strongly advised to prevent potential future attacks.

The fixes are available in Adobe Campaign Classic version 7.4.3 build 9398 for both Windows and Linux environments. Organizations using ACC are urged to apply these updates immediately to mitigate the risks associated with these critical security defects.

Separately, Adobe also released updates for Adobe Bridge, resolving eight critical vulnerabilities. These include flaws leading to privilege escalation and arbitrary code execution, with CVSS scores ranging from 7.8 to 8.6. Several security researchers, including Kieran ("kaiksi") and "yjdfy," were credited for discovering and reporting these issues.

The vulnerabilities in Adobe Bridge include untrusted search path issues, incorrect authorization, path traversal, and out-of-bounds write vulnerabilities. The combination of these patches underscores Adobe's ongoing efforts to secure its product suite against a wide range of threats.

Users and administrators of Adobe Campaign Classic and Adobe Bridge should prioritize applying the latest security updates to protect their environments from potential exploitation. Staying current with vendor patches remains a fundamental aspect of robust cybersecurity hygiene.

This new report details additional critical vulnerabilities within Adobe Campaign Classic, expanding on the previously reported remote code execution flaw. Specifically, it highlights three unauthenticated remote flaws (CVE-2026-48331 SSRF, CVE-2026-48323 template injection, CVE-2026-48330 SQL injection), all rated CVSS 10.0, alongside further SQL injection (CVE-2026-48326) and eval injection (CVE-2026-48317) vulnerabilities. The article emphasizes the critical nature of these issues, particularly for internet-facing deployments, and reiterates the need to upgrade to ACC v7.4.3 build 9399.

This update expands on the previously reported critical flaw in Adobe Campaign Classic by detailing additional vulnerabilities. The new article highlights three critical flaws in ColdFusion, including an OS command injection (CVE-2026-48362) with a CVSS score of 10/10, and an eval injection (CVE-2026-48273) with a CVSS score of 9.9/10. Furthermore, Adobe Commerce also received patches for seven vulnerabilities, including a privilege escalation bug (CVE-2026-71362).

This new advisory from Adobe expands upon previously disclosed vulnerabilities, detailing three additional critical flaws in ColdFusion and Campaign Classic. Notably, it includes two CVSS 10.0 rated vulnerabilities in Campaign Classic (CVE-2026-71398 and CVE-2026-27302) and one in ColdFusion (CVE-2026-48362), alongside other high-severity issues affecting Commerce. While the previous article focused on a single Campaign Classic flaw, this update addresses a broader set of critical vulnerabilities across multiple Adobe products.

Synthesized by Vypr AI