🔴 Critical  |  Source: The Hacker News


Adobe has patched a maximum-severity (CVSS 10.0) vulnerability in Campaign Classic, its enterprise marketing automation platform, tracked as CVE-2026-48449. The flaw stems from incorrect authorisation and can lead to arbitrary code execution without any user interaction, meaning an attacker could potentially compromise a server remotely with no victim involvement. Given the zero-interaction requirement and perfect CVSS score, this represents an extremely serious risk for organisations running ACC.

Security Architect’s Take: Prioritise emergency patching of all Adobe Campaign Classic instances immediately — CVSS 10.0 with no user interaction required means this is highly exploitable at scale. If patching cannot be done instantly, consider isolating ACC servers from public-facing networks and restricting inbound access to trusted IP ranges whilst the patch is applied.

Original advisory: Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction