Adobe Campaign Classic Patches 18 Critical Flaws, Including a Perfect 10.0 CVE
Adobe fixed 18 critical vulnerabilities in Campaign Classic in September 2026, as detailed in security bulletin APSB26-142 and Dutch NCSC advisory NCSC-2026-0393. The flaws span OS command injection, SQL injection, server-side request forgery, and incorrect authorization, with ten requiring no authentication to exploit. The most severe, CVE-2026-75699, carries a maximum CVSS score of 10.0, making unpatched deployments a high-priority risk. The fully patched version is Campaign Classic 7.4.4 build 9402, with hosted environments already updated. Until patches are applied, administrators are advised to restrict access to Campaign Classic endpoints and limit outbound connections as interim mitigations.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in