TL;DR
Adobe patched three critical flaws in Adobe Campaign Classic on August 25, 2026. All three score a maximum CVSS 10.0 and allow arbitrary code execution. Adobe rates the update Priority 1, so on-premise admins should patch now.
- Product: Adobe Campaign Classic
- Vulnerabilities: 3 flaws (CVE-2026-76197, CVE-2026-76195, CVE-2026-76193)
- Highest severity: 10.0 (Critical · CVSSv3)
- Worst impact: (ACC) | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
- Status: No confirmed exploitation yet; patches available
- Action: Update to ACC v7: 7.4.4 build 9401 now
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-76197 | 10 | CWE-78 | ACC v7: 7.4.4 build 9401 | Not exploited |
| CVE-2026-76195 | 10 | CWE-78 | ACC v7: 7.4.4 build 9401 | Not exploited |
| CVE-2026-76193 | 10 | CWE-918 | ACC v7: 7.4.4 build 9401 | Not exploited |
Why This Adobe Campaign Classic Vulnerability Matters
Adobe Campaign Classic runs marketing and messaging campaigns for large brands. A break here exposes customer data and mail systems. Each Adobe Campaign Classic vulnerability in this batch earned a perfect 10.0 score.
That rating signals the worst case. Because attackers need no privileges and no user interaction, the risk is severe. As a result, Adobe assigned its top Priority 1 rating.
How the Attacks Work
Two flaws stem from OS command injection. Adobe says the update fixes issues that could result in arbitrary code execution.
The third is a server-side request forgery bug. All three carry the same critical impact.
The CVSS vector shows a network attack path with low complexity. Consequently, a remote attacker could run commands on an exposed server. The scope is marked as changed, which widens the potential damage.
Is It Being Exploited?
No exploitation in the wild has been confirmed. Adobe states it is not aware of any exploits in the wild
for these issues. Likewise, no public proof-of-concept exists yet.
Affected Versions
The flaws affect ACC v7 build 9400 and earlier, on Windows and Linux. The bulletin covers only on-premise deployments and the on-premise parts of hybrid setups. Adobe-hosted instances are already fixed.
Patch and Mitigation Steps
Update to ACC v7 7.4.4 build 9401 right away. Adobe’s APSB26-134 security bulletin lists the full details. On-premise customers must act, since no workaround is offered.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!