CVE Tools
Back to feed
Patch released Campaign Classic rce Bridge Adobe

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

The Hacker News·By The Hacker News··2 min read
CVE Tools coverage

Adobe has issued security updates to resolve a high-severity vulnerability (CVE-2026-48449) in its Campaign Classic platform, which could allow arbitrary code execution without user interaction. The flaw, rated 10.0 on the CVSS scale, stems from incorrect authorization controls. Another related issue (CVE-2026-48448) with a score of 8.6 involves SQL injection risks that might enable attackers to read arbitrary files. These vulnerabilities were addressed in Campaign Classic version 7.4.3 build 9398. Separately, Adobe also patched eight critical flaws in Adobe Bridge, including several tied to privilege escalation and remote code execution. Users are strongly encouraged to install these updates to mitigate potential threats.