Exploits

Adobe Campaign Classic Vulnerability: Critical Update Released

Published  ·  7 min read

Adobe has released security updates for a maximum-severity vulnerability in Campaign Classic, its enterprise marketing automation platform. The flaw could allow arbitrary code execution without any user interaction. If you are running this product, you need to update immediately.

The Adobe Campaign Classic vulnerability is tracked as CVE-2026-48449 and carries a CVSS score of 10.0. That is the highest possible severity rating. The issue is a case of incorrect authorization that could result in arbitrary code execution in the context of the current user.

Adobe also patched a second high-severity flaw in Campaign Classic, CVE-2026-48448, which stems from SQL injection and could lead to arbitrary file reads. The company said it is not aware of any of the flaws being exploited in the wild, but the severity of the vulnerabilities demands prompt action.

Let me walk through what is affected, what has been fixed, and what you need to do.

The Campaign Classic Vulnerabilities

The Adobe Campaign Classic vulnerability CVE-2026-48449 is the headline issue. It is an incorrect authorization flaw that allows an attacker to execute arbitrary code without requiring any user interaction.The CVSS score of 10.0 indicates the severity of the impact.

The second vulnerability, CVE-2026-48448, has a CVSS score of 8.6. This is a SQL injection vulnerability which allows attackers to read arbitrary files from the system. Although reading files is not as serious as executing codes, it can nevertheless result in leaking confidential information.

Adobe's advisory states: "This update addresses critical vulnerabilities that could result in arbitrary code execution and arbitrary file system read." The company noted that it is not aware of either flaw being exploited in the wild.

Which Versions Are Affected?

Both Adobe Campaign Classic vulnerabilities affect Campaign Classic v7. The fixes are included in ACC v7: 7.4.3 build 9398 for Windows and Linux. If you are running an earlier version, you are vulnerable and need to update.

The advisory does not list specific affected versions beyond the need to update to the patched build. This suggests that multiple earlier versions are vulnerable to the Adobe Campaign Classic vulnerability.

The Adobe Bridge Vulnerabilities

Separately, Adobe has also shipped updates to remediate eight critical-rated flaws in Adobe Bridge. These vulnerabilities affect the digital asset management tool and could lead to privilege escalation and arbitrary code execution.

The eight Adobe Bridge vulnerabilities are:

  • CVE-2026-48395 (CVSS: 8.6) - An untrusted search path vulnerability leading to arbitrary code execution
  • CVE-2026-48396 (CVSS: 8.6) - An incorrect authorization vulnerability leading to arbitrary code execution
  • CVE-2026-48390 (CVSS: 8.6) - An incorrect authorization vulnerability leading to privilege escalation
  • CVE-2026-48391 (CVSS: 8.2) - An untrusted search path vulnerability leading to arbitrary code execution
  • CVE-2026-48374 (CVSS: 7.8) - A path traversal vulnerability leading to arbitrary code execution
  • CVE-2026-48392 (CVSS: 7.8) - An out-of-bounds write vulnerability leading to arbitrary code execution
  • CVE-2026-48393 (CVSS: 7.8) - An out-of-bounds write vulnerability leading to arbitrary code execution
  • CVE-2026-48394 (CVSS: 7.8) - An out-of-bounds write vulnerability leading to arbitrary code execution

All eight Adobe Bridge vulnerabilities carry high or critical severity ratings. Users of Adobe Bridge should apply the latest updates for optimal protection.

Credits for Discovery

Adobe credited security researcher Kieran, known as "kaiksi," with discovering and reporting five of the Adobe Bridge vulnerabilities: CVE-2026-48390, CVE-2026-48391, CVE-2026-48395, CVE-2026-48396, and CVE-2026-48374.

The remaining three Adobe Bridge vulnerabilities CVE-2026-48392, CVE-2026-48393, and CVE-2026-48394 were reported by a researcher using the handle "yjdfy."

Responsible disclosure from the security research community helps Adobe identify and patch these issues before they can be widely exploited.

What Makes the Campaign Classic Vulnerability So Serious?

The Adobe Campaign Classic vulnerability CVE-2026-48449 is rated CVSS 10.0 for good reason. It allows for the execution of code arbitrarily, without the need for any user intervention at all. In practice, a hacker can exploit this vulnerability to run malicious code in the compromised system.

Campaign Classic is an enterprise-level marketing automation platform that handles sensitive information about its customers, campaign configurations, and interconnection with other business systems. Compromising the system will result in data breaches, compromise of the system, and subsequent lateral movement inside the network.

The SQL injection vulnerability, identified by CVE-2026-48448, is also important to note. Even though the vulnerability does not allow the attacker to execute any code but only read the files, it may result in exposing sensitive information such as configuration files and credentials.

The Bigger Picture for Adobe Products

The vulnerabilities in Adobe Campaign Classic and Adobe Bridge belong to a wider trend. The software made by Adobe is widely spread through enterprises and creative industries. It makes a good target for the attackers.

Adobe has been proactive in addressing security issues, but the number of critical vulnerabilities in their products is a reminder that all enterprise software requires ongoing security attention. Organizations need to stay current with patches and monitor their Adobe deployments for signs of compromise.

What Organizations Should Do

The first step to be taken is to implement the updates immediately. In regards to Campaign Classic, one should move to ACC v7: 7.4.3 build 9398 on Windows and Linux systems. In regards to Adobe Bridge, the user should install the latest available update from Adobe.

Beyond patching, organizations should review their Campaign Classic deployments for any signs of unauthorized access or unusual activity. While Adobe is not aware of exploitation in the wild, the severity of the Adobe Campaign Classic vulnerability means defenders should not assume they are safe.

These are some of the recommendations:

  • Identify all Campaign Classic installations and patch them
  • Check logs for any anomalies
  • Check for any unauthorized file accesses or other anomalies in the system
  • Install the Adobe Bridge update on all computers where it is installed
  • Limit the privileged access to Campaign Classic where possible

Wrapping It Up

The Adobe Campaign Classic vulnerability CVE-2026-48449 is a maximum-severity flaw that requires immediate attention. The CVSS rating of 10.0 is a red flag indicating that this is no ordinary software patching. It is a critical fix for a serious security issue.

Adobe has also patched eight critical Adobe Bridge vulnerabilities that could lead to privilege escalation and arbitrary code execution. The company is not aware of exploitation in the wild, but the potential impact is significant.

The updates are available. The information is public. The risk is real. There is no reason to delay. Check your Campaign Classic version, apply the update to build 9398, and update Adobe Bridge to the latest version.

As always, The Hacker News will continue to track these vulnerabilities and update its coverage as new information emerges.

FAQ Section

What is the Adobe Campaign Classic vulnerability CVE-2026-48449?

It is a maximum-severity incorrect authorization flaw in Adobe Campaign Classic that allows arbitrary code execution without user interaction. The vulnerability carries a CVSS score of 10.0.

Which Adobe Campaign Classic versions are affected?

The vulnerability affects Campaign Classic v7. Adobe has released ACC v7: 7.4.3 build 9398 for Windows and Linux to address the issue.

What other Adobe vulnerabilities were patched?

Adobe also patched eight critical flaws in Adobe Bridge, including untrusted search path, incorrect authorization, path traversal, and out-of-bounds write vulnerabilities that could lead to privilege escalation and arbitrary code execution.

Has the Adobe Campaign Classic vulnerability been exploited?

Adobe stated it is not aware of any of the flaws being exploited in the wild at this time. However, the severity of the vulnerabilities warrants immediate patching.

How can the organizations protect themselves from any such threats?

They should implement the patches immediately. They should upgrade their Campaign Classic to ACC v7: 7.4.3 build 9398 and Adobe Bridge to its latest version. They should review their logs for any suspicious activity.

Source: The Hacker News
Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067