Adobe Releases Security Updates For Adobe Campaign Classic And Adobe Bridge Flaws

Published:

Adobe has released security updates to address multiple critical vulnerabilities affecting Adobe Campaign Classic (ACC) and Adobe Bridge, including a maximum severity flaw with a CVSS score of 10.0 that could allow arbitrary code execution without requiring any user interaction. The most severe issue affects Adobe Campaign Classic, the company’s enterprise marketing automation platform, and has been identified as CVE 2026 48449. Adobe stated that the vulnerability results from incorrect authorization and could allow arbitrary code execution in the context of the current user. Alongside this issue, the company also fixed another high severity vulnerability, tracked as CVE 2026 48448 with a CVSS score of 8.6, which stems from a SQL injection flaw that could enable arbitrary file system reads. Adobe confirmed that it is not aware of any evidence indicating these vulnerabilities have been exploited in real world attacks.

According to Adobe, both Adobe Campaign Classic vulnerabilities have been resolved in version 7.4.3 build 9398 for Windows and Linux systems. The company explained that the updates address security weaknesses capable of leading to arbitrary code execution and unauthorized file system access, making the installation of the latest version important for enterprise users operating the platform. The critical vulnerability identified as CVE 2026 48449 requires no user interaction, increasing its potential impact because successful exploitation could occur without any action from the targeted user. Adobe emphasized that the latest security release strengthens the protection of Adobe Campaign Classic deployments against these identified risks while continuing to monitor for any reports of malicious exploitation.

In addition to Adobe Campaign Classic, Adobe also released updates for Adobe Bridge to remediate eight critical rated security vulnerabilities. These flaws include multiple incorrect authorization weaknesses, untrusted search path issues, path traversal vulnerabilities, and out of bounds write flaws that could result in arbitrary code execution or privilege escalation. The vulnerabilities are tracked as CVE 2026 48395, CVE 2026 48396, CVE 2026 48390, CVE 2026 48391, CVE 2026 48374, CVE 2026 48392, CVE 2026 48393, and CVE 2026 48394, with severity scores ranging from 7.8 to 8.6 under the Common Vulnerability Scoring System. The affected vulnerabilities could allow attackers to execute malicious code or gain elevated privileges if successfully exploited, highlighting the importance of applying the available security updates across supported Adobe Bridge installations.

Adobe acknowledged the contributions of independent security researchers who reported the vulnerabilities through responsible disclosure. Security researcher Kieran, also known as “kaiksi,” was credited with identifying and reporting CVE 2026 48390, CVE 2026 48391, CVE 2026 48395, CVE 2026 48396, and CVE 2026 48374, while researcher “yjdfy” reported CVE 2026 48392, CVE 2026 48393, and CVE 2026 48394. Although Adobe stated that none of the identified flaws are known to have been exploited in the wild, the company strongly recommends that customers update Adobe Campaign Classic and Adobe Bridge to the latest available versions. Applying these security updates will help organizations reduce the risk of unauthorized code execution, privilege escalation, and file system access while maintaining the security of enterprise environments using Adobe software.

Source

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem. 

Related articles

spot_img