ZeroHour
Product

Adobe Campaign Classic

1 mentions in 7 days · 1 in 30 days · 2 total · first seen · last

Timeline

Adobe security advisory (AV26-808) – Update 1

Canada's Cyber Centre updated Adobe advisory AV26-808 to flag that CVE-2026-71362 in Adobe Commerce is being exploited in the wild.

The Canadian Centre for Cyber Security advisory AV26-808 (Update 1) lists vulnerabilities affecting Adobe products including Campaign Classic, Adobe Commerce, Magento Open Source, ColdFusion 2023/2025, Lightroom Classic, and Content Credentials SDKs. Update 1 notes that open-source reporting indicates CVE-2026-71362 is being exploited in the wild. Users and administrators are urged to review the referenced links and apply updates, including those in Adobe bulletin APSB26-92 for Adobe Commerce.

Canadian Centre for Cyber Securityupdated · 1d agofirst · 5d agoAdvisory in the wild 5 sourcesCVE-2026-71362

Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

Adobe patches seven flaws in ColdFusion, Commerce, and Campaign Classic, including actively exploited CVE-2026-71362 enabling customer account takeover.

Adobe issued Priority 1 updates fixing CVSS 10.0 flaws in ColdFusion (CVE-2026-48362, OS command injection) and Campaign Classic (CVE-2026-71398, CVE-2026-27302, incorrect authorization), plus CVE-2026-71362 (CVSS 9.1) in Adobe Commerce and Magento Open Source. Sansec reports threat actors are actively exploiting CVE-2026-71362 to switch customer sessions to other accounts and access private customer data. Adobe-hosted Campaign Classic instances are already remediated, while on-premise deployments are urged to patch within 72 hours. ColdFusion fixes ship in versions 2025.0.12 and 2023.0.23, and Campaign Classic fixes in v7 7.4.4 build 9400.

The Hacker News · Aug 15, 2026Vulnerability in the wildCVE-2026-48362CVE-2026-48273CVE-2026-71384+5 CVEs

Related CVEs

  • Unauthenticated Privilege Escalation Flaw in Adobe Commerce (Magento)
    CVE-2026-71362 is an incorrect-authorization flaw (CWE-863) in Adobe Commerce, the e-commerce platform formerly known as Magento, in which authorization checks are applied incorrectly and can be bypassed. It is triggered over the network without authentication or user interaction, per the CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N). A successful attacker gains elevated access to sensitive resources — a privilege-escalation condition that Adobe's APSB26-92 advisory and press coverage describe as an account-takeover risk. Any organization running an unpatched Adobe Commerce/Magento deployment is affected; exact version ranges are listed in Adobe security bulletin APSB26-92. The flaw came under active attack shortly after public disclosure, and its EPSS score of 25.1% (98th percentile) signals a high likelihood of continued near-term exploitation.
    · Adobe Commerce (Magento)mass
  • Unauthenticated RCE in Adobe Campaign Classic via Incorrect Authorization
    Adobe Campaign Classic contains an incorrect authorization flaw (CWE-863) that allows an unauthenticated remote attacker to execute arbitrary code in the context of the current user. The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:C) indicates the flaw is reachable over the network with no privileges and no user interaction, and the changed scope shows the executed code crosses a security boundary, meaning a request to a vulnerable Campaign Classic instance can lead to code running beyond the application layer. A successful attacker gains code execution with high impact to confidentiality, integrity, and availability on the affected server. Organizations running Adobe Campaign Classic — typically large enterprises operating on-premises or hybrid marketing infrastructure — are affected; the available data does not specify affected version ranges, so defenders should consult the Adobe security bulletin for exact builds. There is currently no evidence of in-the-wild exploitation, no known public proof-of-concept, and the flaw is not in CISA's KEV; EPSS assigns a 0.8% probability of exploitation within 30 days (54th percentile).
    · Adobe Campaign Classicniche
  • Unauthenticated OS Command Injection RCE in Adobe ColdFusion
    Adobe ColdFusion is affected by an OS command injection vulnerability (CWE-78, Improper Neutralization of Special Elements used in an OS Command) rated critical at CVSS 10.0. It is triggered over the network with no authentication and no user interaction (AV:N/AC:L/PR:N/UI:N), so any network-accessible ColdFusion server is directly reachable by an unauthenticated attacker. Successful exploitation yields arbitrary code execution in the context of the current user, and the changed scope (S:C) indicates the injected commands can impact resources beyond the vulnerable ColdFusion component itself, such as other services or systems reachable from it. All ColdFusion deployments are plausibly affected; the data does not specify affected or fixed version ranges, so administrators should check Adobe's security bulletin (the related coverage notes Adobe patched this flaw alongside Campaign Classic issues). Exploitation has not been confirmed: it is not in CISA KEV and no public proof-of-concept is known, though EPSS assigns a 4.3% probability of exploitation within 30 days (91st percentile), warranting prompt patching.
    · Adobe ColdFusionlarge
  • Unauthenticated Arbitrary Code Execution via Authorization Flaw in Adobe Campaign Classic
    CVE-2026-27302 is an incorrect authorization flaw (CWE-863) in Adobe Campaign Classic (ACC) in which access controls are not properly enforced, allowing an attacker to trigger arbitrary code execution in the context of the application's user. Per the CVSS 3.1 vector, it is exploitable over a network with no privileges required and no user interaction, and the 'scope changed' designation means the code execution escapes the vulnerable component, extending impact beyond the application itself. A successful attacker gains arbitrary code execution on the affected server with high impact to confidentiality, integrity, and availability, reflected in the maximum 10.0 base score. Any organization running an affected version of Campaign Classic — an enterprise marketing campaign management platform — is exposed; exact affected version ranges are not included in the available data and must be confirmed in Adobe's advisory. There is no known public exploit or PoC, the flaw is not in CISA KEV, EPSS estimates a roughly 0.7% probability of exploitation within 30 days (51st percentile), and Adobe shipped the fix in a batch release that also addressed two other CVSS 10.0 flaws in ColdFusion and Campaign Classic.
    · Adobe Campaign Classic (ACC)large
  • Eval Injection RCE in Adobe ColdFusion (CVSS 9.9, low-privileged attacker)
    CVE-2026-48273 is a critical (CVSS 9.9) eval injection flaw (CWE-95) in Adobe ColdFusion in which untrusted input is not properly neutralized before it is placed into dynamically evaluated code. A remote attacker who has only low-privileged access to a vulnerable ColdFusion server can trigger the flaw over the network, with no user interaction required. Successful exploitation yields arbitrary code execution in the context of the current user, and the changed CVSS scope (S:C) indicates the impact can extend beyond the directly vulnerable component, a pattern typical of ColdFusion flaws that enable broader system-level code execution. All Adobe ColdFusion deployments are potentially affected; the source data does not specify affected version ranges, so admins should consult Adobe's bulletin for the exact versions fixed. As of this writing there is no known public proof-of-concept and the flaw is not in CISA KEV, though EPSS assigns a 1.7% probability of exploitation within 30 days; the fix shipped in Adobe's large recent patch batch, which also addressed three CVSS 10.0 ColdFusion and Campaign Classic flaws.
    · Adobe ColdFusionlarge
  • Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current
    Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
    · adobe campaign
  • Incorrect Authorization in Adobe ColdFusion Enables Security Bypass
    Adobe ColdFusion contains an incorrect authorization flaw (CWE-863) that permits a security feature bypass, rated critical at CVSS 9.6. An attacker with access to the adjacent network — the vulnerable component sits in the administrative network zone by default — can trigger it with no privileges and no user interaction. Because the scope is 'changed,' the flaw lets the attacker cross a trust boundary, bypass security controls, and gain unauthorized read and write access, potentially causing an application denial-of-service. Any organization running an affected ColdFusion release is exposed, but default configurations that confine the component to the admin network zone limit how many are remotely reachable; the provided data did not specify affected version ranges. Exploitation status is currently quiet: no public proof-of-concept, not listed in CISA KEV, and EPSS estimates only a ~0.4% probability of exploitation within 30 days, though Adobe has shipped fixes as part of a recent ColdFusion patch release.
    · Adobe ColdFusionlarge
  • Unauthenticated SQL Injection Leading to RCE in Adobe Campaign Classic
    Adobe Campaign Classic contains an SQL injection flaw (CWE-89) that an attacker can leverage to execute arbitrary code in the context of the current user, with high confidentiality, integrity, and availability impact per Adobe's scoring. The flaw is reachable over the network without credentials (AV:N/PR:N) and requires no user interaction, but exploitation depends on conditions beyond the attacker's control (AC:H), and the changed scope (S:C) indicates the injected commands can affect resources beyond the vulnerable component. It affects organizations running Adobe Campaign Classic, Adobe's enterprise campaign-management platform, whose instances are typically deployed on-premises or in hybrid cloud setups. There is currently no public proof of concept, the flaw is not in CISA's KEV catalog, and EPSS estimates roughly a 0.6% probability of exploitation within 30 days. Adobe has published a fix in its security bulletin, and the disclosure arrives alongside Adobe's recent batch of critical ColdFusion and Campaign Classic patches.
    · Adobe Campaign Classic (ACC)moderate

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.