TL;DR
Adobe published a Priority 1 security update for Adobe Campaign Classic. The patch resolves seven severe flaws, including three bugs with a CVSS score of 10.0. Consequently, attackers can exploit these issues to achieve arbitrary code execution on vulnerable servers.
- Total: 7 CVEs
- Severity: 6 Critical · 1 High
- Actively exploited: None confirmed
- Highest severity: 10.0 (Critical · CVSSv3) — CVE-2026-48331
- Action: Apply the latest security updates now
Notable CVEs
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-48331 | 10 | CWE-918 | ACC v7: 7.4.3 build 9399 | Not exploited |
| CVE-2026-48323 | 10 | CWE-1336 | ACC v7: 7.4.3 build 9399 | Not exploited |
| CVE-2026-48330 | 10 | CWE-89 | ACC v7: 7.4.3 build 9399 | Not exploited |
| CVE-2026-48326 | 9.9 | CWE-89 | ACC v7: 7.4.3 build 9399 | Not exploited |
| CVE-2026-48333 | 9.8 | CWE-863 | ACC v7: 7.4.3 build 9399 | Not exploited |
| CVE-2026-48317 | 9.6 | CWE-95 | ACC v7: 7.4.3 build 9399 | Not exploited |
| CVE-2026-48399 | 7.5 | CWE-657 | ACC v7: 7.4.3 build 9399 | Not exploited |
Why It Matters
Marketing departments rely heavily on automation platforms to manage customer data. Therefore, these arbitrary code execution vulnerabilities place enterprise networks at extreme risk. A successful breach grants threat actors full control over the underlying infrastructure. Furthermore, attackers could steal sensitive marketing databases or pivot to other connected systems. The vendor notes, “Adobe is not aware of any exploits in the wild for any of the issues addressed in these updates.” However, the high severity scores demand immediate action.
How the Attacks Work
Threat actors can trigger these critical flaws without prior authentication. For example, the Server-Side Request Forgery bug (CVE-2026-48331) allows attackers to force the server to issue unauthorized requests. Similarly, two separate SQL injection flaws enable attackers to send malicious database queries. Additionally, CVE-2026-48323 involves improper neutralization of special elements within a template engine. By supplying crafted inputs, an attacker forces the application to evaluate malicious code. Ultimately, these weaknesses collectively provide multiple pathways to complete system compromise, enabling arbitrary code execution.
Affected Versions
This security bulletin applies to Adobe Campaign Classic v7 on both Windows and Linux platforms. Specifically, installations running version 7.4.3 build 9398 and earlier contain these flaws. Administrators should verify their current version immediately.
Patch and Mitigation Steps
Adobe categorizes this release with a Priority 1 rating. Consequently, administrators must upgrade their vulnerable instances to ACC v7 7.4.3 build 9399. Applying this patch removes the arbitrary code execution threats entirely. Finally, organizations should review the official documentation and install the security update for Adobe Campaign Classic to secure their deployments.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.