Adobe Campaign Classic bug (CVE-2026-48449) enables arbitrary code execution
Source headline: Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
Intelligence Summary
Adobe has issued security updates for Adobe Campaign Classic (ACC) to address a maximum-severity vulnerability. The flaw, CVE-2026-48449, is rated 10.0 on the CVSS scale and can allow arbitrary code execution. The issue is tied to incorrect authorization, potentially permitting malicious actions under the right conditions. Organizations using ACC in enterprise marketing workflows should review their exposure and apply the vendor patches promptly. If updates are not yet available in your environment, limit access to the affected functionality until remediation is completed.
Recommended Action
Prioritize immediate review, validate exposure, and patch or mitigate affected systems.