live markets
S&P 5006,389.45▲ 0.42%NASDAQ21,102.30▲ 0.61%DOW44,812.10▼ 0.18%GOLD3,412.80▲ 0.35%WTI CRUDE68.42▼ 1.12%BRENT72.18▼ 0.94%EUR/USD1.0842▲ 0.08%GBP/USD1.3391▼ 0.05%JPY/USD0.0068▲ 0.11%NAT GAS3.12▲ 0.74%
pulseofnations.
Sat, Aug 1 2026 — 10:29 UTC telegram ↗ Join the wire

Adobe Patches CVSS 10.0 Flaw in Campaign Classic Platform

Adobe shipped urgent fixes for a maximum-severity Campaign Classic flaw allowing code execution without user interaction, plus critical Bridge bugs.

Adobe has released security updates to address a maximum-severity vulnerability in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution without any user interaction.

The flaw, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system, the maximum possible rating. Adobe described it as a case of incorrect authorization that could allow arbitrary code execution in the context of the current user, with no user interaction required to trigger it. The same update also resolves a second high-severity bug, CVE-2026-48448 (CVSS 8.6), a SQL injection flaw that could enable arbitrary file reads on affected systems.

“This update addresses critical vulnerabilities that could result in arbitrary code execution and arbitrary file system read,” Adobe said in its advisory. The company said it is not aware of either flaw being exploited in the wild. Both shortcomings have been addressed in ACC v7: 7.4.3 build 9398 for Windows and Linux.

Campaign Classic is Adobe’s legacy enterprise marketing platform, used by large organizations to run email, mobile and cross-channel campaigns. A CVSS 10.0 rating is reserved for vulnerabilities that require no privileges, no user interaction and carry a critical security impact, making this one of the most severe flaws Adobe has disclosed in the product in recent years. Marketing automation platforms are attractive targets for attackers because they often sit adjacent to customer databases, CRM systems and other sensitive infrastructure.

Separately, Adobe also shipped updates to remediate eight critical-rated flaws in Adobe Bridge that could lead to privilege escalation and arbitrary code execution. Adobe credited security researcher Kieran (“kaiksi”) with discovering and reporting CVE-2026-48390, CVE-2026-48391, CVE-2026-48395, CVE-2026-48396 and CVE-2026-48374, and “yjdfy” for CVE-2026-48392, CVE-2026-48393 and CVE-2026-48394.

The patches arrive as Adobe continues an aggressive security update cadence amid heightened scrutiny of enterprise software supply chains. For organizations running Campaign Classic, the combination of a maximum severity score and the lack of any user interaction requirement means the update should be treated as urgent. In network-exposed configurations, the flaw could in principle be exploited by remote attackers without any action from the victim, security analysts noted.

Security teams are advised to apply the latest updates for optimal protection and to inventory any instances of Campaign Classic or Adobe Bridge still running older builds. Adobe did not disclose a timeline for when the flaws were discovered, but urged customers to move to the patched builds as soon as possible.

Sources: The Hacker News, Adobe Security Advisory APSB26-114, Adobe Security Advisory APSB26-89

Author: Technology Desk

React to this dispatch
Share this dispatch Telegram X WhatsApp

discussion

Join the discussion

Your email address will not be published. Required fields are marked *