TL;DR
Adobe patched two critical flaws in Adobe Campaign Classic on July 29, 2026. The worst, CVE-2026-48449, scores a perfect CVSS 10.0 and allows arbitrary code execution. A second bug, CVE-2026-48448, lets attackers read files on the server. Adobe reports no exploits in the wild so far.
- Product: Adobe Campaign Classic
- Vulnerabilities: 2 flaws (CVE-2026-48449, CVE-2026-48448)
- Highest severity: 10.0 (Critical · CVSSv3)
- Worst impact: (ACC) | Incorrect Authorization (CWE-863)
- Status: No confirmed exploitation yet; patches available
- Action: Update to 7.4.3 build 9398 now
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-48449 | 10 | CWE-863 | 7.4.3 build 9398 | Not exploited |
| CVE-2026-48448 | 8.6 | CWE-89 | 7.4.3 build 9398 | Not exploited |
Why it matters
Adobe Campaign Classic runs marketing and email campaigns for large organizations. A CVSS 10.0 rating is as severe as a flaw gets. CVE-2026-48449 needs no privileges and no user interaction. As a result, an attacker with network access could run code on an unpatched server.
How the attack works
CVE-2026-48449 stems from incorrect authorization. In short, the software fails to check permissions correctly. An attacker can bypass those checks and reach protected functions. That access then leads to arbitrary code execution in the current user’s context. The second flaw, CVE-2026-48448, is a SQL injection issue. According to Adobe, it enables “arbitrary file system read,” which can expose sensitive data.
Affected versions
The bugs affect Adobe Campaign Classic v7, build 7.4.3.9397 and earlier, on Windows and Linux.
Patch and mitigation
Adobe fixed both flaws in ACC v7 build 7.4.3.9398. The update carries Priority 1, Adobe’s most urgent rating. Therefore, admins should apply it right away. You can review the full Adobe advisory for version details. Adobe also states it is “not aware of any exploits in the wild” for these issues.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.