Cyber Security News

Critical Adobe Campaign Classic Vulnerabilities Enables Arbitrary Code Execution

Adobe has issued a critical security update for Adobe Campaign Classic, addressing multiple flaws that could enable arbitrary code execution on vulnerable systems. The update, tracked as APSB26-120 and published on August 3, 2026, carries Adobe’s highest priority rating of 1.

The security issues affect Adobe Campaign Classic ACC v7.4.3 build 9398 and earlier on Windows and Linux. Organizations should upgrade to ACC v7.4.3 build 9399 as soon as possible.

Organizations use Adobe Campaign Classic to manage cross-channel marketing campaigns, customer profiles, email workflows, and campaign automation. A successful compromise could give attackers access to sensitive marketing data, internal infrastructure, customer information, and connected systems.

Adobe Campaign Classic Vulnerabilities

The most serious flaws are three unauthenticated remote vulnerabilities (CVSS 10.0) that can lead to arbitrary code execution: CVE-2026-48331 – Server-side request forgery (SSRF), CVE-2026-48323 – Template engine injection, CVE-2026-48330 – SQL injection.

Their CVSS vectors show that an attacker could exploit them remotely over a network without requiring authentication or user interaction. This makes internet-facing and externally accessible Campaign Classic deployments especially important to patch quickly.

CVE-2026-48331 is an SSRF vulnerability. SSRF bugs can allow an attacker to make the vulnerable server send requests to internal services, cloud metadata endpoints, or systems that are normally inaccessible from the internet. In certain environments, this can help attackers access credentials, map internal networks, or reach administrative services.

Adobe also fixed another SQL injection vulnerability, CVE-2026-48326, rated 9.9 out of 10. Unlike the maximum-severity SQL injection flaw, exploiting this issue requires low-level privileges. However, a malicious authenticated user or an attacker with stolen credentials could potentially use it to execute code and compromise the underlying server.

CVE-2026-48333, rated 9.8, is an incorrect authorization vulnerability that could allow privilege escalation. Attackers may exploit such flaws to access functions or data beyond their intended permissions.

The remaining issues include CVE-2026-48317, an eval injection vulnerability with a CVSS score of 9.6, and CVE-2026-48399, a security feature bypass flaw with a CVSS score of 7.5.

Eval injection can occur when an application processes dynamic code unsafely, potentially allowing attackers to run attacker-controlled commands.

Adobe said it is not aware of any exploits targeting these vulnerabilities in the wild. However, the critical severity, remote attack paths, and lack of authentication requirements make rapid remediation essential.

The Adobe bulletin applies to on-premise and hybrid Adobe Campaign Classic deployments, while Adobe-hosted instances have already been remediated and require no customer action.

Security teams should identify exposed Campaign Classic servers, apply build 9399, review administrative accounts, restrict unnecessary network access, and monitor logs for unusual requests, unexpected database activity, or suspicious changes to privileges.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

3 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

12 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

13 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

14 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

14 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

14 hours ago