Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

August 1, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: High
Victim: Enterprise users of Adobe Campaign Classic and Adobe Bridge
Incident: Disclosure and patching of critical vulnerabilities including a CVSS 10.0 remote code execution flaw.
Impact: Attackers could achieve full system compromise or unauthorized data access without requiring user interaction.
Attacker: None reported
Analysis: Adobe has resolved a maximum-severity authorization flaw in Campaign Classic that enables unauthenticated arbitrary code execution. The update also addresses a high-severity SQL injection vulnerability allowing arbitrary file reads and eight critical issues in Adobe Bridge. While no active exploitation is currently reported, the CVSS 10.0 rating indicates a severe risk if left unpatched.
Recommendations: Immediately update Adobe Campaign Classic to v7: 7.4.3 build 9398 for Windows and Linux.; Apply the latest security updates for Adobe Bridge to remediate privilege escalation and code execution risks.; Monitor enterprise marketing automation logs for signs of unauthorized access or unexpected system behavior.
Source: The Hacker News

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *