Bulletin ID
Security update available for Adobe Campaign Classic | APSB26-142
|
|
Date Published |
Priority |
|
APSB26-142 |
September 8, 2026 |
1 |
Summary
Adobe has released a security update for Adobe Campaign Classic. This update addresses critical vulnerabilities that could result in arbitrary code execution, security feature bypass, arbitrary file system read, and application denial-of-service.
Adobe is not aware of any exploits in the wild for any of the issues addressed in this update.
Affected versions
| Product | Affected version | Platform |
|---|---|---|
| Adobe Campaign Classic |
ACC v7: 7.4.4 build 9401 and earlier | Windows, Linux |
Solution
Adobe categorizes these updates with the following priority rating and recommends users update their installation to the newest version:
| Product | Updated version | Platform | Priority rating | Availability |
|---|---|---|---|---|
| Adobe Campaign Classic |
ACC v7 7.4.4 build 9402 | Windows, Linux | 1 |
This security bulletin applies to fully on-premise deployments of Adobe Campaign Classic and the on-premise components of hybrid deployments. Adobe-hosted instances have already been remediated and require no customer action.
Due to the deployment model for Adobe-hosted environments, the applicable security fixes were deployed without incrementing the customer-visible Campaign build number. As a result, some Adobe-hosted instances may continue to report build 9401 even though the applicable security fixes have already been deployed.
Vulnerability Details
| Vulnerability Category | Vulnerability Impact | Severity | CVSS base score | CVSS vector | CVE Number |
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) |
Arbitrary code execution |
Critical |
10.0 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
CVE-2026-82004 |
Improper Control of Generation of Code ('Code Injection') (CWE-94) |
Arbitrary code execution |
Critical |
10.0 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
CVE-2026-73369 |
Improper Control of Generation of Code ('Code Injection') (CWE-94) |
Arbitrary code execution |
Critical |
10.0 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
CVE-2026-84412 |
Improper Control of Generation of Code ('Code Injection') (CWE-94) |
Arbitrary code execution |
Critical |
10.0 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
CVE-2026-89275 |
Incorrect Authorization (CWE-863) |
Arbitrary code execution |
Critical |
10.0 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
CVE-2026-75723 |
Improper Control of Generation of Code ('Code Injection') (CWE-94) |
Arbitrary code execution |
Critical |
10.0 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
CVE-2026-75699 |
Improper Control of Generation of Code ('Code Injection') (CWE-94) |
Application denial-of-service |
Critical |
10.0 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
CVE-2026-75703 |
Improper Control of Generation of Code ('Code Injection') (CWE-94) |
Arbitrary code execution |
Critical |
10.0 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
CVE-2026-75721 |
Improper Control of Generation of Code ('Code Injection') (CWE-94) |
Arbitrary code execution |
Critical |
9.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L |
CVE-2026-89276 |
Improper Input Validation (CWE-20) |
Arbitrary code execution |
Critical |
9.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
CVE-2026-82008 |
Improper Input Validation (CWE-20) |
Arbitrary code execution |
Critical |
9.9 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H |
CVE-2026-82003 |
Server-Side Request Forgery (SSRF) (CWE-918) |
Security feature bypass |
Critical |
9.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L |
CVE-2026-83660 |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) |
Arbitrary code execution |
Critical |
9.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
CVE-2026-82010 |
Server-Side Request Forgery (SSRF) (CWE-918) |
Arbitrary code execution |
Critical |
9.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
CVE-2026-82013 |
Server-Side Request Forgery (SSRF) (CWE-918) |
Arbitrary file system read |
Critical |
9.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N |
CVE-2026-82443 |
Incorrect Authorization (CWE-863) |
Arbitrary code execution |
Critical |
9.1 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
CVE-2026-75728 |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) |
Security feature bypass |
Critical |
9.1 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L |
CVE-2026-82011 |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) |
Arbitrary code execution |
Critical |
9.1 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
CVE-2026-82009 |
Revisions
- September 22, 2026: Added CVE-2026-73369, CVE-2026-84412, CVE-2026-89275, CVE-2026-75723, CVE-2026-75699, CVE-2026-75703, CVE-2026-75721, CVE-2026-89276, CVE-2026-82008, CVE-2026-82003, CVE-2026-83660, CVE-2026-82010, CVE-2026-82013, CVE-2026-82443, CVE-2026-75728, CVE-2026-82011, and CVE-2026-82009.