Critical Vulnerabilities in Adobe Campaign Classic
Adobe Campaign Classic is affected by three critical vulnerabilities, including SSRF and OS Command Injection, which allow unauthenticated remote attackers to achieve full system compromise.
CVE search metadata
CVE search record: CVE-2024-41865. Severity: high. CVSS: 7.8. EPSS: 0.34%. KEV: no. Product: Campaign Classic. Brief: Critical Vulnerabilities in Adobe Campaign Classic. Brief link: https://feed.craftedsignal.io/briefs/2026-08-adobe-campaign-classic/
CVE search record: CVE-2024-41866. Severity: medium. CVSS: 5.5. EPSS: 0.26%. KEV: no. Product: Campaign Classic. Brief: Critical Vulnerabilities in Adobe Campaign Classic. Brief link: https://feed.craftedsignal.io/briefs/2026-08-adobe-campaign-classic/
CVE search record: CVE-2024-41867. Severity: medium. CVSS: 5.5. EPSS: 0.27%. KEV: no. Product: Campaign Classic. Brief: Critical Vulnerabilities in Adobe Campaign Classic. Brief link: https://feed.craftedsignal.io/briefs/2026-08-adobe-campaign-classic/
The NCSC-NL has identified three critical vulnerabilities in Adobe Campaign Classic, carrying a maximum CVSS score of 10.0. These flaws include Server-Side Request Forgery (SSRF) and OS Command Injection, both of which can be triggered without user interaction by an unauthenticated attacker. The exploitation of these vulnerabilities allows for remote code execution and unauthorized access to the underlying server infrastructure. Given the high potential for system compromise, organizations running Adobe Campaign Classic are advised to apply the latest security patches provided by Adobe as a matter of urgency. The vulnerabilities are identified as CVE-2024-41865, CVE-2024-41866, and CVE-2024-41867.
Impact
Successful exploitation of these vulnerabilities results in unauthorized remote access to the host server running Adobe Campaign Classic. This allows attackers to execute arbitrary commands, exfiltrate sensitive data, or pivot into the internal network. The NCSC-NL assesses the potential damage to organizations as 'high'.
Recommendation
- Immediately apply the security updates provided by Adobe to remediate CVE-2024-41865, CVE-2024-41866, and CVE-2024-41867.
- Review web server logs for suspicious requests involving anomalous URI parameters or outbound connections originating from the Adobe Campaign Classic application server that may indicate exploitation attempts.
Immediate actions
Patch Adobe Campaign Classic installations to address CVE-2024-41865, CVE-2024-41866, and CVE-2024-41867