Adobe Security Bulletin

Security update available for Adobe Campaign Classic | APSB26-142

Bulletin ID

Date Published

Priority

APSB26-142

September 8, 2026

1

Summary

Adobe has released a security update for Adobe Campaign Classic. This update addresses critical vulnerabilities that could result in arbitrary code execution, security feature bypass, arbitrary file system read, and application denial-of-service.

Adobe is not aware of any exploits in the wild for any of the issues addressed in this update.  

Affected versions

Product Affected version Platform
Adobe Campaign Classic
ACC v7: 7.4.4 build 9401 and earlier Windows, Linux

Solution

Adobe categorizes these updates with the following priority rating and recommends users update their installation to the newest version:

Product Updated version Platform Priority rating Availability
Adobe Campaign Classic
ACC v7 7.4.4 build 9402 Windows, Linux 1

Release Notes

Note

This security bulletin applies to fully on-premise deployments of Adobe Campaign Classic and the on-premise components of hybrid deployments. Adobe-hosted instances have already been remediated and require no customer action.

Due to the deployment model for Adobe-hosted environments, the applicable security fixes were deployed without incrementing the customer-visible Campaign build number. As a result, some Adobe-hosted instances may continue to report build 9401 even though the applicable security fixes have already been deployed.

Vulnerability Details

Vulnerability Category Vulnerability Impact Severity CVSS base score CVSS vector CVE Number

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)

Arbitrary code execution

Critical

10.0

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CVE-2026-82004

Improper Control of Generation of Code ('Code Injection') (CWE-94)

Arbitrary code execution

Critical

10.0

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CVE-2026-73369

Improper Control of Generation of Code ('Code Injection') (CWE-94)

Arbitrary code execution

Critical

10.0

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CVE-2026-84412

Improper Control of Generation of Code ('Code Injection') (CWE-94)

Arbitrary code execution

Critical

10.0

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CVE-2026-89275

Incorrect Authorization (CWE-863)

Arbitrary code execution

Critical

10.0

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CVE-2026-75723

Improper Control of Generation of Code ('Code Injection') (CWE-94)

Arbitrary code execution

Critical

10.0

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CVE-2026-75699

Improper Control of Generation of Code ('Code Injection') (CWE-94)

Application denial-of-service

Critical

10.0

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CVE-2026-75703

Improper Control of Generation of Code ('Code Injection') (CWE-94)

Arbitrary code execution

Critical

10.0

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CVE-2026-75721

Improper Control of Generation of Code ('Code Injection') (CWE-94)

Arbitrary code execution

Critical

9.9

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L

CVE-2026-89276

Improper Input Validation (CWE-20)

Arbitrary code execution

Critical

9.9

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CVE-2026-82008

Improper Input Validation (CWE-20)

Arbitrary code execution

Critical

9.9

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

CVE-2026-82003

Server-Side Request Forgery (SSRF) (CWE-918)

Security feature bypass

Critical

9.9

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L

CVE-2026-83660

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)

Arbitrary code execution

Critical

9.9

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CVE-2026-82010

Server-Side Request Forgery (SSRF) (CWE-918)

Arbitrary code execution

Critical

9.9

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CVE-2026-82013

Server-Side Request Forgery (SSRF) (CWE-918)

Arbitrary file system read

Critical

9.6

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

CVE-2026-82443

Incorrect Authorization (CWE-863)

Arbitrary code execution

Critical

9.1

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CVE-2026-75728

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)

Security feature bypass

Critical

9.1

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L

CVE-2026-82011

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)

Arbitrary code execution

Critical

9.1

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

CVE-2026-82009

 

Note
Effective August 11, 2026, Adobe may assign a single CVE identifier to internally discovered vulnerabilities with the same severity rating and CWE category when a release includes systemic fixes.

Revisions

  • September 22, 2026: Added CVE-2026-73369, CVE-2026-84412, CVE-2026-89275, CVE-2026-75723, CVE-2026-75699, CVE-2026-75703, CVE-2026-75721, CVE-2026-89276, CVE-2026-82008, CVE-2026-82003, CVE-2026-83660, CVE-2026-82010, CVE-2026-82013, CVE-2026-82443, CVE-2026-75728, CVE-2026-82011, and CVE-2026-82009.

Adobe, Inc.

Get help faster and easier

New user?