Skip to content
feed: live
>_ 0dayNews
adobe

Adobe Patches Max-Severity RCE in Campaign Classic

Adobe patched CVE-2026-48449, a CVSS 10.0 incorrect authorization flaw in Campaign Classic that enables remote code execution without user interaction.

Adobe Patches Max-Severity RCE in Campaign Classic
Photo: Vmenkov / Wikimedia Commons · CC BY-SA 3.0
kilobaud Dave "Kilobaud" Ferris · Published · 2 min read

Adobe has released security updates for Campaign Classic, its enterprise marketing automation platform, patching CVE-2026-48449 — a maximum-severity incorrect authorization flaw that scored 10.0 on the CVSS scale and can result in arbitrary code execution without requiring user interaction.

CVSS 10.0 means no authentication required, no user action to trigger it, network-reachable attack surface. That combination doesn’t stay unnoticed for long once it’s public.

What the flaw is

The Hacker News reports the vulnerability is classified as incorrect authorization — a category where software fails to properly verify that a requestor is entitled to take the action or access the resource being requested. At a score of 10.0 with no user interaction required, exploitation does not depend on valid credentials or a victim clicking anything.

Adobe has not published full technical details in publicly available reporting at time of writing. Affected versions and the complete security bulletin are available through Adobe’s security update channels.

Who runs Campaign Classic

Campaign Classic is Adobe’s on-premises and hybrid-deployment marketing automation platform. It handles campaign orchestration, subscriber list management, triggered email delivery, and in most enterprise deployments it integrates directly with CRM systems and customer databases.

That integration profile is worth paying attention to. A successful exploitation of ACC isn’t scoped to the marketing department’s archives — it’s access to whatever that platform can reach. In most production deployments, that includes customer records and the communication infrastructure tied to them.

What to do

Patch. The update is available; apply it. If a managed service provider operates Campaign Classic on your behalf, confirm the patch has been applied on your instance — your exposure is your provider’s patch cadence until they confirm otherwise.

CISA’s Known Exploited Vulnerabilities catalog does not list CVE-2026-48449 at time of writing, and no confirmed active exploitation has been reported by Adobe or major research outlets. That status can change quickly for a flaw of this severity.

The access profile problem

[Analysis] Marketing automation platforms occupy an uncomfortable position in enterprise security posture. They’re not core network infrastructure, which means they often get less rigorous patch review cycles. They’re not typically public-facing consumer apps, so they sometimes fall outside regular external attack surface scans. But they’re integrated deeply with production data — subscriber records, purchase histories, triggered communication workflows, and the CRM linkages that tie it together.

The mental model of “marketing tool” doesn’t match the access profile of the software. CVSS 10.0 on a platform like this is a reminder of how wide that gap can be. Patch now, before someone else measures it from the outside.

Related CVEs
  • [ CRITICAL ] CVE-2026-48449 Adobe Campaign Classic Incorrect Authorization Enables RCE

Found this useful? Share it.