Mastodon Mastodon Mastodon Mastodon

Urgent Updates for Adobe Campaign Classic and Bridge

Photo of author

CyberSecureFox Editorial Team

Published:

Adobe has released security updates that address the maximum‑severity vulnerability CVE-2026-48449 (CVSS 10.0) in the marketing automation platform Adobe Campaign Classic (ACC). The vulnerability allows arbitrary code execution in the context of the current user without any user interaction. At the same time, the company also fixed another serious flaw in ACC and eight critical vulnerabilities in Adobe Bridge. Organizations using these products need to apply the updates immediately — patches are available for both Windows and Linux.

Vulnerabilities in Adobe Campaign Classic

The main threat — CVE-2026-48449 — is classified as an Incorrect Authorization issue. A score of CVSS 10.0 out of 10.0 represents the highest possible severity level: exploitation does not require user interaction and results in arbitrary code execution. According to security bulletin APSB26-114, Adobe is not aware of this vulnerability being exploited in real‑world attacks; however, its characteristics make it an extremely attractive target for attackers.

The second vulnerability that was fixed — CVE-2026-48448 (CVSS 8.6) — is an SQL injection that enables arbitrary file reads from the file system. Combined with the first vulnerability, this creates a dangerous scenario: an attacker could potentially first gain access to confidential data through file reads and then achieve full code execution.

Both vulnerabilities are remediated in ACC v7: 7.4.3 build 9398 for Windows and Linux. NVD entries are available for CVE-2026-48449 and CVE-2026-48448.

Eight critical vulnerabilities in Adobe Bridge

In a separate update, Adobe fixed eight critical‑severity vulnerabilities in Adobe Bridge, a digital asset management tool. The vulnerabilities span multiple classes and can lead to arbitrary code execution or privilege escalation:

  • CVE-2026-48395 (CVSS 8.6) — untrusted search path, arbitrary code execution
  • CVE-2026-48396 (CVSS 8.6) — incorrect authorization, arbitrary code execution
  • CVE-2026-48390 (CVSS 8.6) — incorrect authorization, privilege escalation
  • CVE-2026-48391 (CVSS 8.2) — untrusted search path, arbitrary code execution
  • CVE-2026-48374 (CVSS 7.8) — path traversal, arbitrary code execution
  • CVE-2026-48392, CVE-2026-48393, CVE-2026-48394 (CVSS 7.8 each) — out-of-bounds write, arbitrary code execution

The variety of vulnerability classes — from authorization errors to memory corruption — points to systemic security issues in the Bridge code base. Five vulnerabilities were discovered by researcher Kieran (kaiksi), and three by a researcher using the pseudonym yjdfy.

Impact assessment

Adobe Campaign Classic is an enterprise platform used to manage marketing campaigns, mailings, and customer data. A vulnerability with a CVSS score of 10.0 in such a product poses a particular danger for several reasons:

  • ACC processes customers’ personal data, including email addresses, interaction history, and audience segmentation
  • The platform is integrated with other corporate systems — compromising ACC can become an entry point for lateral movement
  • The lack of any requirement for user interaction lowers the barrier for automated exploitation

Adobe Bridge, although less critical in terms of the data it processes, is widely used in creative departments and can serve as an attack vector against the workstations of designers and content managers.

Recommendations

  • Adobe Campaign Classic: update immediately to version 7.4.3 build 9398. Given the CVSS 10.0 score and the absence of any user interaction requirement, this update should be your top priority
  • Adobe Bridge: install the latest available version specified in bulletin APSB26-89
  • Review ACC server access logs for anomalous requests, especially those showing signs of SQL injection
  • Ensure that the accounts under which ACC runs have the minimum necessary privileges — this will limit damage in the event of a compromise

None of the listed vulnerabilities has yet been added to the CISA KEV catalog, and Adobe has not recorded any cases of exploitation. However, the publication of details for a CVE with a 10.0 score will inevitably attract the attention of attackers. Administrators of Adobe Campaign Classic servers should apply the update to version 7.4.3 build 9398 within the next few hours, without waiting for exploits to appear in the public domain.


CyberSecureFox Editorial Team

The CyberSecureFox Editorial Team covers cybersecurity news, vulnerabilities, malware campaigns, ransomware activity, AI security, cloud security, and vendor security advisories. Articles are prepared using official advisories, CVE/NVD data, CISA alerts, vendor publications, and public research reports. Content is reviewed before publication and updated when new information becomes available.

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.