CVE-2026-89275

10.0

Adobe · Campaign Classic

Adobe Campaign Classic is vulnerable to improper code injection, allowing unauthenticated remote attackers to execute arbitrary code with elevated privileges.

Executive summary

A critical code injection vulnerability in Adobe Campaign Classic allows for unauthenticated remote code execution, posing an extreme risk to infrastructure integrity.

Vulnerability

The application suffers from CWE-94, an improper control of generation of code vulnerability. An unauthenticated attacker can trigger arbitrary code execution without user interaction, resulting in a full compromise of the affected system.

Business impact

The CVSS score of 10.0 reflects the maximum severity of this flaw, as it allows complete system takeover by remote, unauthenticated actors. Successful exploitation would lead to full data exfiltration, permanent loss of system control, and potential lateral movement into the internal network, representing a catastrophic risk to business continuity.

Remediation

Immediate Action: Update Adobe Campaign Classic to build 9402 or later as specified in the vendor security advisory.

Proactive Monitoring: Inspect server logs for unusual process execution, unexpected outbound network connections, or unauthorized attempts to access sensitive configuration files.

Compensating Controls: Deploy strict egress filtering and WAF rules to block suspicious payloads targeting the Adobe Campaign application interface until patching is finalized.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the critical CVSS severity and the nature of remote code execution, this vulnerability demands immediate attention from security teams. Organizations must prioritize the update to build 9402 or higher across all production environments to close the attack vector. Failure to remediate could result in a total compromise of the application and underlying host systems.

More Adobe CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources