Critical Adobe Campaign Classic Vulnerabilities Enables Arbitrary Code Execution

Adobe issued security bulletin APSB26-120 for Adobe Campaign Classic, fixing multiple critical flaws that could enable remote arbitrary code execution. Affected are ACC v7.4.3 build 9398 and earlier on Windows and Linux. Adobe rates the update priority 1 and says upgrade to build 9399. Key CVEs include CVE-2026-48331 (SSRF), CVE-2026-48323 (template injection), and CVE-2026-48330 (SQL injection).

Original reporting
Published Aug 4, 2026, 10:52 AM UTC
Analysis
alphai AI DeskAI-generated
Added to alphai Aug 4, 2026, 4:59 PM UTC. Informational, not investment advice.
How this was made
alphai summarizes source reporting and applies a structured AI analysis for relevance, timing, sentiment and ticker impact. Always verify material claims with the original publisher.
Critical Adobe Campaign Classic Vulnerabilities Enables Arbitrary Code Execution — source image
Decision brief

The 30-second read

$ADBENeutralMed
01

Why it matters

The advisory highlights multiple unauthenticated remote vulnerabilities (including SSRF, template engine injection, and SQL injection) that could enable arbitrary code execution, making rapid upgrades to build 9399 the immediate action for exposed environments.

02

Market read

For traders, the key is the severity and remote exploitability of the vulnerabilities, which can drive near-term customer patching and security spend, though no direct financial impact is disclosed.

03

What to watch

Customer patching timelines, exposure of internet-facing deployments, and potential incident response costs could matter more than the advisory itself for near-term sentiment.

Relevance 7/10Novelty 8/10Timing: today, patch urgency for ACC v7.4.3 build 9398 and earlier

Background

Adobe Campaign Classic is used for cross-channel marketing, customer profiles, email workflows, and campaign automation; the bulletin covers on-prem and hybrid deployments.

Company-level read

Ticker impact

$ADBENeutralMedium confidence
Context

Adobe issued a critical APSB26-120 update for Adobe Campaign Classic, requiring upgrades to ACC v7.4.3 build 9399 to address remote code execution flaws.

Expected impact

Limited direct impact on ADBE shares, but could drive short-term risk premium tied to enterprise security spend and customer patching urgency.

Evidence & confidence

The article is a security advisory with no disclosed financial guidance impact, but it is high severity (CVSS 10.0) and remote-exploit capable, which can affect customer risk management and support costs.

Market effects

Enterprise software and cybersecurity risk management may see incremental demand for patching, monitoring, and vulnerability management services.

No specific regional market impact indicated; advisory applies to Windows and Linux deployments.

Global relevance for organizations running Adobe Campaign Classic, especially internet-facing/hybrid deployments.

Counterpoint

Because Adobe says it is not aware of exploits in the wild and Adobe-hosted instances are already remediated, the market may treat this as contained operational risk rather than a revenue-impact event.

Key entities

  • Adobe Campaign Classic

    Marketing automation platform covered by APSB26-120 security bulletin.

  • APSB26-120

    Adobe’s critical update published August 3, 2026 for ACC vulnerabilities.

  • CVE-2026-48331

    Unauthenticated remote SSRF (CVSS 10.0) enabling server-side requests to internal resources.

  • CVE-2026-48323

    Unauthenticated remote template engine injection (CVSS 10.0) potentially leading to code execution.

  • CVE-2026-48330

    Unauthenticated remote SQL injection (CVSS 10.0) potentially leading to arbitrary code execution.

Related articles

$ADBEMed

Adobe's ChatGPT Plugin: Enterprise AI Strategy

Adobe launched a ChatGPT plugin that lets users access more than 70 tools from Photoshop, Premiere, and Acrobat within the ChatGPT interface, with a handoff to Adobe apps for advanced editing. The company said the goal is to drive broader adoption and subscription usage. The article cites enterprise AI priorities and market growth projections through 2031.

$ADBEMed

Adobe launches ChatGPT plugin to link its creative tools

Adobe launched a ChatGPT plugin that lets users access more than 70 Adobe tools, including Photoshop, Firefly, Premiere, Acrobat, Lightroom, Illustrator, InDesign, and Adobe Stock. Adobe says the plugin routes tasks described in plain language through the relevant apps, consolidating prior ChatGPT connectors and supporting production workflows across images, video, design, and documents.

$ADBEMed

Adobe Brings Photoshop, Premiere & 70+ Creative Apps Into ChatGPT

Adobe launched a new ChatGPT app that integrates more than 70 Adobe creative and productivity tools, including Photoshop, Premiere Pro, Illustrator, InDesign, Lightroom, Acrobat Pro and Firefly, inside OpenAI’s chatbot. Adobe says it consolidates earlier Photoshop, Express and Acrobat Pro integrations and lets users access tools via @Adobe, as guests or with an Adobe account.

$ADBEMed

Adobe says it patched critical vulnerabilities in Adobe Campaign Classic, including CVE-2026-48449 (CVSS 10.0) for…

Adobe says it patched critical vulnerabilities in Adobe Campaign Classic, including CVE-2026-48449 (CVSS 10.0) for remote code execution via incorrect authorization, and CVE-2026-48448 (CVSS 8.6) for SQL injection enabling arbitrary file reads. Fixes are in Campaign Classic v7.4.3 build 9398 for Windows and Linux. Adobe reports no known exploits in the wild.