Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Violent Physical Crypto Thefts Surge to $30m in Losses

August 6, 2026

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

August 6, 2026

TeamPCP Traced Back to 2020 Cryptojacking Operation

August 6, 2026
Facebook X (Twitter) Instagram
Thursday, August 6
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
News

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Team-CWDBy Team-CWDAugust 6, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution.

The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system.

It has been described as a case of incorrect authorization that could result in arbitrary code execution in the context of the current user without requiring any user interaction.

The update also resolves another high-severity flaw (CVE-2026-48448, CVSS score: 8.6) stemming from SQL injection that could pave the way for arbitrary file reads.

“This update addresses critical vulnerabilities that could result in arbitrary code execution and arbitrary file system read,” Adobe said in an advisory. The company noted that it’s not aware of any of the flaws being exploited in the wild.

Both shortcomings have been addressed in ACC v7: 7.4.3 build 9398 for Windows and Linux.

Separately, Adobe has also shipped updates to remediate eight critical-rated flaws in Adobe Bridge that could lead to privilege escalation and arbitrary code execution –

  • CVE-2026-48395 (CVSS score: 8.6) – An untrusted search path vulnerability that leads to arbitrary code execution
  • CVE-2026-48396 (CVSS score: 8.6) – An incorrect authorization vulnerability that leads to arbitrary code execution
  • CVE-2026-48390 (CVSS score: 8.6) – An incorrect authorization vulnerability that leads to privilege escalation
  • CVE-2026-48391 (CVSS score: 8.2) – An untrusted search path vulnerability that leads to arbitrary code execution
  • CVE-2026-48374 (CVSS score: 7.8) – A path traversal vulnerability that leads to arbitrary code execution
  • CVE-2026-48392 (CVSS score: 7.8) – An out-of-bounds write vulnerability that leads to arbitrary code execution
  • CVE-2026-48393 (CVSS score: 7.8) – An out-of-bounds write vulnerability that leads to arbitrary code execution
  • CVE-2026-48394 (CVSS score: 7.8) – An out-of-bounds write vulnerability that leads to arbitrary code execution

Adobe credited security researcher Kieran (“kaiksi”) with discovering and reporting CVE-2026-48390, CVE-2026-48391, CVE-2026-48395, CVE-2026-48396, and CVE-2026-48374, and “yjdfy” for CVE-2026-48392, CVE-2026-48393, and CVE-2026-48394.

Users are advised to apply the latest updates for optimal protection.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleTeamPCP Traced Back to 2020 Cryptojacking Operation
Next Article Violent Physical Crypto Thefts Surge to $30m in Losses
Team-CWD
  • Website

Related Posts

News

Violent Physical Crypto Thefts Surge to $30m in Losses

August 6, 2026
News

TeamPCP Traced Back to 2020 Cryptojacking Operation

August 6, 2026
News

Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware

August 6, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA

July 11, 20268 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Is it OK to let your children post selfies online?

February 17, 2026

Why cybercriminals want to break into your email account

June 29, 2026

Drowning in spam or scam emails lately? Here’s why

January 27, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.