Adobe Patches CVSS 10.0 RCE Flaw in Campaign Classic, Bridge
Adobe has rolled out emergency security updates to address a maximum-severity vulnerability in Campaign Classic (ACC), its enterprise marketing automation platform, that could allow attackers to execute arbitrary code without any user interaction. Tracked as CVE-2026-48449, the flaw carries a rare CVSS score of 10.0 and stems from an incorrect authorization issue. If exploited, it would let attackers run malicious code under the privileges of the current user, making it especially dangerous in shared enterprise environments where Campaign Classic handles sensitive customer data. The patch is available in ACC v7.4.3 build 9398 for both Windows and Linux deployments. Adobe confirmed it is not aware of any active exploitation in the wild, but the critical rating leaves no room for delay in patching.
Alongside the headline flaw, Adobe also resolved a high-severity SQL injection vulnerability (CVE-2026-48448, CVSS 8.6) that could enable arbitrary file reads on affected servers. In a separate advisory, the company shipped fixes for eight critical-rated flaws in Adobe Bridge, several of which could lead to privilege escalation and arbitrary code execution. These include untrusted search path issues (CVE-2026-48395, CVE-2026-48391), additional incorrect authorization bugs (CVE-2026-48396, CVE-2026-48390), a path traversal flaw (CVE-2026-48374), and multiple out-of-bounds write vulnerabilities (CVE-2026-48392 through CVE-2026-48394). Security researchers Kieran ("kaiksi") and "yjdfy" were credited for responsibly disclosing the Bridge issues through coordinated reporting.
Enterprise security teams should prioritize deploying the fixed builds across all Campaign Classic and Bridge installations, particularly those exposed to the internet or integrated with customer-facing marketing workflows. Admins managing Adobe's enterprise stack should also verify that their SSL/TLS configurations remain hardened using an SSL/TLS checker, since misconfigured certificates on ACC servers can compound the risk of unauthorized access. For organizations running Adobe Bridge locally, a quick port scanner review can help confirm there are no extraneous services exposed that could be chained with these code execution flaws. Organizations managing credentials for ACC admin panels should also run them through a password checker to ensure no weak or compromised credentials are protecting mission-critical marketing infrastructure.