Adobe released security updates for Campaign Classic, Content Credentials Rust SDK and C2PA Tool, Illustrator, XD, and Substance 3D Designer, Painter, and Sampler. The most severe defects are three critical remote-code-execution vulnerabilities in Campaign Classic, rated CVSS 10.0, that could allow an attacker to take full control of an affected system.
Organizations should urgently update Campaign Classic 7.4.4 build 9400 and earlier to build 9401 and apply Adobe’s available fixes for the other affected products, including Substance 3D Designer 16.0.5 and Content Credentials Rust SDK c2pa-v0.90.11 / C2PA Tool c2patool-v0.27.11. Adobe had not observed exploitation at publication, but the Canadian Centre for Cyber Security advised administrators to review Adobe guidance and deploy the updates promptly.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security published advisory AV26-848, directing users and administrators to review Adobe guidance and apply available updates for the affected products.
Adobe reported vulnerabilities affecting Campaign Classic, Substance 3D Designer, Painter and Sampler, Adobe XD, C2PA Tool, Content Credentials Rust SDK, and Illustrator. Affected Campaign Classic releases included ACC v7.4.4 build 9400 and earlier.
Adobe released security updates, including Campaign Classic ACC v7.4.4 build 9401, to address three CVSS 10.0 remote-code-execution flaws (CVE-2026-76193, CVE-2026-76195, and CVE-2026-76197). Adobe also issued updates for affected Content Credentials SDK, Illustrator, Substance 3D, and XD products and said it had not observed exploitation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
10 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourcecybersecuritynews.com
Open sourcethreataft.com
Open sourcetenable.com
Open sourcecyber.gc.ca
Open sourceheise.de
Open sourcesecurityonline.info
Open sourcecirt.gy
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.