Adobe has issued a critical security update for Adobe Campaign Classic, addressing multiple flaws that could enable arbitrary code execution on vulnerable systems. The update, tracked as APSB26-120 and published on August 3, 2026, carries Adobe’s highest priority rating of 1.
The security issues affect Adobe Campaign Classic ACC v7.4.3 build 9398 and earlier on Windows and Linux. Organizations should upgrade to ACC v7.4.3 build 9399 as soon as possible.
Organizations use Adobe Campaign Cla
Adobe has issued a critical security update for Adobe Campaign Classic, addressing multiple flaws that could enable arbitrary code execution on vulnerable systems. The update, tracked as APSB26-120 and published on August 3, 2026, carries Adobe’s highest priority rating of 1.
The security issues affect Adobe Campaign Classic ACC v7.4.3 build 9398 and earlier on Windows and Linux. Organizations should upgrade to ACC v7.4.3 build 9399 as soon as possible.
Organizations use Adobe Campaign Classic to manage cross-channel marketing campaigns, customer profiles, email workflows, and campaign automation. A successful compromise could give attackers access to sensitive marketing data, internal infrastructure, customer information, and connected systems.
Adobe Campaign Classic Vulnerabilities
The most serious flaws are three unauthenticated remote vulnerabilities (CVSS 10.0) that can lead to arbitrary code execution: CVE-2026-48331 – Server-side request forgery (SSRF), CVE-2026-48323 – Template engine injection, CVE-2026-48330 – SQL injection.
Their CVSS vectors show that an attacker could exploit them remotely over a network without requiring authentication or user interaction. This makes internet-facing and externally accessible Campaign Classic deployments especially important to patch quickly.
CVE-2026-48331 is an SSRF vulnerability. SSRF bugs can allow an attacker to make the vulnerable server send requests to internal services, cloud metadata endpoints, or systems that are normally inaccessible from the internet. In certain environments, this can help attackers access credentials, map internal networks, or reach administrative services.
Adobe also fixed another SQL injection vulnerability, CVE-2026-48326, rated 9.9 out of 10. Unlike the maximum-severity SQL injection flaw, exploiting this issue requires low-level privileges. However, a malicious authenticated user or an attacker with stolen credentials could potentially use it to execute code and compromise the underlying server.
CVE-2026-48333, rated 9.8, is an incorrect authorization vulnerability that could allow privilege escalation. Attackers may exploit such flaws to access functions or data beyond their intended permissions.
The remaining issues include CVE-2026-48317, an eval injection vulnerability with a CVSS score of 9.6, and CVE-2026-48399, a security feature bypass flaw with a CVSS score of 7.5.
Eval injection can occur when an application processes dynamic code unsafely, potentially allowing attackers to run attacker-controlled commands.
Adobe said it is not aware of any exploits targeting these vulnerabilities in the wild. However, the critical severity, remote attack paths, and lack of authentication requirements make rapid remediation essential.
The Adobe bulletin applies to on-premise and hybrid Adobe Campaign Classic deployments, while Adobe-hosted instances have already been remediated and require no customer action.
Security teams should identify exposed Campaign Classic servers, apply build 9399, review administrative accounts, restrict unnecessary network access, and monitor logs for unusual requests, unexpected database activity, or suspicious changes to privileges.
Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction.
Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute arbitrary code in the context of the current user without requiring any user interaction.
“Adobe h
Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction.
Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute arbitrary code in the context of the current user without requiring any user interaction.
“Adobe has released a security update for Adobe Campaign Classic. This update addresses critical vulnerabilities that could result in arbitrary code execution and arbitrary file system read.” reads the advisory. “Adobe is not aware of any exploits in the wild for any of the issues addressed in these updates.”
Organizations using Adobe Campaign Classic should apply the available security updates as soon as possible to reduce the risk of exploitation.
Adobe also fixed CVE-2026-48448 (CVSS score 8.6), a high-severity SQL injection flaw that could allow arbitrary file reads.
Both vulnerabilities are patched in Adobe Campaign Classic v7.4.3 build 9398 for Windows and Linux.
Adobe also released updates for Adobe Bridge, fixing eight critical vulnerabilities that could allow attackers to execute arbitrary code or escalate privileges. The flaws include incorrect authorization, untrusted search path, path traversal, and out-of-bounds write vulnerabilities, with CVSS scores ranging from 7.8 to 8.6.
Researcher Kieran (kaiksi) disclosed the flaws CVE-2026-48390, CVE-2026-48391, CVE-2026-48395, CVE-2026-48396, and CVE-2026-48374, while the researcher yjdfy reported the vulnerabilities CVE-2026-48392, CVE-2026-48393, and CVE-2026-48394.
Adobe fixed multiple critical flaws, including max severity bugs in ColdFusion and Campaign Classic that could lead to remote code execution
Adobe has released security updates for ColdFusion and Campaign Classic, fixing multiple critical vulnerabilities, including seven maximum-severity issues (CVSS score of 10.0). If exploited, the flaws could allow attackers to execute arbitrary code, escalate privileges, read sensitive files, or bypass security protections.
Adobe strongly recommends
Adobe fixed multiple critical flaws, including max severity bugs in ColdFusion and Campaign Classic that could lead to remote code execution
Adobe has released security updates for ColdFusion and Campaign Classic, fixing multiple critical vulnerabilities, including seven maximum-severity issues (CVSS score of 10.0). If exploited, the flaws could allow attackers to execute arbitrary code, escalate privileges, read sensitive files, or bypass security protections.
Adobe strongly recommends that customers apply the updates as soon as possible to reduce the risk of compromise.
The vulnerabilities include:
CVE-2026-48276, CVE-2026-48283 (CVSS score of 10.0) – Allow attackers to upload malicious files and execute arbitrary code.
CVE-2026-48277, CVE-2026-48281, CVE-2026-48316 (CVSS score of 10.0) – Input validation flaws that could let attackers execute arbitrary code.
CVE-2026-48282 (CVSS score of 10.0) – A path traversal flaw that could result in arbitrary code execution.
CVE-2026-48313 (CVSS score of 9.3) – A path traversal flaw that could let attackers read sensitive files.
CVE-2026-48315 (CVSS score of 9.3) – An input validation flaw that could allow privilege escalation.
Adobe addressed these vulnerabilities in ColdFusion 2023 Update 21 and ColdFusion 2025 Update 10. Security researchers Anirudh Anand, Matan Sandori, and 2Bsecure reported several of the vulnerabilities.
The firm thanked researchers for reporting the issues and helping improve security: Anirudh Anand reported CVE-2026-48283 and CVE-2026-48313, while Matan Sandori and 2Bsecure reported CVE-2026-48307.
The company also fixed a critical flaw, tracked as CVE-2026-48286 (CVSS score of 10.0) in Adobe Campaign Classic that could let attackers execute arbitrary code due to an authorization weakness.
The issue affects on-premises deployments running version 7.4.3 build 9396 and earlier and is fixed in build 9397. Adobe-hosted instances are not affected.
The software giant said it has seen no evidence of active exploitation.
“Adobe is not aware of any exploits in the wild for any of the issues addressed in these updates.” reads the advisory.