VMTech
Discuss a project

Adobe patches CVSS 10.0 Campaign Classic flaw and eight Bridge vulnerabilities

Adobe patches CVSS 10.0 Campaign Classic flaw and eight Bridge vulnerabilities

On August 1, 2026, Adobe released security updates for two Adobe Campaign Classic vulnerabilities. CVE-2026-48449 carries the maximum CVSS score of 10.0 and can allow arbitrary code execution without user interaction, while CVE-2026-48448 is rated 8.6.

Why the Campaign Classic flaws demand attention

Campaign Classic is an enterprise marketing automation platform, so a compromise may affect systems involved in customer communications and campaign operations. CVE-2026-48449 stems from incorrect authorization and permits code execution in the context of the current user.

CVE-2026-48448 is a SQL injection vulnerability that can lead to arbitrary file reads. Although its score is lower, access to files on an application host may expose sensitive data or provide useful information for further intrusion.

Patched versions and additional Adobe Bridge fixes

Adobe resolved both Campaign Classic issues in ACC v7 version 7.4.3 build 9398 for Windows and Linux. The company said it was not aware of either vulnerability being exploited in the wild when the advisory was issued.

“This update addresses critical vulnerabilities that could result in arbitrary code execution and arbitrary file system read,” Adobe said.

Adobe also shipped updates for eight Adobe Bridge vulnerabilities associated with arbitrary code execution or privilege escalation. CVE-2026-48395, CVE-2026-48396 and CVE-2026-48390 score 8.6; CVE-2026-48391 scores 8.2; and CVE-2026-48374, CVE-2026-48392, CVE-2026-48393 and CVE-2026-48394 each score 7.8.

The Bridge issues include untrusted search paths, incorrect authorization, path traversal and out-of-bounds writes. Security researcher Kieran, also known as “kaiksi,” reported five of them, while “yjdfy” reported the three out-of-bounds write flaws.

For businesses running Campaign Classic, the practical priority is to inventory every deployment, upgrade it to build 9398 and confirm that the corrected binaries are active on both Windows and Linux hosts. Teams should also review access and application logs rather than treating the absence of known exploitation as evidence that patching can wait.

#adobe#cybersecurity#vulnerability#patchmanagement
Open analytics
On the site 0 views
min read 2 01.08.2026
Instagram

Adobe patches CVSS 10.0 Campaign Classic flaw and eight Bridge vulnerabilities

Open the post on Instagram ↗