In a nutshell: Adobe Campaign Classic contains a critical authorization vulnerability (CVE-2026-48449, CVSS 10.0) that enables remote code execution without user interaction.
Adobe has released security updates for Campaign Classic to patch a maximum severity vulnerability with a CVSS score of 10.0. The vulnerability enables arbitrary code execution without user interaction due to missing authorization checks.
The vulnerability CVE-2026-48449 affects Adobe Campaign Classic (ACC), an enterprise marketing automation platform, with a maximum CVSS severity score of 10.0.
The security issue stems from a faulty authorization check that allows arbitrary code execution. This occurs without requiring user interaction on the target system.
For CISOs, this represents a critical risk in any environment where Campaign Classic is deployed as a central marketing platform. The maximum CVSS rating indicates that the vulnerability is exploitable without further conditions and immediate patches are required. Adobe has provided corresponding updates that should be deployed urgently.
Source: thehackernews.com · Published August 1, 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.