Securityaffairs.Co
Critical Adobe Campaign Classic Vulnerability CVE-2026-48449 Disclosed
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Adobe has patched a critical vulnerability in Campaign Classic, tracked as CVE-2026-48449, which allows unauthenticated attackers to execute arbitrary code remotely without user interaction. The flaw, rated with a CVSS score of 10.0, affects on-premise builds up to version 7.4.3 build 9397. The vulnerability is due to incorrect authorization, enabling attackers to gain access to sensitive customer data and potentially launch phishing attacks from a trusted platform. Adobe has classified this as a Priority 1 advisory, urging administrators to apply the patch (build 9398) within 72 hours of its release on July 29, 2026. The impact is significant, as compromised Campaign Classic servers can expose customer databases and legitimate email-sending capabilities. This vulnerability is particularly concerning for organizations relying on Adobe's marketing automation tools.
Key Points: • CVE-2026-48449 has a CVSS score of 10.0, indicating maximum severity. • The vulnerability allows remote code execution without user interaction, affecting on-premise builds up to 7.4.3. • Adobe has classified the advisory as Priority 1, urging immediate patching within 72 hours.