Adobe Security Bulletin

Security update available for Adobe Campaign Classic | APSB26-88

Bulletin ID

Date Published

Priority

APSB26-88

July 28, 2026

1

Summary

Adobe has released security updates for Adobe Campaign Classic. This update addresses a critical vulnerability  that could result in security feature bypass.

Adobe is not aware of any exploits in the wild for any of the issues addressed in these updates.  

Affected versions

Product Affected version Platform
Adobe Campaign Classic
ACC v7: 7.4.3 build 9397 and earlier Windows, Linux

Solution

Adobe categorizes these updates with the following priority rating and recommends users update their installation to the newest version:

Product Updated version Platform Priority rating Availability
Adobe Campaign Classic
ACC v7: 7.4.3 build 9398 Windows, Linux 1

Releases

Note

This security advisory applies to on-premise Adobe Campaign instances only, including fully on-premise deployments and on-premise components in hybrid deployments. No action is required for Adobe-hosted instances; those environments have already been remediated.

Vulnerability Details

Vulnerability Category

Vulnerability Impact

Severity

CVSS base score 

CVE Number

Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)

Security feature bypass

Critical

9.3

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N 

CVE-2026-48397

Acknowledgments

 

 

NOTE: Adobe has a public bug bounty program with HackerOne. If you are interested in working with Adobe as an external security researcher, please check us out here: https://hackerone.com/adobe.

 

For more information, visit https://helpx.adobe.com/security.html, or email PSIRT@adobe.com

Adobe, Inc.

Get help faster and easier

New user?