If your organisation runs Adobe Campaign Classic on its own servers, check one number today: your build. Adobe has just patched an Adobe Campaign Classic vulnerability rated 10.0 on the CVSS scale. That is the highest score the system allows. Adobe also marked it Priority 1, its highest urgency tier. This is a walkthrough of what the flaw does, who needs to act, and how to check your exposure fast.
Table of Contents
The short version
CVE-2026-48449 is an incorrect authorization flaw in Adobe Campaign Classic (ACC) v7. It affects both Windows and Linux, at build 9397 or earlier. An attacker can run code on the server with no login. They need no user interaction either. Adobe fixed it in build 9398. That fix went out on 29 July, under bulletin APSB26-114.
Adobe says it has seen no evidence of exploitation so far. Treat that as a head start, not a reason to wait. A maximum-severity bug with a public writeup rarely stays quiet for long.
Two flaws, not one
The same update fixes a second issue too. CVE-2026-48448 is a SQL injection bug rated 8.6. It lets an attacker read arbitrary files off the server. On its own, that would already be a serious finding.
Paired with an authorization bypass that needs no credentials, the risk grows. An attacker could pull configuration files, stored credentials, or customer data from the campaign database before anyone notices. Both issues share the same fix, so there is no reason to patch one and defer the other. Update once, and you close both doors. Treat this Adobe Campaign Classic vulnerability and its companion bug as a single ticket, not two separate ones competing for attention on your patch queue.
Don’t confuse this with an earlier Campaign Classic fix
Adobe patched a different authorization flaw in Campaign Classic back in June. That fix, bulletin APSB26-69, moved customers to build 9397. If your team applied it and considers the matter closed, check again. This new Adobe Campaign Classic vulnerability, CVE-2026-48449, was found afterwards. It needs build 9398. Patching in June does not cover you here.
Step 1: Confirm this Adobe Campaign Classic vulnerability applies to you
This only affects on-premise ACC deployments. If Adobe hosts your Campaign instance, the vendor has already fixed its side. There is nothing further for you to do. If you run ACC yourself, on your own Windows or Linux servers, keep reading. The next four steps are for you.
Step 2: Confirm your build number
Log into your ACC console and check the build version. Anything at build 9397 or earlier is vulnerable. Build 9398 fixes both CVE-2026-48449 and CVE-2026-48448. If your change management system tracks patch levels centrally, this is a five-minute check, not a project.

Step 3: Check network exposure
This flaw needs no authentication and no user interaction. So the risk scales directly with how reachable your ACC application server is. An instance exposed to the open internet is a far higher priority than one sitting behind a VPN. Marketing platforms are sometimes made reachable from outside the firewall, so agencies or remote staff can log in. That convenience is exactly what turns a bad bug into an urgent one.
Not sure which situation describes your environment? That uncertainty is worth resolving quickly. An external check of what is actually reachable beats an assumption carried over from when the system was first set up.
Step 4: Patch, or restrict access in the meantime
Apply build 9398 as soon as your change process allows. Adobe has not published an interim mitigation beyond the update itself. Until it is in place, your only lever is reducing who can reach the server. Tighten firewall rules to the application tier. Confirm no test or staging copy of ACC has been left reachable and forgotten. Check whether any third-party integration routes through the same server on a wider network path than it needs.
Step 5: Don’t stop at this one patch
A CVSS 10.0 authorization bug is a useful prompt. Ask a broader question: does anything else customer-facing or internet-reachable in your stack rely on authorization logic that nobody has tested from an attacker’s perspective recently? Vendors find and fix bugs like this one after the fact. A scoped penetration test finds that same class of gap in your own environment, before an incident forces the question rather than after.
Is Campaign Classic one of several internet-facing systems your team manages? If so, this patch is a fair trigger to schedule that wider review, rather than treating each advisory as its own fire drill. A CISO who tracks how each new critical bug gets handled builds a much stronger case for that review than one who reacts to headlines alone.
Subscribe to our newsletter
Honest updates, straight to your inbox. Unsubscribe any time.