Adobe Security Bulletin

Security update available for Adobe Campaign Classic | APSB26-123

Bulletin ID

Date Published

Priority

APSB26-123

August 11, 2026

1

Summary

Adobe has released a security update for Adobe Campaign Classic. This update addresses critical vulnerabilities  that could result in arbitrary code execution.

Adobe is not aware of any exploits in the wild for any of the issues addressed in this update.  

Affected versions

Product Affected version Platform
Adobe Campaign Classic
ACC v7: 7.4.3 build 9399 and earlier Windows, Linux

Solution

Adobe categorizes these updates with the following priority rating and recommends users update their installation to the newest version:

Product Updated version Platform Priority rating Availability
Adobe Campaign Classic
ACC v7 7.4.4 build 9400 Windows, Linux 1

Release Notes

Note

This security bulletin applies only to fully on-premise deployments of Adobe Campaign Classic and to the on-premise components of hybrid deployments. Adobe-hosted instances have already been remediated and require no customer action.

Vulnerability Details

Vulnerability Category Vulnerability Impact Severity CVSS base score CVSS vector CVE Number

Incorrect Authorization (CWE-863)

Arbitrary code execution

Critical

10.0

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CVE-2026-71398

Incorrect Authorization (CWE-863)

Arbitrary code execution

Critical

10.0

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CVE-2026-27302

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)

Arbitrary code execution

Critical

9.0

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

CVE-2026-48381

 

Note
Effective August 11, 2026, Adobe may assign a single CVE identifier to internally discovered vulnerabilities with the same severity rating and CWE category when a release includes systemic fixes.

Adobe, Inc.

Get help faster and easier

New user?