Vulnerability Management

Adobe fixes critical vulnerabilities in Campaign Classic and Bridge

In this photo taken on April 16, 2020, a general view shows the Indian office of Adobe. Since the company ended support for Magento 1, it has become a target of attacks like the massive campaign that affected 2,000 web sites this weekend. (Photo by MANJUNATH KIRAN/AFP via Getty Images)

As outlined in Security Affairs, Adobe has released security updates to address critical vulnerabilities in its enterprise marketing automation platform, Adobe Campaign Classic. The most severe flaw, with a CVSS score of 10.0, could allow attackers to execute arbitrary code remotely without any user interaction.

The critical vulnerability in Adobe Campaign Classic, identified as CVE-2026-48449, stems from incorrect authorization and poses a significant risk for remote code execution. Additionally, a high-severity SQL injection flaw (CVE-2026-48448) could enable arbitrary file reads. Both issues are patched in version 7.4.3 build 9398. Adobe also addressed eight critical vulnerabilities in Adobe Bridge, including issues related to incorrect authorization, untrusted search paths, path traversal, and out-of-bounds writes, with CVSS scores ranging from 7.8 to 8.6. These vulnerabilities could lead to arbitrary code execution or privilege escalation.

Organizations using these Adobe products are strongly advised to apply the security updates promptly to mitigate potential exploitation risks. Adobe has stated it is not aware of any active exploits in the wild for these specific vulnerabilities.

Source: Security Affairs

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds