Critical Adobe Campaign Classic Vulnerability CVE-2026-48449 Disclosed

Critical Adobe Campaign Classic Vulnerability CVE-2026-48449 Disclosed

First seen 2 Aug 2026, 08:53 UTC Securityaffairs.CoInnovationnetworkdesignwww.tenable.com 78% similarity 79.5

Article Content

Browse articles
ThreatCluster

Adobe has patched a critical vulnerability in Campaign Classic, tracked as CVE-2026-48449, which allows unauthenticated attackers to execute arbitrary code remotely without user interaction. The flaw, rated with a CVSS score of 10.0, affects on-premise builds up to version 7.4.3 build 9397. The vulnerability is due to incorrect authorization, enabling attackers to gain access to sensitive customer data and potentially launch phishing attacks from a trusted platform. Adobe has classified this as a Priority 1 advisory, urging administrators to apply the patch (build 9398) within 72 hours of its release on July 29, 2026. The impact is significant, as compromised Campaign Classic servers can expose customer databases and legitimate email-sending capabilities. This vulnerability is particularly concerning for organizations relying on Adobe's marketing automation tools.

Key Points: • CVE-2026-48449 has a CVSS score of 10.0, indicating maximum severity. • The vulnerability allows remote code execution without user interaction, affecting on-premise builds up to 7.4.3. • Adobe has classified the advisory as Priority 1, urging immediate patching within 72 hours.

ThreatCluster AI How this analysis works

Timeline

2026-06-30
CVE-2026-48286 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-29
Adobe releases patch for CVE-2026-48449
Adobe issued a patch to address a critical vulnerability in Campaign Classic, urging immediate updates.
Innovationnetworkdesign
2026-07-30
CVE-2026-48449 published
The vulnerability was officially published, detailing the risk of arbitrary code execution due to incorrect authorization.
Tenable
2026-07-30
CVE-2026-48448 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-01
Adobe confirms critical flaw in Campaign Classic
Adobe acknowledged the maximum severity vulnerability, emphasizing the urgency for organizations to patch.
Securityaffairs.Co

Community

Browse all →

Tracked Entities in This Story