Critical Adobe Campaign Classic Vulnerabilities Enables Arbitrary Code Execution
Adobe issued security bulletin APSB26-120 for Adobe Campaign Classic, fixing multiple critical flaws that could enable remote arbitrary code execution. Affected are ACC v7.4.3 build 9398 and earlier on Windows and Linux. Adobe rates the update priority 1 and says upgrade to build 9399. Key CVEs include CVE-2026-48331 (SSRF), CVE-2026-48323 (template injection), and CVE-2026-48330 (SQL injection).
How this was made

The 30-second read
Why it matters
The advisory highlights multiple unauthenticated remote vulnerabilities (including SSRF, template engine injection, and SQL injection) that could enable arbitrary code execution, making rapid upgrades to build 9399 the immediate action for exposed environments.
Market read
For traders, the key is the severity and remote exploitability of the vulnerabilities, which can drive near-term customer patching and security spend, though no direct financial impact is disclosed.
What to watch
Customer patching timelines, exposure of internet-facing deployments, and potential incident response costs could matter more than the advisory itself for near-term sentiment.
Background
Adobe Campaign Classic is used for cross-channel marketing, customer profiles, email workflows, and campaign automation; the bulletin covers on-prem and hybrid deployments.
Ticker impact
Adobe issued a critical APSB26-120 update for Adobe Campaign Classic, requiring upgrades to ACC v7.4.3 build 9399 to address remote code execution flaws.
Limited direct impact on ADBE shares, but could drive short-term risk premium tied to enterprise security spend and customer patching urgency.
The article is a security advisory with no disclosed financial guidance impact, but it is high severity (CVSS 10.0) and remote-exploit capable, which can affect customer risk management and support costs.
Market effects
Enterprise software and cybersecurity risk management may see incremental demand for patching, monitoring, and vulnerability management services.
No specific regional market impact indicated; advisory applies to Windows and Linux deployments.
Global relevance for organizations running Adobe Campaign Classic, especially internet-facing/hybrid deployments.
Counterpoint
Because Adobe says it is not aware of exploits in the wild and Adobe-hosted instances are already remediated, the market may treat this as contained operational risk rather than a revenue-impact event.
Key entities
- softwareAdobe Campaign Classic
Marketing automation platform covered by APSB26-120 security bulletin.
- security_bulletinAPSB26-120
Adobe’s critical update published August 3, 2026 for ACC vulnerabilities.
- vulnerabilityCVE-2026-48331
Unauthenticated remote SSRF (CVSS 10.0) enabling server-side requests to internal resources.
- vulnerabilityCVE-2026-48323
Unauthenticated remote template engine injection (CVSS 10.0) potentially leading to code execution.
- vulnerabilityCVE-2026-48330
Unauthenticated remote SQL injection (CVSS 10.0) potentially leading to arbitrary code execution.



