Adobe has issued critical updates for its Campaign Classic platform, an enterprise-level marketing automation tool, to fix a severe vulnerability that could lead to unauthorized code execution. Identified as CVE-2026-48449, this flaw ranks the highest on the Common Vulnerability Scoring System (CVSS) with a score of 10.0, highlighting its potential impact.
Understanding the Vulnerability
The flaw results from improper authorization processes within Adobe Campaign Classic, allowing attackers to execute arbitrary code without needing user intervention. This makes it particularly dangerous as it can be exploited remotely under the current user’s credentials, potentially compromising the entire system.
Alongside this, Adobe has patched another significant vulnerability, CVE-2026-48448, which scores 8.6 on the CVSS. This issue involves SQL injection, which could allow attackers to access and read arbitrary files, further expanding the potential attack surface.
Addressing Critical Software Flaws
Adobe’s advisory emphasizes that these updates are crucial for preventing potential code execution and unauthorized file access. Released as part of ACC v7: 7.4.3 build 9398, these updates apply to both Windows and Linux systems. Notably, Adobe has confirmed that, to date, there have been no reported cases of these vulnerabilities being exploited in live environments.
In addition to Campaign Classic, Adobe has released patches for Adobe Bridge, addressing eight critical vulnerabilities, including CVE-2026-48395 and CVE-2026-48396, which could lead to privilege escalation and code execution. This demonstrates Adobe’s continued efforts to secure its software products.
Recommendations for Users
Adobe has credited security researchers Kieran and “yjdfy” for identifying these vulnerabilities, highlighting the importance of collaborative cybersecurity efforts. Users are strongly urged to implement these updates immediately to safeguard their systems against potential attacks.
Keeping software up-to-date is a fundamental step in maintaining security, especially in enterprise environments where the impact of such vulnerabilities can be extensive. By addressing these flaws promptly, businesses can ensure their operations remain secure and resilient against cyber threats.
