Adobe Campaign Classic Critical Flaws Let Attackers Run Code
Key Takeaways Adobe has addressed three critical vulnerabilities in its Campaign Classic software. These flaws, primarily OS command injection and server-side request forgery, could allow...
Key Takeaways
- Adobe has addressed three critical vulnerabilities in its Campaign Classic software.
- These flaws, primarily OS command injection and server-side request forgery, could allow unauthenticated attackers to execute arbitrary code remotely.
- On-premises installations of Adobe Campaign Classic version 7.4.4 build 9400 and earlier on Windows and Linux are affected.
- Adobe has released a priority patch (build 9401) and strongly urges immediate updates for all affected systems.
Adobe Issues Urgent Patch for Critical Campaign Classic Vulnerabilities
Adobe has released a crucial Priority 1 security update for its Adobe Campaign Classic product, addressing three critical vulnerabilities that could enable unauthenticated remote attackers to execute arbitrary code on affected systems. The patches were made available following the publication of security bulletin APSB26-134 on August 25, 2026.
Table Of Content
The identified flaws specifically impact on-premises installations of Adobe Campaign Classic version 7.4.4 build 9400 and all earlier versions, running on both Windows and Linux operating environments. While Adobe has stated it has no evidence of these vulnerabilities being exploited in the wild, the severe CVSS scores and the potential for network-based attacks without authentication make immediate patching a critical requirement for organizations.
Details of the Critical Flaws
The security bulletin addresses three distinct vulnerabilities: CVE-2026-76197, CVE-2026-76195, and CVE-2026-76193. Each of these can be exploited remotely over a network without requiring any user interaction or credentials, leading to significant impacts on the confidentiality, integrity, and availability of affected systems.
CVE-2026-76197 and CVE-2026-76195 are classified as OS command injection vulnerabilities. These types of flaws occur when an application fails to properly sanitize or handle special characters and attacker-controlled input before passing it to an operating system command. A successful exploit would allow a threat actor to inject and execute arbitrary commands within the security context of the Adobe Campaign Classic process.
The third vulnerability, CVE-2026-76193, is a server-side request forgery (SSRF) flaw, categorized under CWE-918. SSRF vulnerabilities enable attackers to manipulate a server into making requests on their behalf. Depending on the application’s functionality and network configuration, this can potentially expose internal services, facilitate access to otherwise unreachable systems, or serve as a stepping stone in a broader attack chain leading to code execution. Adobe has rated this SSRF vulnerability as critical, noting its potential to also lead to arbitrary code execution.
Given that organizations leverage Adobe Campaign Classic for managing and automating multi-channel marketing campaigns, a compromise of an exposed or inadequately segmented deployment could have far-reaching implications. This includes unauthorized access to sensitive campaign data, connected infrastructure, credentials, and other internal network resources, extending risks beyond the application server itself.
Patching and Mitigation
Adobe has released Adobe Campaign Classic v7 7.4.4 build 9401 to remediate these critical issues. Administrators currently running build 9400 or any prior versions are strongly advised to upgrade to the patched build immediately. It is crucial to verify that all relevant Windows and Linux instances have been successfully updated.
The bulletin applies to fully on-premises deployments and the on-premises components of hybrid deployments. Adobe has confirmed that all Adobe-hosted instances have already been remediated, thus requiring no customer action for those specific deployments.
What You Should Do
- Apply Updates Immediately: Upgrade all affected on-premises Adobe Campaign Classic installations to version 7.4.4 build 9401 without delay.
- Verify Patch Installation: Confirm that the update has been successfully applied across all relevant Windows and Linux instances.
- Restrict Access: Limit access to Campaign Classic interfaces and restrict their exposure to only trusted networks.
- Monitor Logs: Regularly review application and host logs for any signs of abnormal process execution or unexpected outbound connections originating from Campaign Classic servers.
- Network Segmentation: Ensure robust network segmentation is in place to minimize the blast radius should a compromise occur.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.