CVE-2026-75703

10.0

Adobe · Adobe Campaign Classic

Adobe Campaign Classic is vulnerable to remote code injection, allowing unauthenticated attackers to execute arbitrary code without user interaction.

Executive summary

Adobe Campaign Classic is affected by a critical code injection vulnerability that permits unauthenticated remote code execution, posing a severe risk to system integrity and confidentiality.

Vulnerability

This vulnerability is a Code Injection flaw (CWE-94) triggered by improper control of generated code. The CVSS vector indicates that the attack is network-exploitable with no authentication or user interaction required, allowing for full system compromise.

Business impact

With a CVSS score of 10.0, this vulnerability represents the highest level of risk to the organization. A successful exploit grants an attacker full control over the application environment, potentially leading to unauthorized data exfiltration, complete system takeover, and significant reputational damage. The lack of required privileges makes this an ideal target for automated exploitation tools.

Remediation

Immediate Action: Update Adobe Campaign Classic to build 9402 or later immediately to resolve the vulnerability.

Proactive Monitoring: Review web server and application logs for suspicious inbound requests containing unusual code patterns or unexpected command strings.

Compensating Controls: Implement a Web Application Firewall (WAF) with updated rulesets to detect and block malicious injection attempts targeting application inputs.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical nature of this vulnerability and the ease of exploitation, immediate patching is mandatory. Security teams should prioritize this update across all instances of Adobe Campaign Classic to prevent unauthorized remote access and potential full-system compromise.

More Adobe CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources