As outlined in Security Affairs, Adobe has released security updates to address critical vulnerabilities in its enterprise marketing automation platform, Adobe Campaign Classic. The most severe flaw, with a CVSS score of 10.0, could allow attackers to execute arbitrary code remotely without any user interaction.The critical vulnerability in Adobe Campaign Classic, identified as CVE-2026-48449, stems from incorrect authorization and poses a significant risk for remote code execution. Additionally, a high-severity SQL injection flaw (CVE-2026-48448) could enable arbitrary file reads. Both issues are patched in version 7.4.3 build 9398. Adobe also addressed eight critical vulnerabilities in Adobe Bridge, including issues related to incorrect authorization, untrusted search paths, path traversal, and out-of-bounds writes, with CVSS scores ranging from 7.8 to 8.6. These vulnerabilities could lead to arbitrary code execution or privilege escalation.Organizations using these Adobe products are strongly advised to apply the security updates promptly to mitigate potential exploitation risks. Adobe has stated it is not aware of any active exploits in the wild for these specific vulnerabilities.Source: Security Affairs
Vulnerability Management
Adobe fixes critical vulnerabilities in Campaign Classic and Bridge
(Photo by MANJUNATH KIRAN/AFP via Getty Images)
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
