Adobe has released a critical security update for Adobe Campaign Classic to address multiple high-severity vulnerabilities that could allow attackers to execute arbitrary code and access sensitive data through unauthorized file system reads.
This advisory, tracked as APSB26-114 and published on July 29, 2026, has a priority rating of 1, indicating the highest level of urgency for patching.
Critical Adobe Campaign Flaw
The vulnerabilities affect Adobe Campaign Classic v7.4.3 build 9397 and earlier versions on both Windows and Linux platforms, with a specific impact on fully on-premise deployments and the on-premise components of hybrid environments.
Adobe has confirmed that its hosted instances have already been remediated, reducing exposure for cloud-managed customers.
The most critical issue, tracked as CVE-2026-48449, is an incorrect authorization vulnerability (CWE-863) with a maximum CVSS score of 10.0.
This flaw could allow unauthenticated attackers to execute arbitrary code remotely without requiring user interaction, making it particularly dangerous in exposed environments.
The vulnerability is classified under the CVSS vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, indicating network-based exploitation with low attack complexity and high impact across confidentiality, integrity, and availability.
Successful exploitation could enable full system compromise, allowing attackers to deploy malware, establish persistence, or pivot within enterprise networks.
A second critical vulnerability, CVE-2026-48448, involves improper neutralization of special elements in SQL commands (CWE-89), commonly known as SQL Injection. This flaw carries a CVSS score of 8.6 and could allow attackers to perform arbitrary file system reads.
The vector for this issue is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N, which enables remote exploitation without authentication and could expose sensitive configuration files, credentials, or internal data structures.
While it does not directly impact system integrity or availability, the confidentiality risks are significant, especially in environments that handle customer data and marketing automation workflows.
Adobe has stated that it is not aware of any active exploitation in the wild at the time of disclosure; however, given the critical nature of these vulnerabilities and the detailed advisory information available, rapid weaponization is likely.
Threat actors often target enterprise campaign management systems because they integrate with customer databases, email infrastructure, and internal business logic.
To mitigate risks, Adobe has released an updated version, Adobe Campaign Classic v7.4.3 build 9398, and strongly recommends immediate patching.
Organizations running on-premises deployments should prioritize upgrading their instances and thoroughly review system access logs for suspicious activity.
Additional defensive measures include restricting external access to campaign servers, implementing network segmentation, and applying web application firewall (WAF) rules to detect exploitation attempts.
Security teams should also monitor indicators such as unusual SQL queries, unauthorized file access patterns, and unexpected process execution within campaign servers.
Given the critical CVSS score and the lack of required privileges, these vulnerabilities represent a high-value target for attackers seeking initial access into enterprise environments.
ALERT: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposure.





