Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical CUPS Vulnerability (CVE-2023-4586) Lets Attackers Gain Root Privileges
August 4, 2026
New Roblox Malware Steals Desktop Streams and Webcam Footage
August 4, 2026
Keyv npm package compromised in supply chain attack
August 4, 2026
Home/CyberSecurity News/Critical Adobe Campaign Classic Flaws Let Attackers Run Code
CyberSecurity News

Critical Adobe Campaign Classic Flaws Let Attackers Run Code

Key Takeaways Adobe has released a critical security update for its Campaign Classic product, addressing multiple severe vulnerabilities. The flaws, which include several rated 10.0 on the CVSS...

Jennifer sherman
Jennifer sherman
August 4, 2026 3 Min Read
3 0

Key Takeaways

  • Adobe has released a critical security update for its Campaign Classic product, addressing multiple severe vulnerabilities.
  • The flaws, which include several rated 10.0 on the CVSS scale, could allow unauthenticated remote code execution.
  • All versions of Adobe Campaign Classic ACC v7.4.3 build 9398 and earlier on both Windows and Linux are affected.
  • Organizations utilizing on-premise or hybrid deployments must upgrade to ACC v7.4.3 build 9399 immediately. Adobe-hosted instances have already been patched.

Adobe has issued an urgent security bulletin, APSB26-120, to address a series of critical vulnerabilities within Adobe Campaign Classic. Published on August 3, 2026, the update carries Adobe’s highest priority rating, underscoring the severe risk these flaws pose. Successful exploitation could lead to arbitrary code execution on affected systems.

Table Of Content

  • Key Takeaways
  • Adobe Campaign Classic Vulnerabilities
  • Critical Remote Code Execution Flaws
  • Additional High-Severity Vulnerabilities
  • What You Should Do

The vulnerabilities impact Adobe Campaign Classic (ACC) v7.4.3 build 9398 and earlier versions, running on both Windows and Linux environments. Businesses are strongly advised to upgrade their installations to ACC v7.4.3 build 9399 without delay.

Adobe Campaign Classic is a vital tool for organizations, enabling them to manage complex cross-channel marketing campaigns, maintain customer profiles, automate email workflows, and streamline campaign operations. A compromise of this system could expose highly sensitive marketing data, internal infrastructure details, confidential customer information, and potentially impact interconnected systems.

Adobe Campaign Classic Vulnerabilities

Critical Remote Code Execution Flaws

The most severe issues identified are three unauthenticated remote vulnerabilities, each scoring a perfect 10.0 on the CVSS scale, that allow for arbitrary code execution. These include:

  • CVE-2026-48331: A Server-Side Request Forgery (SSRF) vulnerability.
  • CVE-2026-48323: A template engine injection flaw.
  • CVE-2026-48330: An SQL injection vulnerability.

The CVSS vectors for these flaws highlight their extreme danger: attackers can exploit them remotely over a network without needing any authentication or user interaction. This makes externally accessible or internet-facing Campaign Classic deployments particularly vulnerable and necessitates immediate patching.

Specifically, CVE-2026-48331, the SSRF vulnerability, could permit an attacker to force the vulnerable server to make requests to internal services, cloud metadata endpoints, or other systems typically inaccessible from the internet. In certain configurations, this could facilitate credential theft, internal network mapping, or access to administrative services.

Additional High-Severity Vulnerabilities

Beyond the critical 10.0 flaws, Adobe also patched CVE-2026-48326, another SQL injection vulnerability rated 9.9 out of 10. While this particular flaw requires low-level privileges for exploitation, an authenticated malicious user or an attacker leveraging stolen credentials could still exploit it to execute code and compromise the underlying server.

CVE-2026-48333, with a CVSS score of 9.8, addresses an incorrect authorization vulnerability that could lead to privilege escalation. Such flaws can be exploited by attackers to gain access to functions or data beyond their authorized permissions.

Other significant issues resolved include CVE-2026-48317, an eval injection vulnerability scoring 9.6, and CVE-2026-48399, a security feature bypass flaw rated 7.5. Eval injection vulnerabilities typically arise from unsafe processing of dynamic code, potentially allowing attackers to execute arbitrary commands.

Adobe has stated that it is currently unaware of any active exploits targeting these vulnerabilities in the wild. However, the combination of their critical severity, remote attack vectors, and the absence of authentication requirements makes swift remediation absolutely essential for all affected organizations. The Adobe bulletin applies to on-premise and hybrid Adobe Campaign Classic deployments. Customers using Adobe-hosted instances do not need to take action, as these environments have already been remediated by Adobe.

What You Should Do

  • Immediately identify all exposed Adobe Campaign Classic servers within your infrastructure.
  • Apply the update to ACC v7.4.3 build 9399 on all affected Windows and Linux systems as soon as possible.
  • Review and audit all administrative accounts for Adobe Campaign Classic, ensuring strong passwords and least privilege principles.
  • Restrict unnecessary network access to Campaign Classic deployments, especially for internet-facing instances.
  • Monitor system logs diligently for any unusual requests, unexpected database activity, or suspicious changes in user privileges.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityVulnerability

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Critical Flaws in Google Cloud AI Let Attackers Hijack CI/CD Pipelines

Next Post

Critical Gitea RCE Vulnerability CVE-2024-XXXX Exposes Servers

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Gitea RCE Vulnerability CVE-2024-XXXX Exposes Servers
August 4, 2026
Critical Adobe Campaign Classic Flaws Let Attackers Run Code
August 4, 2026
Critical Flaws in Google Cloud AI Let Attackers Hijack CI/CD Pipelines
August 4, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us