ShellCodeX
Tools • Events • News • Insights
ShellCodeX Intelligence Brief
CRITICAL Vulnerabilities

Adobe Campaign Classic bug (CVE-2026-48449) enables arbitrary code execution

Source headline: Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Threat level Critical
Signal strength 85/100
Source confidence 1 source
Published 3 hours ago

Intelligence Summary

Adobe has issued security updates for Adobe Campaign Classic (ACC) to address a maximum-severity vulnerability. The flaw, CVE-2026-48449, is rated 10.0 on the CVSS scale and can allow arbitrary code execution. The issue is tied to incorrect authorization, potentially permitting malicious actions under the right conditions. Organizations using ACC in enterprise marketing workflows should review their exposure and apply the vendor patches promptly. If updates are not yet available in your environment, limit access to the affected functionality until remediation is completed.

Recommended Action

Prioritize immediate review, validate exposure, and patch or mitigate affected systems.

Topics

#adobe #campaign-classic #arbitrary-code-execution #authorization-flaw #cve-2026-48449
Original reporting The Hacker News Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
Open original source