Adobe Campaign Classic Vulnerabilities Enable Arbitrary Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Adobe has released a Priority 1 security update for Adobe Campaign Classic following the identification of three critical vulnerabilities that could allow unauthenticated remote attackers to execute arbitrary code.

The flaws affect on-premises Adobe Campaign Classic version 7.4.4 build 9400 and earlier installations on Windows and Linux. Tracked as APSB26-134, the security bulletin was published on August 25, 2026.

Adobe said it is not aware of any exploitation in the wild of the vulnerabilities addressed in the release. However, the maximum CVSS score and network-exposed attack conditions make prompt patching essential.

Adobe Campaign Classic Vulnerabilities

The affected vulnerabilities are CVE-2026-76197, CVE-2026-76195, and CVE-2026-76193. An attacker could exploit the flaws remotely over a network, without credentials or user interaction, and cause high-impact damage to confidentiality, integrity, and availability.

These OS command injection vulnerabilities occur when an application fails to safely handle special characters or attacker-controlled input before passing it to an operating system command.

In a successful attack, a threat actor may inject commands that run in the security context of the Adobe Campaign Classic process.

The third issue, CVE-2026-76193, is a server-side request forgery vulnerability, tracked as CWE-918. SSRF weaknesses can let attackers manipulate a server into making requests on their behalf.

Depending on the affected application’s functionality and network access, this can expose internal services, access otherwise unreachable systems, or contribute to code-execution attack chains.

Adobe rates this flaw as critical and says it can also result in arbitrary code execution. Organizations use Adobe Campaign Classic to manage and automate cross-channel marketing campaigns.

A compromise of an exposed or insufficiently segmented deployment could therefore create risks beyond the application server itself, including unauthorized access to campaign data, connected infrastructure, credentials, and internal network resources.

Adobe has released Adobe Campaign Classic v7 7.4.4 build 9401 to resolve the issues. Administrators running build 9400 or earlier should upgrade to the patched build immediately and confirm that all relevant Windows and Linux instances have been updated.

The bulletin applies to fully on-premises deployments and the on-premises components of hybrid deployments. Adobe stated that Adobe-hosted instances have already been remediated and do not require customer action.

Until patching is complete, defenders should limit access to Campaign Classic interfaces, restrict exposure to trusted networks, review application and host logs for abnormal process execution, and investigate unexpected outbound connections originating from Campaign Classic servers.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

The post Adobe Campaign Classic Vulnerabilities Enable Arbitrary Code Execution appeared first on Cyber Security News.