CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Adobe Patches Critical Campaign Classic Flaw Allowing Code Execution Without User Interaction

August 1, 2026

Adobe has released security updates to address a maximum-severity vulnerability in Campaign Classic (ACC), its enterprise marketing automation platform. The flaw, tracked as CVE-2026-48449, carries a CVSS score of 10.0 and stems from an incorrect authorization issue that could allow arbitrary code execution in the context of the current user without requiring any user interaction.

The update also resolves a high-severity SQL injection vulnerability (CVE-2026-48448, CVSS 8.6) that could lead to arbitrary file reads. Adobe stated it is not aware of any active exploitation of these flaws. Both issues are fixed in ACC v7: 7.4.3 build 9398 for Windows and Linux.

In addition, Adobe shipped patches for eight critical-rated vulnerabilities in Adobe Bridge, including issues leading to privilege escalation and arbitrary code execution. These include CVE-2026-48395, CVE-2026-48396, CVE-2026-48390, CVE-2026-48391, CVE-2026-48374, CVE-2026-48392, CVE-2026-48393, and CVE-2026-48394, with CVSS scores ranging from 7.8 to 8.6. The vulnerabilities cover untrusted search paths, incorrect authorization, path traversal, and out-of-bounds writes.

Adobe credited security researchers Kieran (“kaiksi”) and “yjdfy” for reporting these issues. Users are strongly advised to apply the latest updates to protect their systems.

CVEs: CVE-2026-48449, CVE-2026-48448, CVE-2026-48395, CVE-2026-48396, CVE-2026-48390, CVE-2026-48391, CVE-2026-48374, CVE-2026-48392, CVE-2026-48393, CVE-2026-48394, CVE-2026-50522

Companies: Adobe

Products: Adobe Campaign Classic, Adobe Bridge