Adobe has released an emergency update for Campaign Classic after discovering two critical vulnerabilities. The most dangerous flaw carries a maximum CVSS score of 10.0. It allows arbitrary code execution without any prior authentication or user interaction. The fix targets on-premises installations of the platform on both Windows and Linux.
Campaign Classic: Two Critical Flaws
Large enterprises rely on Adobe Campaign Classic to manage marketing campaigns, mass mailings, and customer data. Version 7.4.3 build 9397 and all earlier ACC v7 releases are vulnerable. Adobe closed both flaws in version 7.4.3 build 9398, assigning the update its highest internal priority rating, as detailed in security bulletin APSB26-114.
CVE-2026-48449 CVSS 10.0: Improper Authorisation
Campaign Classic does not verify strictly enough whether a requested operation is permitted. An attacker can therefore bypass the intended restrictions and execute arbitrary code.
The perfect CVSS score reflects several compounding factors. The attack travels over the network. It requires no account, no complex preconditions, and no user interaction. A successful exploit can compromise confidentiality, integrity, and availability.
In this context, authorisation means checking access rights, not confirming identity with a password. The system may correctly identify the requester yet still allow an action for which that requester holds no privilege. Adobe has not disclosed the technical exploitation scenario or specified which Campaign Classic components harbour the flaw.
CVE-2026-48448 CVSS 8.6: SQL Injection
The second vulnerability stems from improper handling of special elements inside SQL commands. An attacker can inject crafted query fragments into database commands and achieve arbitrary file reads on the file system.
SQL injection arises when a program mixes user-supplied data with database commands without properly separating the two. Specially prepared input reshapes the query, and the server then executes more than the developers intended. For CVE-2026-48448, the consequence is file reading rather than direct code execution or data modification.
Exploitation likewise needs no account or user action. The attack runs over the network at low complexity, though it does not directly affect system integrity or availability, which accounts for the lower score.
Scope and Deployment
The bulletin covers only fully on-premises Campaign Classic installations and on-premises components of hybrid configurations. Adobe has already updated instances hosted on its own infrastructure. Cloud-hosted customers need take no action.
Adobe has found no evidence that either vulnerability has been exploited in the wild. Even so, it urges administrators of on-premises servers to install build 9398 without waiting for public exploit code to appear.
Adobe Bridge: Eight Critical Vulnerabilities
Alongside the Campaign Classic patch, Adobe closed eight critical flaws in Bridge, the application used to browse, organise, and process photographs, video, and other media. The bugs allow privilege escalation or arbitrary code execution. Adobe Bridge 15.1.6 LTS, 16.0.5, and all earlier versions on Windows and macOS are affected. The fixes ship in releases 15.1.7 LTS and 16.0.6.
CVE-2026-48395 and CVE-2026-48391: Insecure Search Path
Both flaws carry high scores (8.6 and 8.2 respectively). When loading a required component, Bridge may look beyond trusted system directories and reach a file planted by an attacker. The result is arbitrary code execution. CVE-2026-48391 differs in that the attacker already needs limited local privileges.
CVE-2026-48396: Improper Authorisation (CVSS 8.6)
An authorisation error enables arbitrary code execution following a local attack. User interaction is required, but elevated privileges beforehand are not.
CVE-2026-48390: Privilege Escalation (CVSS 8.2)
Improper privilege verification lets an attacker gain rights that the original process or user should never hold. Local access and user interaction are needed, yet no initial privileges are required.
CVE-2026-48374: Path Traversal (CVSS 7.8)
Insufficient path validation lets an attacker escape the directory to which Bridge should restrict access. This can lead to arbitrary code execution.
CVE-2026-48392, CVE-2026-48393, CVE-2026-48394: Out-of-Bounds Write (CVSS 7.8 Each)
Bridge writes data beyond its allocated buffer, corrupting adjacent memory regions. Successful exploitation grants arbitrary code execution. Each flaw requires local access and user interaction but no prior privileges.
Key Differences and Remediation
The Bridge vulnerabilities differ sharply from the Campaign Classic flaws in how they are exploited. Campaign Classic can be attacked over the network with no user involvement. Every Bridge issue, by contrast, requires a local vector and user action. Adobe has not reported active exploitation of any of the Bridge flaws.
Bridge updates carry the third priority level. Adobe recommends installing version 15.1.7 LTS or 16.0.6 through the Creative Cloud desktop application. Campaign Classic administrators should separately verify their on-premises and hybrid configurations and update server components to build 9398.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.