Select a theme from the list.
Insights

From our experts

Latest
Fileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingMass Exploitation Hits WordPress Sites Through Two Critical Upload FlawsCitrix NetScaler Authentication Bypass Draws Real-World Attack TrafficProject Zenith Recasts the Windows PC as a Local AI Development PlatformPostGREShell Turns Trusted Replication Accounts Into Server BackdoorsStyleSmuggler Zero-Day Puts Magento Stores on Emergency FootingRogue AI Agents Turn an Abandoned Wiki Into a Secret Coordination HubFileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingMass Exploitation Hits WordPress Sites Through Two Critical Upload FlawsCitrix NetScaler Authentication Bypass Draws Real-World Attack TrafficProject Zenith Recasts the Windows PC as a Local AI Development PlatformPostGREShell Turns Trusted Replication Accounts Into Server BackdoorsStyleSmuggler Zero-Day Puts Magento Stores on Emergency FootingRogue AI Agents Turn an Abandoned Wiki Into a Secret Coordination Hub
Security Insight

Adobe Campaign Classic Patch Closes Maximum-Severity Enterprise Code Execution Flaw

Adobe Campaign Classic Patch Closes Maximum-Severity Enterprise Code Execution Flaw
Photo by Rafael Minguet Delgado on Pexels

Adobe has patched a CVSS 10.0 vulnerability in Campaign Classic that could allow arbitrary code execution without user interaction. A second flaw could permit SQL injection and arbitrary file access, making the update an important priority for organizations running the marketing platform.

News Date: 2026-08-01

Adobe has released an urgent security update for Campaign Classic after correcting a maximum-severity vulnerability that could allow an attacker to execute arbitrary code. Campaign Classic is used by enterprises to manage customer communications and marketing campaigns, placing it close to valuable databases, customer records, messaging infrastructure, and internal business workflows.

A Serious Authorization Failure

The primary vulnerability, CVE-2026-48449, carries a CVSS score of 10.0. Adobe described it as an incorrect authorization issue capable of producing code execution in the context of the affected user without requiring user interaction.

The update also addresses CVE-2026-48448, a high-severity SQL injection vulnerability with a CVSS score of 8.6. Successful exploitation could allow an attacker to read arbitrary files from the underlying system. In a real enterprise environment, that may expose configuration files, credentials, integration secrets, database connection details, or other information that could support a broader intrusion.

Adobe has fixed both vulnerabilities in Campaign Classic version 7.4.3 build 9398 for Windows and Linux. The company said it was not aware of exploitation in the wild when the advisory was issued, but the absence of observed attacks should not be treated as evidence that vulnerable systems are safe.

Recommended Response

  • Identify every Campaign Classic deployment, including development, staging, and disaster recovery systems.
  • Upgrade Windows and Linux installations to version 7.4.3 build 9398 or a later supported release.
  • Confirm that internet access to administrative and application interfaces is limited to necessary users and networks.
  • Review logs for unusual queries, file access, process creation, account changes, or outbound connections.
  • Rotate sensitive credentials if suspicious activity is found or if the platform handled secrets accessible to its service account.

Marketing Platforms Are High-Value Infrastructure

I believe organizations frequently underestimate the security importance of marketing technology. These systems may not look as critical as identity servers or financial databases, but they often contain extensive customer information and trusted connections to email, analytics, cloud storage, and customer relationship management platforms.

The severity score should attract attention, but context remains essential. Security teams should determine whether the platform is externally reachable, what privileges its service accounts possess, and which connected systems could be affected. Patching is the immediate requirement, while segmentation and least-privilege integration design provide the longer-term protection.

Talk to our team →

Latest

Fileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemorySep 9, 2026Microsoft Brings Agentic Vulnerability Hunting Into Azure GovernmentSep 9, 2026Microsoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesSep 9, 2026Public Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinySep 8, 2026PEEP Turns Trusted Browsers Into Persistent Command CentersSep 8, 2026BigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingSep 8, 2026

Most read

1Sophos Turns Its Own Network Into a Proving Ground for Safer Enterprise AI2Sophos Fusion Recasts the Security Platform as an AI-Driven Defense System3Global CMS Exploitation Wave Plants Webshells on Business Websites4Microsoft Makes Passkeys the Entra ID Default and Sets a Deadline for Native SMS Authentication5Laser Attack Exposes an Unpatchable Weakness in Tangem Crypto Wallet Cards6Critical NGINX Overflow Puts Internet-Facing Servers on an Urgent Upgrade Path