Invaders
Back to Blog
Structured data rendered for: WebPage
INVADERS
Get Started

Share

Back to Blog
  1. Home
  2. Resources
  3. Blog
  4. vulnerability
  5. Adobe Campaign Classic flaws put on-prem marketing systems on the emergency patch list

Adobe Campaign Classic flaws put on-prem marketing systems on the emergency patch list

August 2, 2026
Lucas OliveiraLucas Oliveira
5 min read
Adobe Campaign Classic flaws put on-prem marketing systems on the emergency patch list

Adobe Campaign Classic flaws put on-prem marketing systems on the emergency patch list

Adobe has released an urgent security update for Adobe Campaign Classic after disclosing two critical vulnerabilities in the on-premise version of the platform. The headline issue is CVE-2026-48449, an incorrect authorization flaw with a CVSS 10.0 score that can lead to remote code execution without user interaction. The companion bug, CVE-2026-48448, is a SQL injection issue rated 8.6 that can expose sensitive memory and allow arbitrary file system reads.

The affected product is Adobe Campaign Classic v7 7.4.3 build 9397 and earlier on Windows and Linux. Adobe says fully Adobe-hosted instances have already been remediated, but fully on-premise deployments and the on-premise components of hybrid deployments need customer action. The fixed release is ACC v7 7.4.3 build 9398.

Adobe also says it is not aware of exploitation in the wild. That is useful context, but it should not make defenders casual. Campaign platforms often sit close to customer data, segmentation logic, email delivery infrastructure, analytics exports, credentials, and integration tokens. A no-interaction code execution flaw in that environment is not just a software update. It is a trust-boundary problem around a system that can influence how an organization communicates with customers.

What Adobe fixed

APSB26-114 covers two separate weaknesses in Adobe Campaign Classic.

CVE-2026-48449 is categorized as incorrect authorization, tracked under CWE-863. Adobe and NVD describe the impact as arbitrary code execution in the context of the current user, with no user interaction required. The CVSS vector is network-accessible, low complexity, no privileges required, no user interaction, and changed scope, producing a 10.0 critical score.

CVE-2026-48448 is categorized as improper neutralization of special elements used in an SQL command, tracked under CWE-89. NVD describes the issue as a SQL injection vulnerability that can disclose sensitive memory and be leveraged for file system read access. Adobe rates it critical with a CVSS 8.6 score.

Both issues are fixed in Adobe Campaign Classic v7 7.4.3 build 9398 for Windows and Linux.

Why this matters

Adobe Campaign Classic is not a random application tucked away on a workstation. In many organizations it is part of the customer engagement and marketing operations stack. That can make the blast radius broader than the application server itself.

If attackers gain code execution on an exposed or poorly segmented Campaign Classic instance, they may be able to inspect local configuration, access integration secrets, read campaign data, alter workflows, or move toward connected databases and delivery systems. If the SQL injection path exposes files or sensitive memory, defenders should also think about credentials and tokens that may be present in configuration files, logs, export directories, or adjacent service accounts.

This is the practical reason CVSS 10.0 deserves attention here. The score is not only about whether exploitation is known today. It reflects how little friction the vulnerability class appears to require and how much control a successful exploit could provide. For a platform that can touch customer data and outbound messaging, that is enough to justify emergency treatment.

On-premise and hybrid deployments are the priority

Adobe's advisory draws a clear operational boundary: Adobe-hosted instances have already been remediated, while fully on-premise deployments and on-premise components in hybrid deployments are in scope for customer patching.

That distinction matters for asset owners. Some organizations may think of Adobe Campaign as a managed marketing platform while still running on-premise components that handle connectors, integration workflows, or local data processing. Those hybrid pieces should be included in the patch check, not waved away because part of the service is hosted.

Security teams should identify:

  • All Adobe Campaign Classic v7 servers
  • Whether each instance is fully hosted, fully on-premise, or hybrid
  • Installed build numbers, especially anything at or below 7.4.3 build 9397
  • Internet-facing or partner-facing access paths
  • Local integration credentials and service accounts
  • Recent access and application logs around unusual workflow or file activity

What defenders should do now

Upgrade Adobe Campaign Classic v7 to 7.4.3 build 9398 wherever on-premise or hybrid components are present. Because Adobe assigned priority rating 1, this should be treated as urgent for affected environments.

Teams that cannot patch immediately should reduce exposure while change control catches up. Restrict network access to Campaign Classic administration and application interfaces, require access through trusted administrative networks or VPN paths, and confirm that web-facing routes are not unnecessarily reachable from the internet.

After patching, run a focused incident response review. Adobe is not aware of exploitation, but the combination of code execution and file-read impact is serious enough to justify a short hunt rather than a simple ticket closure.

Recommended checks include:

  • Review Campaign Classic application logs, web server logs, and OS logs for abnormal requests or unexpected process launches
  • Look for changes to workflows, scripts, connectors, delivery configurations, and scheduled jobs
  • Check for suspicious file access around configuration directories, export folders, credentials, and logs
  • Rotate high-value integration secrets if the instance was exposed or if file access cannot be ruled out
  • Validate segmentation between Campaign Classic, databases, SMTP infrastructure, analytics tools, and customer-data repositories

The broader lesson

Marketing automation platforms are increasingly part of the enterprise attack surface. They hold customer data, connect to CRM and analytics systems, trigger outbound communications, and often run with service accounts that were designed for business continuity rather than least privilege.

That makes this Adobe Campaign Classic update a useful reminder: vulnerability management should be workflow-aware. A critical flaw in a marketing platform may affect privacy, brand trust, deliverability, customer operations, and downstream integrations all at once.

The immediate action is simple: update to build 9398. The more durable action is to review how much trust sits inside Campaign Classic and whether that trust is segmented, monitored, and easy to rotate when the next critical advisory lands.

References

  1. Security update available for Adobe Campaign Classic | APSB26-114
  2. CVE-2026-48449 Detail
  3. CVE-2026-48448 Detail
  4. Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
  5. Adobe Security Bulletins and Advisories
Tags:
Adobe
Adobe Campaign Classic
CVE
vulnerability
Remote Code Execution
SQL Injection
Patch Management
Incident Response
L

Written by

Lucas Oliveira

Research

A DevOps engineer and cybersecurity enthusiast with a passion for uncovering the latest in zero-day exploits, automation, and emerging tech. I write to share real-world insights from the trenches of IT and security, aiming to make complex topics more accessible and actionable. Whether I’m building tools, tracking threat actors, or experimenting with AI workflows, I’m always exploring new ways to stay one step ahead in today’s fast-moving digital landscape.

Hot TopicsLast 7 days

#Authentication Bypass
16 posts
#AI Security
14 posts
#Account Takeover
7 posts
#Access Control
5 posts
#Active Exploitation
4 posts
#API Security
3 posts
#Application Security
3 posts
#Authentication Tokens
3 posts
View all tags →

Categories

All ArticlesBusiness0Cloud & Application Security16Cloud Security1Cybercrime9Data Breach2Data Protection3Infostealer2Ransomware Groups2Ransomware Trends3Security3supply chain attack8Supply Chain Security5Threat Hunting & Intel34vulnerability115

Stay Updated

Get the latest cybersecurity insights delivered to your inbox.

INVADERS

Providing enterprise-grade cybersecurity solutions to protect organizations from evolving digital threats.

FacebookTwitterLinkedIn

Services

  • Web App Vulnerability Reports
  • Threat Hunting & Intelligence
  • Cybercrime & APT Tracking
  • Incident Response & Remediation

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Security Policy

Company

  • About Us
  • Careers
  • Blog
  • Press

© 2026 Invaders Cybersecurity. All rights reserved.

PrivacyTermsCookies