CVE-2026-73369

10.0

Adobe · Adobe Campaign Classic

Adobe Campaign Classic is vulnerable to improper control of code generation, allowing unauthenticated attackers to execute arbitrary code.

Executive summary

Adobe Campaign Classic is affected by a critical code injection vulnerability that allows unauthenticated remote attackers to achieve full system compromise.

Vulnerability

This is a code injection flaw (CWE-94) that permits an unauthenticated attacker to execute arbitrary code on the host system. The vulnerability is triggered over the network without requiring user interaction or elevated privileges.

Business impact

The CVSS score of 10.0 reflects the maximum severity, as this vulnerability provides a direct pathway for full system takeover. A successful exploit could lead to complete data exfiltration, the installation of persistent backdoors, and total loss of confidentiality, integrity, and availability of the affected Adobe Campaign instance.

Remediation

Immediate Action: Update Adobe Campaign Classic to build 9402 or later as specified in the official Adobe security advisory.

Proactive Monitoring: Review system and application logs for unusual inbound network traffic or unexpected process execution originating from the Adobe Campaign service account.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block malicious code injection attempts targeting the application infrastructure.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the critical CVSS severity of 10.0 and the potential for unauthenticated remote code execution, this vulnerability poses an extreme risk to the organization. Administrators must prioritize patching Adobe Campaign Classic to version 9402 or higher immediately to eliminate the attack vector. Failure to remediate could result in a total compromise of the affected environment.

More Adobe CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources