CVE-2026-84412
10.0Adobe · Campaign Classic
Adobe Campaign Classic is vulnerable to code injection, allowing unauthenticated remote attackers to achieve arbitrary code execution.
Executive summary
Adobe Campaign Classic is affected by a critical code injection vulnerability that allows unauthenticated remote attackers to execute arbitrary code, posing a severe risk to system integrity.
Vulnerability
This is a code injection vulnerability (CWE-94) that occurs due to improper control of code generation. An unauthenticated attacker can trigger this flaw over the network without user interaction to execute arbitrary code with the privileges of the application process.
Business impact
The potential for unauthenticated remote code execution represents a total compromise of the affected application server. Successful exploitation could lead to full data exfiltration, complete system takeover, and lateral movement within the network, justifying the maximum CVSS score of 10.0. The ability for an attacker to execute code without credentials or interaction makes this a top-priority risk for any organization utilizing this software.
Remediation
Immediate Action: Update Adobe Campaign Classic to version 7.4.4 build 9402 or later as specified in the official Adobe security advisory.
Proactive Monitoring: Review application and system access logs for suspicious command execution patterns or unexpected outbound network connections originating from the Campaign Classic server.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to inspect and block malicious payloads targeting code injection, though these should be considered temporary measures until the patch is applied.
Exploitation status
Public Exploit Available: No (exploit_available: unknown)
Analyst recommendation
Given the critical severity and the potential for full system compromise, organizations must treat this vulnerability with extreme urgency. Administrators should verify their current build version immediately and schedule the update to build 9402 during the next available maintenance window or via emergency change procedures. Neglecting this update leaves the environment vulnerable to complete takeover by remote, unauthenticated actors.
More Adobe CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section