Adobe Campaign Classic is affected by CVE-2026-48449, a critical CWE-863 incorrect authorization flaw that allows unauthenticated remote attackers to execute arbitrary code in the context of the current user without user interaction. The vulnerability carries a CVSS 3.1 score of 10.0 with vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, indicating full compromise potential across confidentiality, integrity, and availability. Affected versions include Adobe Campaign Classic up to and including 7.4.3 build 9397, while 7.4.3 build 9398 is listed as unaffected.
Adobe has released a security update to address the issue, and public reporting said no active exploitation had been confirmed at publication time. The risk is especially significant for on-premises deployments because a successful compromise could expose PII, customer databases, email infrastructure, and connected CRM platforms such as Salesforce and SAP. Organizations are being urged to apply the latest Adobe update immediately, reduce network exposure if patching is delayed, monitor for suspicious Adobe Campaign Classic activity, and review or rotate credentials stored in the platform if compromise is suspected.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
On July 30, 2026, CVE-2026-48449 was recorded as a critical incorrect authorization vulnerability in Adobe Campaign Classic. The flaw can allow unauthenticated remote code execution in the context of the current user without requiring user interaction.
Adobe fixed CVE-2026-48448, a high-severity SQL injection flaw in Adobe Campaign Classic that could enable arbitrary file reads. The issue was remediated in version 7.4.3 build 9398 for Windows and Linux, and Adobe said it was not aware of in-the-wild exploitation.
Adobe released a security update in June 2026 to address CVE-2026-48449 in Adobe Campaign Classic. The issue affects on-premises deployments, with versions up to and including 7.4.3 build 9397 affected and 7.4.3 build 9398 listed as unaffected.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcethehackernews.com
Open sourcemalware.news
Open sourcecyber.gc.ca
Open sourcethreataft.com
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.