Bulletin ID
Security update available for Adobe Campaign Classic | APSB26-88
|
|
Date Published |
Priority |
|
APSB26-88 |
July 28, 2026 |
1 |
Summary
Adobe has released security updates for Adobe Campaign Classic. This update addresses a critical vulnerability that could result in security feature bypass.
Adobe is not aware of any exploits in the wild for any of the issues addressed in these updates.
Affected versions
| Product | Affected version | Platform |
|---|---|---|
| Adobe Campaign Classic |
ACC v7: 7.4.3 build 9397 and earlier | Windows, Linux |
Solution
Adobe categorizes these updates with the following priority rating and recommends users update their installation to the newest version:
| Product | Updated version | Platform | Priority rating | Availability |
|---|---|---|---|---|
| Adobe Campaign Classic |
ACC v7: 7.4.3 build 9398 | Windows, Linux | 1 |
This security advisory applies to on-premise Adobe Campaign instances only, including fully on-premise deployments and on-premise components in hybrid deployments. No action is required for Adobe-hosted instances; those environments have already been remediated.
Vulnerability Details
|
Vulnerability Category |
Vulnerability Impact |
Severity |
CVSS base score |
CVE Number |
|
|
Improper Restriction of XML External Entity Reference ('XXE') (CWE-611) |
Security feature bypass |
Critical |
9.3 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N |
CVE-2026-48397 |
Acknowledgments
NOTE: Adobe has a public bug bounty program with HackerOne. If you are interested in working with Adobe as an external security researcher, please check us out here: https://hackerone.com/adobe.
For more information, visit https://helpx.adobe.com/security.html, or email PSIRT@adobe.com