
Adobe has released an urgent security update for Adobe Campaign Classic after disclosing two critical vulnerabilities in the on-premise version of the platform. The headline issue is CVE-2026-48449, an incorrect authorization flaw with a CVSS 10.0 score that can lead to remote code execution without user interaction. The companion bug, CVE-2026-48448, is a SQL injection issue rated 8.6 that can expose sensitive memory and allow arbitrary file system reads.
The affected product is Adobe Campaign Classic v7 7.4.3 build 9397 and earlier on Windows and Linux. Adobe says fully Adobe-hosted instances have already been remediated, but fully on-premise deployments and the on-premise components of hybrid deployments need customer action. The fixed release is ACC v7 7.4.3 build 9398.
Adobe also says it is not aware of exploitation in the wild. That is useful context, but it should not make defenders casual. Campaign platforms often sit close to customer data, segmentation logic, email delivery infrastructure, analytics exports, credentials, and integration tokens. A no-interaction code execution flaw in that environment is not just a software update. It is a trust-boundary problem around a system that can influence how an organization communicates with customers.
APSB26-114 covers two separate weaknesses in Adobe Campaign Classic.
CVE-2026-48449 is categorized as incorrect authorization, tracked under CWE-863. Adobe and NVD describe the impact as arbitrary code execution in the context of the current user, with no user interaction required. The CVSS vector is network-accessible, low complexity, no privileges required, no user interaction, and changed scope, producing a 10.0 critical score.
CVE-2026-48448 is categorized as improper neutralization of special elements used in an SQL command, tracked under CWE-89. NVD describes the issue as a SQL injection vulnerability that can disclose sensitive memory and be leveraged for file system read access. Adobe rates it critical with a CVSS 8.6 score.
Both issues are fixed in Adobe Campaign Classic v7 7.4.3 build 9398 for Windows and Linux.
Adobe Campaign Classic is not a random application tucked away on a workstation. In many organizations it is part of the customer engagement and marketing operations stack. That can make the blast radius broader than the application server itself.
If attackers gain code execution on an exposed or poorly segmented Campaign Classic instance, they may be able to inspect local configuration, access integration secrets, read campaign data, alter workflows, or move toward connected databases and delivery systems. If the SQL injection path exposes files or sensitive memory, defenders should also think about credentials and tokens that may be present in configuration files, logs, export directories, or adjacent service accounts.
This is the practical reason CVSS 10.0 deserves attention here. The score is not only about whether exploitation is known today. It reflects how little friction the vulnerability class appears to require and how much control a successful exploit could provide. For a platform that can touch customer data and outbound messaging, that is enough to justify emergency treatment.
Adobe's advisory draws a clear operational boundary: Adobe-hosted instances have already been remediated, while fully on-premise deployments and on-premise components in hybrid deployments are in scope for customer patching.
That distinction matters for asset owners. Some organizations may think of Adobe Campaign as a managed marketing platform while still running on-premise components that handle connectors, integration workflows, or local data processing. Those hybrid pieces should be included in the patch check, not waved away because part of the service is hosted.
Security teams should identify:
Upgrade Adobe Campaign Classic v7 to 7.4.3 build 9398 wherever on-premise or hybrid components are present. Because Adobe assigned priority rating 1, this should be treated as urgent for affected environments.
Teams that cannot patch immediately should reduce exposure while change control catches up. Restrict network access to Campaign Classic administration and application interfaces, require access through trusted administrative networks or VPN paths, and confirm that web-facing routes are not unnecessarily reachable from the internet.
After patching, run a focused incident response review. Adobe is not aware of exploitation, but the combination of code execution and file-read impact is serious enough to justify a short hunt rather than a simple ticket closure.
Recommended checks include:
Marketing automation platforms are increasingly part of the enterprise attack surface. They hold customer data, connect to CRM and analytics systems, trigger outbound communications, and often run with service accounts that were designed for business continuity rather than least privilege.
That makes this Adobe Campaign Classic update a useful reminder: vulnerability management should be workflow-aware. A critical flaw in a marketing platform may affect privacy, brand trust, deliverability, customer operations, and downstream integrations all at once.
The immediate action is simple: update to build 9398. The more durable action is to review how much trust sits inside Campaign Classic and whether that trust is segmented, monitored, and easy to rotate when the next critical advisory lands.
Written by
Research
A DevOps engineer and cybersecurity enthusiast with a passion for uncovering the latest in zero-day exploits, automation, and emerging tech. I write to share real-world insights from the trenches of IT and security, aiming to make complex topics more accessible and actionable. Whether I’m building tools, tracking threat actors, or experimenting with AI workflows, I’m always exploring new ways to stay one step ahead in today’s fast-moving digital landscape.
Get the latest cybersecurity insights delivered to your inbox.