INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
| 2026-08-12 11:13 CRITICAL LOWExecutive Summary AI-generated
The latest incident data reveals a critical vulnerability in Adobe's ColdFusion and Campaign Classic software, with multiple severe flaws affecting various versions. These vulnerabilities have been identified as CVE-2026-48362 to CVE-2026-71384, all scoring 10 out of 11 on the CVSS scale, indicating high severity. The most significant flaw is an incorrect authorization vulnerability in Campaign Classic that could lead to arbitrary code execution and privilege escalation. This has prompted Adobe to release patches for these vulnerabilities, with a priority rating of 1, which refers to maximum-severity security flaws.
Technical Mitigations AI-generated
* Implement secure coding practices, such as input validation and sanitization, to prevent SQL injection and cross-site scripting (XSS) attacks.
* Regularly update and patch Adobe products, including ColdFusion, Commerce, Campaign Classic, and Bridge, to ensure you have the latest security fixes and patches.
* Use a web application firewall (WAF) or intrusion detection system (IDS) to monitor and block suspicious traffic and prevent unauthorized access to your website or application.
* Conduct regular security audits and penetration testing to identify vulnerabilities and weaknesses in your systems and applications, and implement remediation measures as needed.
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Campaign Classic FlawsCampaign Classic FlawsCampaign ClassicCampaign ClassicCampaign Classic CVSSCampaign Classic CVSSCampaign Classic
AdobeCampaign Classic
Adobe
CVE-2026-48374CVE-2026-48374
CVE-2026-48448CVE-2026-48448
CVE-2026-71384CVE-2026-71384
CVE-2026-48396CVE-2026-48396
CVE-2026-48390CVE-2026-48390
CVE-2026-48449CVE-2026-48449
CVE-2026-71362CVE-2026-71362
CVE-2026-48273CVE-2026-48273
CVE-2026-48393CVE-2026-48393
CVE-2026-48395CVE-2026-48395
CVE-2026-48392CVE-2026-48392
CVE-2026-48381CVE-2026-48381
CVE-2026-71398CVE-2026-71398
CVE-2026-48391CVE-2026-48391
CVE-2026-48362CVE-2026-48362
CVE-2026-27302CVE-2026-27302
CVE-2026-48394CVE-2026-48394
Target & Sectors
Global Scope
Incident Timeline
Aug 01, 2026
Threat actors exploited a vulnerability in Adobe Campaign Classic allowing them to execute arbitrary code without user interaction.
Aug 12, 2026
Threat actors exploited a vulnerability in Adobe Campaign Classic allowing them to execute arbitrary code without user interaction.
2026/08/12
Adobe has released security updates to address a maximum-severity vulnerability flaw in Adobe Campaign Classic that could result in arbitrary code execution.
Click on any entity below to view its context and source!
organisation
Vulnerability / Web Security
Ravie Lakshmanan
Aug 12, 2026
Vulnerability / Web Security
Adobe has
shipped updates
to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic that, if successfully exploited, could result in arbitrary code execution and privilege escalation.
organisation
Commerce
Ravie Lakshmanan
Aug 12, 2026
Vulnerability / Web Security
Adobe has
shipped updates
to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic that, if successfully exploited, could result in arbitrary code execution and privilege escalation.
infrastructure
2025.0.12
An incorrect authorization vulnerability in ColdFusion that could lead to an application denial-of-service (Fixed in 2025.0.12 and 2023.0.23)
CVE-2026-71362
(CVSS score: 9.1) - An incorrect authorization vulnerability in Commerce that could lead to privilege escalation
CVE-2026-71398
(CVSS score: 10.0) -
An operating system command injection vulnerability in ColdFusion that could lead to arbitrary code execution (Fixed in 2025.0.12 and 2023.0.23)
CVE-2026-48273
(CVSS score: 9.9) -
An eval injection vulnerability in ColdFusion that could lead to arbitrary code execution (Fixed in 2025.0.12 and 2023.0.23)
CVE-2026-71384
(CVSS score: 9.6) -
infrastructure
2023.0.23
An incorrect authorization vulnerability in ColdFusion that could lead to an application denial-of-service (Fixed in 2025.0.12 and 2023.0.23)
CVE-2026-71362
(CVSS score: 9.1) - An incorrect authorization vulnerability in Commerce that could lead to privilege escalation
CVE-2026-71398
(CVSS score: 10.0) -
An operating system command injection vulnerability in ColdFusion that could lead to arbitrary code execution (Fixed in 2025.0.12 and 2023.0.23)
CVE-2026-48273
(CVSS score: 9.9) -
An eval injection vulnerability in ColdFusion that could lead to arbitrary code execution (Fixed in 2025.0.12 and 2023.0.23)
CVE-2026-71384
(CVSS score: 9.6) -
infrastructure
9.1
An incorrect authorization vulnerability in ColdFusion that could lead to an application denial-of-service (Fixed in 2025.0.12 and 2023.0.23)
CVE-2026-71362
(CVSS score: 9.1) - An incorrect authorization vulnerability in Commerce that could lead to privilege escalation
CVE-2026-71398
(CVSS score: 10.0) -
infrastructure
10.0
An incorrect authorization vulnerability in ColdFusion that could lead to an application denial-of-service (Fixed in 2025.0.12 and 2023.0.23)
CVE-2026-71362
(CVSS score: 9.1) - An incorrect authorization vulnerability in Commerce that could lead to privilege escalation
CVE-2026-71398
(CVSS score: 10.0) -
An incorrect authorization vulnerability in Campaign Classic that could lead to arbitrary code execution (Fixed in ACC v7 7.4.4 build 9400)
CVE-2026-27302
(CVSS score: 10.0) -
The disclosure comes less than two weeks after Adobe
released
patches for a maximum-severity security flaw in Campaign Classic (CVE-2026-48449, CVSS score: 10.0) that could result in arbitrary code execution.
organisation
a Restricted Directory
Privilege escalation
Critical
8.2
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
CVE-2026-48390
Untrusted Search Path (
CWE-426
)
Arbitrary code execution
Critical
8.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
CVE-2026-48391
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)
organisation
Adobe
Separately, Adobe has also shipped updates to
remediate eight critical-rated flaws
in Adobe Bridge that could lead to privilege escalation and arbitrary code execution -
CVE-2026-48395
(CVSS score: 8.6) -
The disclosure comes less than two weeks after Adobe
released
patches for a maximum-severity security flaw in Campaign Classic (CVE-2026-48449, CVSS score: 10.0) that could result in arbitrary code execution.
Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform.
infrastructure
8.6
Separately, Adobe has also shipped updates to
remediate eight critical-rated flaws
in Adobe Bridge that could lead to privilege escalation and arbitrary code execution -
CVE-2026-48395
(CVSS score: 8.6) -
Adobe also fixed CVE-2026-48448 (CVSS score 8.6), a high-severity SQL injection flaw that could allow arbitrary file reads.
The update also resolves another high-severity flaw (
CVE-2026-48448
, CVSS score: 8.6) stemming from SQL injection that could pave the way for arbitrary file reads.
organisation
CVE-2026-48390
An incorrect authorization vulnerability that leads to arbitrary code execution
CVE-2026-48390
(CVSS score: 8.6) - An incorrect authorization vulnerability that leads to privilege escalation
CVE-2026-48391
(CVSS score: 8.2) - An untrusted search path vulnerability that leads to arbitrary code execution
CVE-2026-48374
(CVSS score: 7.8) - A path traversal vulnerability that leads to arbitrary code execution
CVE-2026-48392
(CVSS score: 7.8) - An out-of-bounds write vulnerability that leads to arbitrary code execution
CVE-2026-48393
(CVSS score: 7.8) -
organisation
CVE-2026-48392
An incorrect authorization vulnerability that leads to arbitrary code execution
CVE-2026-48390
(CVSS score: 8.6) - An incorrect authorization vulnerability that leads to privilege escalation
CVE-2026-48391
(CVSS score: 8.2) - An untrusted search path vulnerability that leads to arbitrary code execution
CVE-2026-48374
(CVSS score: 7.8) - A path traversal vulnerability that leads to arbitrary code execution
CVE-2026-48392
(CVSS score: 7.8) - An out-of-bounds write vulnerability that leads to arbitrary code execution
CVE-2026-48393
(CVSS score: 7.8) -
organisation
CVE-2026-48393
An incorrect authorization vulnerability that leads to arbitrary code execution
CVE-2026-48390
(CVSS score: 8.6) - An incorrect authorization vulnerability that leads to privilege escalation
CVE-2026-48391
(CVSS score: 8.2) - An untrusted search path vulnerability that leads to arbitrary code execution
CVE-2026-48374
(CVSS score: 7.8) - A path traversal vulnerability that leads to arbitrary code execution
CVE-2026-48392
(CVSS score: 7.8) - An out-of-bounds write vulnerability that leads to arbitrary code execution
CVE-2026-48393
(CVSS score: 7.8) -
infrastructure
7.4.4
An incorrect authorization vulnerability in Campaign Classic that could lead to arbitrary code execution (Fixed in ACC v7 7.4.4 build 9400)
CVE-2026-27302
(CVSS score: 10.0) -
An incorrect authorization vulnerability in Campaign Classic that could lead to arbitrary code execution (Fixed in ACC v7 7.4.4 build 9400)
CVE-2026-48381
(CVSS score: 9.0) -
An SQL injection vulnerability in Campaign Classic that could lead to arbitrary code execution (Fixed in ACC v7 7.4.4 build 9400)
organisation
ACC
An incorrect authorization vulnerability in Campaign Classic that could lead to arbitrary code execution (Fixed in ACC v7 7.4.4 build 9400)
CVE-2026-27302
(CVSS score: 10.0) -
Ravie Lakshmanan
Aug 01, 2026
Vulnerability / Enterprise Security
Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution.
infrastructure
9.0
An incorrect authorization vulnerability in Campaign Classic that could lead to arbitrary code execution (Fixed in ACC v7 7.4.4 build 9400)
CVE-2026-48381
(CVSS score: 9.0) -
organisation
SQL
An SQL injection vulnerability in Campaign Classic that could lead to arbitrary code execution (Fixed in ACC v7 7.4.4 build 9400)
Adobe also fixed CVE-2026-48448 (CVSS score 8.6), a high-severity SQL injection flaw that could allow arbitrary file reads.
The update also resolves another high-severity flaw (
CVE-2026-48448
, CVSS score: 8.6) stemming from SQL injection that could pave the way for arbitrary file reads.
organisation
CVSS
The disclosure comes less than two weeks after Adobe
released
patches for a maximum-severity security flaw in Campaign Classic (CVE-2026-48449, CVSS score: 10.0) that could result in arbitrary code execution.
Adobe also fixed CVE-2026-48448 (CVSS score 8.6), a high-severity SQL injection flaw that could allow arbitrary file reads.
The vulnerability, tracked as
CVE-2026-48449
, carries a severity score of 10.0 on the CVSS scoring system.
organisation
Adobe Campaign Classic
Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform.
infrastructure
Windows
Both vulnerabilities are patched in Adobe Campaign Classic v7.4.3 build 9398 for Windows and Linux.
Both shortcomings have been addressed in ACC v7: 7.4.3 build 9398 for Windows and Linux.
infrastructure
Linux
Both vulnerabilities are patched in Adobe Campaign Classic v7.4.3 build 9398 for Windows and Linux.
Both shortcomings have been addressed in ACC v7: 7.4.3 build 9398 for Windows and Linux.
infrastructure
4.3
Both vulnerabilities are patched in Adobe Campaign Classic v7.4.3 build 9398 for Windows and Linux.
organisation
Adobe Campaign Classic v7.4.3
Both vulnerabilities are patched in Adobe Campaign Classic v7.4.3 build 9398 for Windows and Linux.
organisation
SecurityAffairs
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, Campaign Classic)
organisation
Vulnerability / Enterprise Security
Adobe
Ravie Lakshmanan
Aug 01, 2026
Vulnerability / Enterprise Security
Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution.
infrastructure
9.9
An operating system command injection vulnerability in ColdFusion that could lead to arbitrary code execution (Fixed in 2025.0.12 and 2023.0.23)
CVE-2026-48273
(CVSS score: 9.9) -
organisation
CVE-2026
An operating system command injection vulnerability in ColdFusion that could lead to arbitrary code execution (Fixed in 2025.0.12 and 2023.0.23)
CVE-2026-48273
(CVSS score: 9.9) -
Arbitrary code execution
Critical
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2026-48394
Researcher Kieran (kaiksi) disclosed the flaws CVE-2026-48390, CVE-2026-48391, CVE-2026-48395, CVE-2026-48396, and CVE-2026-48374, while the researcher yjdfy reported the vulnerabilities CVE-2026-48392, CVE-2026-48393, and CVE-2026-48394.
An untrusted search path vulnerability that leads to arbitrary code execution
CVE-2026-48396
(CVSS score: 8.6) -
organisation
CVE-2026-71384
An eval injection vulnerability in ColdFusion that could lead to arbitrary code execution (Fixed in 2025.0.12 and 2023.0.23)
CVE-2026-71384
(CVSS score: 9.6) -
infrastructure
9.6
An eval injection vulnerability in ColdFusion that could lead to arbitrary code execution (Fixed in 2025.0.12 and 2023.0.23)
CVE-2026-71384
(CVSS score: 9.6) -
organisation
ColdFusion
Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws.
organisation
Adobe Campaign Classic CVSS
Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction.
organisation
CVE-2026-48448
Adobe also fixed CVE-2026-48448 (CVSS score 8.6), a high-severity SQL injection flaw that could allow arbitrary file reads.
infrastructure
7.4.3
Both shortcomings have been addressed in ACC v7: 7.4.3 build 9398 for Windows and Linux.
organisation
Adobe Bridge
Adobe also released updates for Adobe Bridge, fixing
eight critical vulnerabilities
that could allow attackers to execute arbitrary code or escalate privileges.
organisation
Vulnerability Category
Vulnerability
Below is the list of the flaws:
Vulnerability Category
Vulnerability Impact
Severity
CVSS base score
CVSS vector
CVE Number
Untrusted Search Path (
CWE-426
)
Tactical Metrics
Metrics
infrastructure
2025.0.12
Software Version
Click for context!
An incorrect authorization vulnerability in ColdFusion that could lead to an application denial-of-service (Fixed in 2025.0.12 and 2023.0.23)
CVE-2026-71362
(CVSS score: 9.1) - An incorrect authorization vulnerability in Commerce that could lead to privilege escalation
CVE-2026-71398
(CVSS score: 10.0) -
An operating system command injection vulnerability in ColdFusion that could lead to arbitrary code execution (Fixed in 2025.0.12 and 2023.0.23)
CVE-2026-48273
(CVSS score: 9.9) -
An eval injection vulnerability in ColdFusion that could lead to arbitrary code execution (Fixed in 2025.0.12 and 2023.0.23)
CVE-2026-71384
(CVSS score: 9.6) -
Metrics
infrastructure
2023.0.23
Software Version
An incorrect authorization vulnerability in ColdFusion that could lead to an application denial-of-service (Fixed in 2025.0.12 and 2023.0.23)
CVE-2026-71362
(CVSS score: 9.1) - An incorrect authorization vulnerability in Commerce that could lead to privilege escalation
CVE-2026-71398
(CVSS score: 10.0) -
An operating system command injection vulnerability in ColdFusion that could lead to arbitrary code execution (Fixed in 2025.0.12 and 2023.0.23)
CVE-2026-48273
(CVSS score: 9.9) -
An eval injection vulnerability in ColdFusion that could lead to arbitrary code execution (Fixed in 2025.0.12 and 2023.0.23)
CVE-2026-71384
(CVSS score: 9.6) -
Metrics
infrastructure
9.1
Software Version
An incorrect authorization vulnerability in ColdFusion that could lead to an application denial-of-service (Fixed in 2025.0.12 and 2023.0.23)
CVE-2026-71362
(CVSS score: 9.1) - An incorrect authorization vulnerability in Commerce that could lead to privilege escalation
CVE-2026-71398
(CVSS score: 10.0) -
Metrics
infrastructure
10.0
Software Version
An incorrect authorization vulnerability in ColdFusion that could lead to an application denial-of-service (Fixed in 2025.0.12 and 2023.0.23)
CVE-2026-71362
(CVSS score: 9.1) - An incorrect authorization vulnerability in Commerce that could lead to privilege escalation
CVE-2026-71398
(CVSS score: 10.0) -
An incorrect authorization vulnerability in Campaign Classic that could lead to arbitrary code execution (Fixed in ACC v7 7.4.4 build 9400)
CVE-2026-27302
(CVSS score: 10.0) -
The disclosure comes less than two weeks after Adobe
released
patches for a maximum-severity security flaw in Campaign Classic (CVE-2026-48449, CVSS score: 10.0) that could result in arbitrary code execution.
Metrics
infrastructure
9.9
Software Version
An operating system command injection vulnerability in ColdFusion that could lead to arbitrary code execution (Fixed in 2025.0.12 and 2023.0.23)
CVE-2026-48273
(CVSS score: 9.9) -
Metrics
infrastructure
9.6
Software Version
An eval injection vulnerability in ColdFusion that could lead to arbitrary code execution (Fixed in 2025.0.12 and 2023.0.23)
CVE-2026-71384
(CVSS score: 9.6) -
Metrics
infrastructure
7.4.4
Software Version
An incorrect authorization vulnerability in Campaign Classic that could lead to arbitrary code execution (Fixed in ACC v7 7.4.4 build 9400)
CVE-2026-27302
(CVSS score: 10.0) -
An incorrect authorization vulnerability in Campaign Classic that could lead to arbitrary code execution (Fixed in ACC v7 7.4.4 build 9400)
CVE-2026-48381
(CVSS score: 9.0) -
An SQL injection vulnerability in Campaign Classic that could lead to arbitrary code execution (Fixed in ACC v7 7.4.4 build 9400)
Metrics
infrastructure
9.0
Software Version
An incorrect authorization vulnerability in Campaign Classic that could lead to arbitrary code execution (Fixed in ACC v7 7.4.4 build 9400)
CVE-2026-48381
(CVSS score: 9.0) -
Metrics
infrastructure
8.6
Software Version
Adobe also fixed CVE-2026-48448 (CVSS score 8.6), a high-severity SQL injection flaw that could allow arbitrary file reads.
Separately, Adobe has also shipped updates to
remediate eight critical-rated flaws
in Adobe Bridge that could lead to privilege escalation and arbitrary code execution -
CVE-2026-48395
(CVSS score: 8.6) -
The update also resolves another high-severity flaw (
CVE-2026-48448
, CVSS score: 8.6) stemming from SQL injection that could pave the way for arbitrary file reads.
Metrics
infrastructure
Windows
Affected Product
Both vulnerabilities are patched in Adobe Campaign Classic v7.4.3 build 9398 for Windows and Linux.
Both shortcomings have been addressed in ACC v7: 7.4.3 build 9398 for Windows and Linux.
Metrics
infrastructure
Linux
Affected Product
Both vulnerabilities are patched in Adobe Campaign Classic v7.4.3 build 9398 for Windows and Linux.
Both shortcomings have been addressed in ACC v7: 7.4.3 build 9398 for Windows and Linux.
Metrics
infrastructure
4.3
Software Version
Both vulnerabilities are patched in Adobe Campaign Classic v7.4.3 build 9398 for Windows and Linux.
Metrics
infrastructure
7.4.3
Software Version
Both shortcomings have been addressed in ACC v7: 7.4.3 build 9398 for Windows and Linux.
Intelligence Sources
Security Affairs
2026-08-01
The Hacker News
2026-08-01
The Hacker News
2026-08-12
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Reset / Delete
Incident Version History
CURRENT VERSION
Last Updated: 2026-08-13T06:34
Comprehensive Tactical Telemetry
Highly Correlated Entities
21x
organisation
Identified Entity
Vulnerability / Web Security
entity
17x
vulnerability
Exploited CVE
CVE-2026-71362
cve
11x
infrastructure
Software Version
2025.0.12
version
4x
campaign
Campaign
Campaign Classic
operation
3x
timeline
Temporal Reference
2026
date
2x
general metric
Aug
12
aug
2x
vulnerability
CVSS Score
10
score
2x
general metric
Arbitrary Code Execution
10
arbitrary code execution
2x
general metric
Critical Av
8
critical av
2x
infrastructure
Affected Product
Windows
software
Contextual Telemetry
Context Block
6 METRICS
tactic
Cyber Operation Type
Privilege Escalation
tactic
general metric
Incorrect Authorization Vulnerability
9
incorrect authorization vulnerability
general metric
Score
9
score
general metric
Rating
1
rating
general metric
Hours
72
hours
general metric
Cvss Score
9
cvss score
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.