Adobe has released an emergency security update addressing two critical vulnerabilities in Adobe Campaign Classic that could allow attackers to execute arbitrary code and steal sensitive files from affected servers.
The bulletin, tracked as APSB26-114, was published on July 29, 2026, and carries Adobe’s highest priority rating. The update patches two distinct flaws, both rated critical.
Critical Adobe Campaign Classic Flaws
The first, CVE-2026-48449, is an Incorrect Authorization vulnerability (CWE-863) that enables arbitrary code execution.
This flaw carries a maximum CVSS 3.1 score of 10.0, indicating network-based exploitation that requires no privileges or user interaction, with complete impact on confidentiality, integrity, and availability.
The second, CVE-2026-48448, is a SQL Injection vulnerability (CWE-89) leading to arbitrary file system read, scoring 8.6 on CVSS 3.1. This flaw could let attackers extract sensitive files from the underlying system without authentication.
The authorization bypass gives attackers a direct path to remote code execution, while the SQL injection flaw provides a parallel avenue for exfiltrating confidential data such as configuration files or credentials.
The flaws affect Adobe Campaign Classic v7, build 7.4.3.9397 and earlier, running on both Windows and Linux. Adobe has clarified that this bulletin applies exclusively to on-premise deployments and the on-premise components of hybrid setups.
Customers using fully Adobe-hosted instances have already been remediated on the server side and require no further action. Adobe urges all on-premise customers to upgrade immediately to build 7.4.3.9398, which resolves both vulnerabilities.
Given the priority-1 rating and the network-exploitable, no-interaction-required nature of CVE-2026-48449, organizations should treat this as an emergency patch cycle rather than routine maintenance.
As of publication, Adobe states it has no evidence of active exploitation for either CVE in the wild. However, given the maximum severity score on CVE-2026-48449 and the platform’s use in enterprise marketing automation.
Adobe also noted a process change taking effect August 11, 2026: vulnerabilities discovered internally that share the same severity and CWE category may be consolidated under a single CVE identifier going forward.
Organizations running on-premises Adobe Campaign Classic instances should prioritize patch deployment, audit recent authentication and file access logs for anomalies, and confirm that hybrid deployment components have received the update, since only the on-premises portions require manual remediation.
Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN.