Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
Adobe's emergency patch for CVE-2026-48449 — a CVSS 10.0 unauthenticated RCE in Campaign Classic — demands immediate action from any enterprise running the marketing-automation platform, given zero-interaction exploitability.
Summary written by editorial AI · Source link below
Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution.
The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system.
It has been described as a case of incorrect authorization that could result in
Editorial Analysis
An unauthenticated, zero-interaction RCE in a marketing platform that often holds large customer datasets makes this a top-priority patching event with potential GDPR notification implications.
Immediately patch Adobe Campaign Classic, isolate unpatched instances from the network, and check logs for signs of prior exploitation.
A maximum-severity flaw in Adobe's enterprise marketing platform allows remote takeover without authentication — patching is urgent.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at THN (Feedburner) in a new tab.
More from the Vulnerabilities Desk
- Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores2d
- Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code2d
- Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities3d
- Government Rails Site Hit Hours After CVE Patch3d
- Critical Citrix NetScaler auth bypass now leveraged in attacks3d