Adobe disclosed CVE-2026-48449, a critical incorrect authorization flaw in Adobe Campaign Classic v7 that can lead to remote code execution, with a CVSS score of 10.0. The vulnerability affects build 9397 and earlier on Windows and Linux, and Adobe addressed the issue in build 9398. Adobe-hosted instances were reported as already remediated, while customer-managed and on-premises deployments remain exposed until patched.
Public reporting and CERT advisories in Paraguay highlighted the severity of the issue and urged organizations using Adobe Campaign Classic to update affected systems. Available information did not identify the exact vulnerable endpoint, component, or exploit chain, and there were no credible public proof-of-concept details or confirmed in-the-wild exploitation in the cited reporting. Defenders were advised to prioritize patching internet-exposed instances, restrict network access during remediation, and monitor host and log telemetry for suspicious behavior.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
As of August 3, 2026, reviewed public sources did not identify a credible proof of concept, exploit module, or confirmed in-the-wild exploitation for CVE-2026-48449. Adobe stated it was not aware of exploits in the wild for the vulnerabilities covered by APSB26-114.
Adobe Campaign Classic v7 build 9397 and earlier on Windows or Linux was disclosed as affected by CVE-2026-48449, a critical incorrect authorization vulnerability that can lead to remote code execution. Adobe assigned the flaw a CVSS score of 10.0 and noted that the same advisory also addressed CVE-2026-48448.
Adobe remediated the critical incorrect authorization vulnerability CVE-2026-48449 in Adobe Campaign Classic v7.4.3 build 9398. Adobe also stated that its hosted Adobe Campaign Classic instances had already been remediated, while customer-managed and on-premises deployments remained in scope for patching.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cert.gov.py
Open sourcesocradar.io
Open sourcecert.gov.py
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.