discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution.

By Ravie Lakshmanan·Aug 1·thehackernews.com·2 min read

Intelligence analysis by Llama

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
Image: thehackernews.com

Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system.

Why it matters

The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system, making it a critical issue that could result in arbitrary code execution without requiring any user interaction.

Imagine you have a super powerful tool that can do anything you want, but it's not supposed to be used without permission. If someone finds a way to make the tool do what they want without needing permission, that's a big problem. Adobe has a tool called Campaign Classic that can do a lot of things, but it's not supposed to be used without permission. Someone found a way to make it do what they want without needing permission, so Adobe fixed it.

Analysis

A Critical Flaw in Adobe Campaign Classic

Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system.

The update also resolves another high-severity flaw (CVE-2026-48448, CVSS score: 8.6) stemming from SQL injection that could pave the way for arbitrary file reads. "This update addresses critical vulnerabilities that could result in arbitrary code execution and arbitrary file system read," Adobe said in an advisory. The company noted that it's not aware of any of the flaws being exploited in the wild. Both shortcomings have been addressed in ACC v7: 7.4.3 build 9398 for Windows and Linux.

Separately, Adobe Fixes Eight Critical Flaws in Adobe Bridge

Adobe has also shipped updates to remediate eight critical-rated flaws in Adobe Bridge that could lead to privilege escalation and arbitrary code execution - CVE-2026-48395 (CVSS score: 8.6), CVE-2026-48396 (CVSS score: 8.6), CVE-2026-48390 (CVSS score: 8.6), CVE-2026-48391 (CVSS score: 8.2), CVE-2026-48374 (CVSS score: 7.8), CVE-2026-48392 (CVSS score: 7.8), CVE-2026-48393 (CVSS score: 7.8), and CVE-2026-48394 (CVSS score: 7.8).

Credit and Recommendations

Adobe credited security researcher Kieran ("kaiksi") with discovering and reporting CVE-2026-48390, CVE-2026-48391, CVE-2026-48395, CVE-2026-48396, and CVE-2026-48374, and "yjdfy" for CVE-2026-48392, CVE-2026-48393, and CVE-2026-48394. Users are advised to apply the latest updates for optimal protection.

Key points

  • Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC) that could result in arbitrary code execution.
  • The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system.
  • The update also resolves another high-severity flaw (CVE-2026-48448, CVSS score: 8.6) stemming from SQL injection that could pave the way for arbitrary file reads.
  • Adobe has also shipped updates to remediate eight critical-rated flaws in Adobe Bridge that could lead to privilege escalation and arbitrary code execution.
The Upside

If the update is applied successfully, the risk of arbitrary code execution and arbitrary file system read will be mitigated, and users will be protected from potential attacks.

The Downside

If the update is not applied in a timely manner, the risk of arbitrary code execution and arbitrary file system read will remain, and users may be vulnerable to potential attacks.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagsadobeapplication-securitycode-executionenterprise-securitylinux-securityprivilege-escalationsql-injectionvulnerabilitywindows-security

Author

Ravie Lakshmanan

Intelligence analysis by

Llama

Published

Aug 1, 2026

Source

thehackernews.com

Share

Topics

adobeapplication-securitycode-executionenterprise-securitylinux-securityprivilege-escalationsql-injectionvulnerabilitywindows-security

Related

More from this desk

Aug 24·bleepingcomputer.com

Hackers target WordPress sites in miniOrange auth bypass attacks

Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress. The vulnerabilities can be used to forge SAML responses and log in as administrators.

Aug 24·bleepingcomputer.com

TikTok reaches $400M settlement with US over COPPA violations

The U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated companies over allegations that they violated the Children’s Online Privacy Protection Act (COPPA).

Aug 24·bleepingcomputer.com

ReliaQuest confirms failed data-theft attack after ShinyHunters breach

ReliaQuest confirms a failed data-theft attack after hackers impersonated a member of the security team. An attacker called multiple employees and tried to trick them into accessing a fake ReliaQuest single sign-on (SSO) page.

Aug 24·thehackernews.com

Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More

U.S. agencies warn of AI-powered attacks on Siemens S7 Series PLCs as a GitLab code-injection flaw (CVE-2026-19478) faces active exploitation, alongside npm supply-chain attacks and suspected Russian espionage clusters.