CVE-2026-75721

10.0

Adobe · Campaign Classic

Adobe Campaign Classic is susceptible to a code injection vulnerability allowing unauthenticated remote attackers to execute arbitrary code, leading to a full system compromise.

Executive summary

Adobe Campaign Classic is affected by a critical code injection vulnerability that allows unauthenticated remote attackers to achieve full system compromise.

Vulnerability

This vulnerability, categorized as CWE-94, involves improper control of code generation which enables arbitrary code execution. The flaw is exploitable by an unauthenticated remote attacker without requiring user interaction.

Business impact

The ability to execute arbitrary code remotely poses a catastrophic risk to organizational data and infrastructure. Given the critical CVSS score of 10.0, successful exploitation would grant an attacker complete control over the affected server, potentially leading to unauthorized data exfiltration, lateral movement within the network, and severe reputational damage.

Remediation

Immediate Action: Update Adobe Campaign Classic to build 9402 or later as documented in Adobe security advisory APSB26-142.

Proactive Monitoring: Review application and server access logs for anomalous requests or unexpected command execution patterns originating from external sources.

Compensating Controls: Deploy Web Application Firewall rules designed to inspect incoming traffic for malicious code injection payloads targeting the Adobe Campaign environment.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Due to the critical severity and the potential for full system takeover, immediate patching is required. Administrators should prioritize the update to build 9402 or higher across all production environments to neutralize this vector, as unauthenticated remote code execution flaws represent the highest level of risk to operational continuity.

More Adobe CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources