Security Affairs
Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic|South Korea Warns of State-Backed Watering Hole Attacks|Google AI Supercharges Chrome Security, Fixing 1,072 Bugs|What an LLM Can Find: A Practical, Cheap Path to Code-level Threat Discovery|Anthropic Finds Claude Breached Real Companies During Security Evaluations|SilverFox Targets Japanese Manufacturer With Advanced ValleyRAT Campaign|Researchers Expose Flying Eagle Criminal Ecosystem Behind Fake Chinese Police App|Why brand impersonation is becoming an initial access vector|Cybercriminals Are Leveraging Autonomous AI Offensive Security Agents|Analog Devices Discloses Data Breach After Unauthorized System Access|FCC Restricts New Foreign Robots and Inverters Over Security Risks|U.S. CISA adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited Vulnerabilities catalog|Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic|South Korea Warns of State-Backed Watering Hole Attacks|Google AI Supercharges Chrome Security, Fixing 1,072 Bugs|What an LLM Can Find: A Practical, Cheap Path to Code-level Threat Discovery|Anthropic Finds Claude Breached Real Companies During Security Evaluations|SilverFox Targets Japanese Manufacturer With Advanced ValleyRAT Campaign|Researchers Expose Flying Eagle Criminal Ecosystem Behind Fake Chinese Police App|Why brand impersonation is becoming an initial access vector|Cybercriminals Are Leveraging Autonomous AI Offensive Security Agents|Analog Devices Discloses Data Breach After Unauthorized System Access|FCC Restricts New Foreign Robots and Inverters Over Security Risks|U.S. CISA adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited Vulnerabilities catalog|
Advertisement

Ad Placeholder

Full Width × 90

Breaking News

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

Adobe Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction.

Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute arbitrary code in the context of the current user without requiring any user interaction.

“Adobe has released a security update for Adobe Campaign Classic. This update addresses critical vulnerabilities  that could result in arbitrary code execution and arbitrary file system read.” reads the advisory. “Adobe is not aware of any exploits in the wild for any of the issues addressed in these updates.”

Organizations using Adobe Campaign Classic should apply the available security updates as soon as possible to reduce the risk of exploitation.

Adobe also fixed CVE-2026-48448 (CVSS score 8.6), a high-severity SQL injection flaw that could allow arbitrary file reads.

Both vulnerabilities are patched in Adobe Campaign Classic v7.4.3 build 9398 for Windows and Linux.

Adobe also released updates for Adobe Bridge, fixing eight critical vulnerabilities that could allow attackers to execute arbitrary code or escalate privileges. The flaws include incorrect authorization, untrusted search path, path traversal, and out-of-bounds write vulnerabilities, with CVSS scores ranging from 7.8 to 8.6.

Below is the list of the flaws:

Vulnerability CategoryVulnerability ImpactSeverityCVSS base scoreCVSS vectorCVE Number
Untrusted Search Path (CWE-426)Arbitrary code executionCritical8.6CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HCVE-2026-48395
Incorrect Authorization (CWE-863)Arbitrary code executionCritical8.6CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HCVE-2026-48396
Incorrect Authorization (CWE-863)Privilege escalationCritical8.2CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:NCVE-2026-48390
Untrusted Search Path (CWE-426)Arbitrary code executionCritical8.2CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:HCVE-2026-48391
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) (CWE-22)Arbitrary code executionCritical7.8CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HCVE-2026-48374
Out-of-bounds Write (CWE-787)Arbitrary code executionCritical7.8CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HCVE-2026-48392
Out-of-bounds Write (CWE-787)Arbitrary code executionCritical7.8CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HCVE-2026-48393
Out-of-bounds Write (CWE-787)Arbitrary code executionCritical7.8CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HCVE-2026-48394

Researcher Kieran (kaiksi) disclosed the flaws CVE-2026-48390, CVE-2026-48391, CVE-2026-48395, CVE-2026-48396, and CVE-2026-48374, while the researcher yjdfy reported the vulnerabilities CVE-2026-48392, CVE-2026-48393, and CVE-2026-48394.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Campaign Classic)