<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:adobe:campaign:7.4.4:9401:*:*:classic:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aadobecampaign7.4.49401classic/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 03 Sep 2026 19:22:39 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aadobecampaign7.4.49401classic/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Adobe Security Updates - September 2026</title><link>https://feed.craftedsignal.io/briefs/2026-09-adobe-security-updates/</link><pubDate>Thu, 03 Sep 2026 19:22:39 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-adobe-security-updates/</guid><description>Roundup of Adobe security advisories published in September 2026.</description><content:encoded><![CDATA[<p>This roundup covers 24 Adobe security vulnerabilities. CVSS base scores range from 7.8 to 10.0. None are reported as actively exploited at the time of release. The issues affect Adobe Commerce, Campaign Classic, ColdFusion, Commerce, Experience Manager, Substance 3D Sampler.</p>
<h2 id="summary">Summary</h2>
<table>
	<thead>
			<tr>
					<th>CVE</th>
					<th>Product</th>
					<th>Severity</th>
					<th>CVSS</th>
					<th>EPSS</th>
					<th>KEV</th>
					<th>Source</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td><a href="#cve-2026-83959">CVE-2026-83959</a></td>
					<td>Substance 3D Sampler</td>
					<td>High</td>
					<td>7.8</td>
					<td>0.17%</td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-83959">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-75650">CVE-2026-75650</a></td>
					<td>Adobe Commerce</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-75650">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-76200">CVE-2026-76200</a></td>
					<td>Commerce</td>
					<td>Critical</td>
					<td>9.3</td>
					<td>0.46%</td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-76200">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-76201">CVE-2026-76201</a></td>
					<td>Commerce</td>
					<td>Critical</td>
					<td>9.3</td>
					<td>0.46%</td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-76201">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-82004">CVE-2026-82004</a></td>
					<td>Campaign Classic</td>
					<td>Critical</td>
					<td>10.0</td>
					<td>1.44%</td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-82004">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-19232">CVE-2026-19232</a></td>
					<td>Experience Manager</td>
					<td>Critical</td>
					<td>9.9</td>
					<td>0.57%</td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-19232">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-48273">CVE-2026-48273</a></td>
					<td>ColdFusion</td>
					<td>Critical</td>
					<td>9.9</td>
					<td>1.90%</td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48273">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-75746">CVE-2026-75746</a></td>
					<td>ColdFusion</td>
					<td>Critical</td>
					<td>9.1</td>
					<td>1.07%</td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-75746">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-73369">CVE-2026-73369</a></td>
					<td>Campaign Classic</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-73369">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-75699">CVE-2026-75699</a></td>
					<td>Campaign Classic</td>
					<td>Critical</td>
					<td>10.0</td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-75699">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-75703">CVE-2026-75703</a></td>
					<td>Campaign Classic</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-75703">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-75721">CVE-2026-75721</a></td>
					<td>Campaign Classic</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-75721">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-75723">CVE-2026-75723</a></td>
					<td>Campaign Classic</td>
					<td>Critical</td>
					<td>10.0</td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-75723">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-75728">CVE-2026-75728</a></td>
					<td>Campaign Classic</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-75728">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-82008">CVE-2026-82008</a></td>
					<td>Campaign Classic</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-82008">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-82009">CVE-2026-82009</a></td>
					<td>Campaign Classic</td>
					<td>Critical</td>
					<td>9.1</td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-82009">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-82010">CVE-2026-82010</a></td>
					<td>Campaign Classic</td>
					<td>Critical</td>
					<td>9.9</td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-82010">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-82011">CVE-2026-82011</a></td>
					<td>Campaign Classic</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-82011">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-82013">CVE-2026-82013</a></td>
					<td>Campaign Classic</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-82013">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-82443">CVE-2026-82443</a></td>
					<td>Campaign Classic</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-82443">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-83660">CVE-2026-83660</a></td>
					<td>Campaign Classic</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-83660">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-84412">CVE-2026-84412</a></td>
					<td>Campaign Classic</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-84412">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-89275">CVE-2026-89275</a></td>
					<td>Campaign Classic</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-89275">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-89276">CVE-2026-89276</a></td>
					<td>Campaign Classic</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-89276">NVD</a> (authoritative)</td>
			</tr>
	</tbody>
</table>
<h2 id="cve-2026-83959">CVE-2026-83959</h2>
<p>Adobe Substance 3D Sampler contains a heap-based buffer overflow vulnerability triggered by opening a malicious file. Successful exploitation allows an attacker to achieve arbitrary code execution in the context of the current user, requiring user interaction to open the crafted file.</p>
<p>Affected products:</p>
<ul>
<li>Substance 3D Sampler</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-83959">https://nvd.nist.gov/vuln/detail/CVE-2026-83959</a></p>
<h2 id="cve-2026-75650">CVE-2026-75650</h2>
<p>Adobe Commerce contains a vulnerability involving improper neutralization of special elements used in a template engine, which allows an unauthenticated attacker to execute arbitrary code. The vulnerability is categorized as remote code execution, does not require user interaction, and impacts the integrity and availability of the system.</p>
<p>Affected products:</p>
<ul>
<li>Adobe Commerce</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-75650">https://nvd.nist.gov/vuln/detail/CVE-2026-75650</a></p>
<h2 id="cve-2026-76200">CVE-2026-76200</h2>
<p>Adobe Commerce contains a stored Cross-Site Scripting (XSS) vulnerability allowing attackers to inject malicious JavaScript into form fields. When a victim accesses the affected page, the script executes within the victim's session, potentially leading to unauthorized account access or session hijacking.</p>
<p>Affected products:</p>
<ul>
<li>Commerce</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-76200">https://nvd.nist.gov/vuln/detail/CVE-2026-76200</a></p>
<p>Related in this roundup: <a href="#cve-2026-76201">CVE-2026-76201</a>.</p>
<h2 id="cve-2026-76201">CVE-2026-76201</h2>
<p>Adobe Commerce contains a stored Cross-Site Scripting (XSS) vulnerability allowing an attacker to inject malicious scripts into form fields. When a victim accesses the affected page, the script executes in their browser, potentially leading to session hijacking or unauthorized account access.</p>
<p>Affected products:</p>
<ul>
<li>Commerce</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-76201">https://nvd.nist.gov/vuln/detail/CVE-2026-76201</a></p>
<p>Related in this roundup: <a href="#cve-2026-76200">CVE-2026-76200</a>.</p>
<h2 id="cve-2026-82004">CVE-2026-82004</h2>
<p>Adobe Campaign Classic (ACC) is vulnerable to an OS command injection flaw (CVE-2026-82004) that allows unauthenticated attackers to achieve remote code execution in the context of the current user without requiring user interaction. The vulnerability has a CVSS v3.1 base score of 10.0 and involves a changed scope, indicating potential impact beyond the affected service.</p>
<p>Affected products:</p>
<ul>
<li>Campaign Classic</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-82004">https://nvd.nist.gov/vuln/detail/CVE-2026-82004</a></p>
<p>Related in this roundup: <a href="#cve-2026-73369">CVE-2026-73369</a>, <a href="#cve-2026-75699">CVE-2026-75699</a>, <a href="#cve-2026-75703">CVE-2026-75703</a>, <a href="#cve-2026-75721">CVE-2026-75721</a>, <a href="#cve-2026-75723">CVE-2026-75723</a>, <a href="#cve-2026-75728">CVE-2026-75728</a>, <a href="#cve-2026-82008">CVE-2026-82008</a>, <a href="#cve-2026-82009">CVE-2026-82009</a>, <a href="#cve-2026-82010">CVE-2026-82010</a>, <a href="#cve-2026-82011">CVE-2026-82011</a>, <a href="#cve-2026-82013">CVE-2026-82013</a>, <a href="#cve-2026-82443">CVE-2026-82443</a>, <a href="#cve-2026-83660">CVE-2026-83660</a>, <a href="#cve-2026-84412">CVE-2026-84412</a>, <a href="#cve-2026-89275">CVE-2026-89275</a>, <a href="#cve-2026-89276">CVE-2026-89276</a>.</p>
<h2 id="cve-2026-19232">CVE-2026-19232</h2>
<p>Adobe Experience Manager is vulnerable to an incorrect authorization flaw that allows a low-privileged attacker to achieve arbitrary code execution. The vulnerability does not require user interaction and can result in the attacker gaining elevated access or control over a victim's session, leading to a full compromise of the affected account scope.</p>
<p>Affected products:</p>
<ul>
<li>Experience Manager</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-19232">https://nvd.nist.gov/vuln/detail/CVE-2026-19232</a></p>
<h2 id="cve-2026-48273">CVE-2026-48273</h2>
<p>Adobe ColdFusion is vulnerable to an improper neutralization of directives in dynamically evaluated code (Eval Injection), which allows a low-privileged attacker to achieve remote code execution without user interaction. The vulnerability results in a change of scope, significantly increasing the impact of successful exploitation.</p>
<p>Affected products:</p>
<ul>
<li>ColdFusion</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48273">https://nvd.nist.gov/vuln/detail/CVE-2026-48273</a></p>
<p>Related in this roundup: <a href="#cve-2026-75746">CVE-2026-75746</a>.</p>
<h2 id="cve-2026-75746">CVE-2026-75746</h2>
<p>Adobe ColdFusion is vulnerable to a high-severity SQL injection flaw (CVE-2026-75746) that allows a highly privileged attacker to achieve remote code execution. The vulnerability does not require user interaction and impacts the integrity and availability of the application environment.</p>
<p>Affected products:</p>
<ul>
<li>ColdFusion</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-75746">https://nvd.nist.gov/vuln/detail/CVE-2026-75746</a></p>
<p>Related in this roundup: <a href="#cve-2026-48273">CVE-2026-48273</a>.</p>
<h2 id="cve-2026-73369">CVE-2026-73369</h2>
<p>Adobe Campaign Classic (ACC) is vulnerable to a code injection vulnerability (CVE-2026-73369) that allows for remote code execution in the context of the current user. The vulnerability does not require user interaction for exploitation and is classified as having a CVSS v3.1 base score of 10.0.</p>
<p>Affected products:</p>
<ul>
<li>Campaign Classic</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-73369">https://nvd.nist.gov/vuln/detail/CVE-2026-73369</a></p>
<p>Related in this roundup: <a href="#cve-2026-82004">CVE-2026-82004</a>, <a href="#cve-2026-75699">CVE-2026-75699</a>, <a href="#cve-2026-75703">CVE-2026-75703</a>, <a href="#cve-2026-75721">CVE-2026-75721</a>, <a href="#cve-2026-75723">CVE-2026-75723</a>, <a href="#cve-2026-75728">CVE-2026-75728</a>, <a href="#cve-2026-82008">CVE-2026-82008</a>, <a href="#cve-2026-82009">CVE-2026-82009</a>, <a href="#cve-2026-82010">CVE-2026-82010</a>, <a href="#cve-2026-82011">CVE-2026-82011</a>, <a href="#cve-2026-82013">CVE-2026-82013</a>, <a href="#cve-2026-82443">CVE-2026-82443</a>, <a href="#cve-2026-83660">CVE-2026-83660</a>, <a href="#cve-2026-84412">CVE-2026-84412</a>, <a href="#cve-2026-89275">CVE-2026-89275</a>, <a href="#cve-2026-89276">CVE-2026-89276</a>.</p>
<h2 id="cve-2026-75699">CVE-2026-75699</h2>
<p>Adobe Campaign Classic (ACC) contains a code injection vulnerability that allows an unauthenticated attacker to execute arbitrary code with the privileges of the application user. This issue is categorized as a critical risk with a CVSS score of 10.0, as it does not require user interaction and impacts the overall system integrity and confidentiality.</p>
<p>Affected products:</p>
<ul>
<li>Campaign Classic</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-75699">https://nvd.nist.gov/vuln/detail/CVE-2026-75699</a></p>
<p>Related in this roundup: <a href="#cve-2026-82004">CVE-2026-82004</a>, <a href="#cve-2026-73369">CVE-2026-73369</a>, <a href="#cve-2026-75703">CVE-2026-75703</a>, <a href="#cve-2026-75721">CVE-2026-75721</a>, <a href="#cve-2026-75723">CVE-2026-75723</a>, <a href="#cve-2026-75728">CVE-2026-75728</a>, <a href="#cve-2026-82008">CVE-2026-82008</a>, <a href="#cve-2026-82009">CVE-2026-82009</a>, <a href="#cve-2026-82010">CVE-2026-82010</a>, <a href="#cve-2026-82011">CVE-2026-82011</a>, <a href="#cve-2026-82013">CVE-2026-82013</a>, <a href="#cve-2026-82443">CVE-2026-82443</a>, <a href="#cve-2026-83660">CVE-2026-83660</a>, <a href="#cve-2026-84412">CVE-2026-84412</a>, <a href="#cve-2026-89275">CVE-2026-89275</a>, <a href="#cve-2026-89276">CVE-2026-89276</a>.</p>
<h2 id="cve-2026-75703">CVE-2026-75703</h2>
<p>CVE-2026-75703 identifies an improper control of generation of code vulnerability in Adobe Campaign Classic (ACC). The vulnerability allows a remote, unauthenticated attacker to execute arbitrary code in the context of the current user without requiring user interaction. The impact includes a full compromise of the service integrity and availability (CVSS 10.0), necessitating immediate patching.</p>
<p>Affected products:</p>
<ul>
<li>Campaign Classic</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-75703">https://nvd.nist.gov/vuln/detail/CVE-2026-75703</a></p>
<p>Related in this roundup: <a href="#cve-2026-82004">CVE-2026-82004</a>, <a href="#cve-2026-73369">CVE-2026-73369</a>, <a href="#cve-2026-75699">CVE-2026-75699</a>, <a href="#cve-2026-75721">CVE-2026-75721</a>, <a href="#cve-2026-75723">CVE-2026-75723</a>, <a href="#cve-2026-75728">CVE-2026-75728</a>, <a href="#cve-2026-82008">CVE-2026-82008</a>, <a href="#cve-2026-82009">CVE-2026-82009</a>, <a href="#cve-2026-82010">CVE-2026-82010</a>, <a href="#cve-2026-82011">CVE-2026-82011</a>, <a href="#cve-2026-82013">CVE-2026-82013</a>, <a href="#cve-2026-82443">CVE-2026-82443</a>, <a href="#cve-2026-83660">CVE-2026-83660</a>, <a href="#cve-2026-84412">CVE-2026-84412</a>, <a href="#cve-2026-89275">CVE-2026-89275</a>, <a href="#cve-2026-89276">CVE-2026-89276</a>.</p>
<h2 id="cve-2026-75721">CVE-2026-75721</h2>
<p>Adobe Campaign Classic is vulnerable to an Improper Control of Generation of Code ('Code Injection') vulnerability, allowing an unauthenticated remote attacker to execute arbitrary code within the context of the application user. The vulnerability carries a CVSS base score of 10.0 and does not require user interaction to exploit.</p>
<p>Affected products:</p>
<ul>
<li>Campaign Classic</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-75721">https://nvd.nist.gov/vuln/detail/CVE-2026-75721</a></p>
<p>Related in this roundup: <a href="#cve-2026-82004">CVE-2026-82004</a>, <a href="#cve-2026-73369">CVE-2026-73369</a>, <a href="#cve-2026-75699">CVE-2026-75699</a>, <a href="#cve-2026-75703">CVE-2026-75703</a>, <a href="#cve-2026-75723">CVE-2026-75723</a>, <a href="#cve-2026-75728">CVE-2026-75728</a>, <a href="#cve-2026-82008">CVE-2026-82008</a>, <a href="#cve-2026-82009">CVE-2026-82009</a>, <a href="#cve-2026-82010">CVE-2026-82010</a>, <a href="#cve-2026-82011">CVE-2026-82011</a>, <a href="#cve-2026-82013">CVE-2026-82013</a>, <a href="#cve-2026-82443">CVE-2026-82443</a>, <a href="#cve-2026-83660">CVE-2026-83660</a>, <a href="#cve-2026-84412">CVE-2026-84412</a>, <a href="#cve-2026-89275">CVE-2026-89275</a>, <a href="#cve-2026-89276">CVE-2026-89276</a>.</p>
<h2 id="cve-2026-75723">CVE-2026-75723</h2>
<p>Adobe Campaign Classic (ACC) is vulnerable to an incorrect authorization flaw that allows an attacker to achieve arbitrary code execution. The vulnerability does not require user interaction and impacts the system scope, presenting a high risk for potential exploitation.</p>
<p>Affected products:</p>
<ul>
<li>Campaign Classic</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-75723">https://nvd.nist.gov/vuln/detail/CVE-2026-75723</a></p>
<p>Related in this roundup: <a href="#cve-2026-82004">CVE-2026-82004</a>, <a href="#cve-2026-73369">CVE-2026-73369</a>, <a href="#cve-2026-75699">CVE-2026-75699</a>, <a href="#cve-2026-75703">CVE-2026-75703</a>, <a href="#cve-2026-75721">CVE-2026-75721</a>, <a href="#cve-2026-75728">CVE-2026-75728</a>, <a href="#cve-2026-82008">CVE-2026-82008</a>, <a href="#cve-2026-82009">CVE-2026-82009</a>, <a href="#cve-2026-82010">CVE-2026-82010</a>, <a href="#cve-2026-82011">CVE-2026-82011</a>, <a href="#cve-2026-82013">CVE-2026-82013</a>, <a href="#cve-2026-82443">CVE-2026-82443</a>, <a href="#cve-2026-83660">CVE-2026-83660</a>, <a href="#cve-2026-84412">CVE-2026-84412</a>, <a href="#cve-2026-89275">CVE-2026-89275</a>, <a href="#cve-2026-89276">CVE-2026-89276</a>.</p>
<h2 id="cve-2026-75728">CVE-2026-75728</h2>
<p>Adobe Campaign Classic (ACC) contains an incorrect authorization vulnerability that allows an unauthenticated attacker to achieve arbitrary code execution. The vulnerability does not require user interaction, making it a critical risk for deployments of the affected software.</p>
<p>Affected products:</p>
<ul>
<li>Campaign Classic</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-75728">https://nvd.nist.gov/vuln/detail/CVE-2026-75728</a></p>
<p>Related in this roundup: <a href="#cve-2026-82004">CVE-2026-82004</a>, <a href="#cve-2026-73369">CVE-2026-73369</a>, <a href="#cve-2026-75699">CVE-2026-75699</a>, <a href="#cve-2026-75703">CVE-2026-75703</a>, <a href="#cve-2026-75721">CVE-2026-75721</a>, <a href="#cve-2026-75723">CVE-2026-75723</a>, <a href="#cve-2026-82008">CVE-2026-82008</a>, <a href="#cve-2026-82009">CVE-2026-82009</a>, <a href="#cve-2026-82010">CVE-2026-82010</a>, <a href="#cve-2026-82011">CVE-2026-82011</a>, <a href="#cve-2026-82013">CVE-2026-82013</a>, <a href="#cve-2026-82443">CVE-2026-82443</a>, <a href="#cve-2026-83660">CVE-2026-83660</a>, <a href="#cve-2026-84412">CVE-2026-84412</a>, <a href="#cve-2026-89275">CVE-2026-89275</a>, <a href="#cve-2026-89276">CVE-2026-89276</a>.</p>
<h2 id="cve-2026-82008">CVE-2026-82008</h2>
<p>Adobe Campaign Classic (ACC) is vulnerable to an improper input validation flaw that allows a low-privileged attacker to achieve remote code execution in the context of the current user without requiring user interaction. The vulnerability is considered high severity due to the potential for arbitrary code execution.</p>
<p>Affected products:</p>
<ul>
<li>Campaign Classic</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-82008">https://nvd.nist.gov/vuln/detail/CVE-2026-82008</a></p>
<p>Related in this roundup: <a href="#cve-2026-82004">CVE-2026-82004</a>, <a href="#cve-2026-73369">CVE-2026-73369</a>, <a href="#cve-2026-75699">CVE-2026-75699</a>, <a href="#cve-2026-75703">CVE-2026-75703</a>, <a href="#cve-2026-75721">CVE-2026-75721</a>, <a href="#cve-2026-75723">CVE-2026-75723</a>, <a href="#cve-2026-75728">CVE-2026-75728</a>, <a href="#cve-2026-82009">CVE-2026-82009</a>, <a href="#cve-2026-82010">CVE-2026-82010</a>, <a href="#cve-2026-82011">CVE-2026-82011</a>, <a href="#cve-2026-82013">CVE-2026-82013</a>, <a href="#cve-2026-82443">CVE-2026-82443</a>, <a href="#cve-2026-83660">CVE-2026-83660</a>, <a href="#cve-2026-84412">CVE-2026-84412</a>, <a href="#cve-2026-89275">CVE-2026-89275</a>, <a href="#cve-2026-89276">CVE-2026-89276</a>.</p>
<h2 id="cve-2026-82009">CVE-2026-82009</h2>
<p>Adobe Campaign Classic (ACC) is vulnerable to a high-severity SQL injection flaw (CVE-2026-82009) that allows authenticated attackers with high privileges to execute arbitrary SQL commands. Successful exploitation can lead to arbitrary code execution within the context of the current user without requiring user interaction.</p>
<p>Affected products:</p>
<ul>
<li>Campaign Classic</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-82009">https://nvd.nist.gov/vuln/detail/CVE-2026-82009</a></p>
<p>Related in this roundup: <a href="#cve-2026-82004">CVE-2026-82004</a>, <a href="#cve-2026-73369">CVE-2026-73369</a>, <a href="#cve-2026-75699">CVE-2026-75699</a>, <a href="#cve-2026-75703">CVE-2026-75703</a>, <a href="#cve-2026-75721">CVE-2026-75721</a>, <a href="#cve-2026-75723">CVE-2026-75723</a>, <a href="#cve-2026-75728">CVE-2026-75728</a>, <a href="#cve-2026-82008">CVE-2026-82008</a>, <a href="#cve-2026-82010">CVE-2026-82010</a>, <a href="#cve-2026-82011">CVE-2026-82011</a>, <a href="#cve-2026-82013">CVE-2026-82013</a>, <a href="#cve-2026-82443">CVE-2026-82443</a>, <a href="#cve-2026-83660">CVE-2026-83660</a>, <a href="#cve-2026-84412">CVE-2026-84412</a>, <a href="#cve-2026-89275">CVE-2026-89275</a>, <a href="#cve-2026-89276">CVE-2026-89276</a>.</p>
<h2 id="cve-2026-82010">CVE-2026-82010</h2>
<p>Adobe Campaign Classic (ACC) contains an SQL injection vulnerability that can be exploited by a low-privileged attacker to achieve arbitrary code execution. The vulnerability does not require user interaction and impacts the overall scope of the target application.</p>
<p>Affected products:</p>
<ul>
<li>Campaign Classic</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-82010">https://nvd.nist.gov/vuln/detail/CVE-2026-82010</a></p>
<p>Related in this roundup: <a href="#cve-2026-82004">CVE-2026-82004</a>, <a href="#cve-2026-73369">CVE-2026-73369</a>, <a href="#cve-2026-75699">CVE-2026-75699</a>, <a href="#cve-2026-75703">CVE-2026-75703</a>, <a href="#cve-2026-75721">CVE-2026-75721</a>, <a href="#cve-2026-75723">CVE-2026-75723</a>, <a href="#cve-2026-75728">CVE-2026-75728</a>, <a href="#cve-2026-82008">CVE-2026-82008</a>, <a href="#cve-2026-82009">CVE-2026-82009</a>, <a href="#cve-2026-82011">CVE-2026-82011</a>, <a href="#cve-2026-82013">CVE-2026-82013</a>, <a href="#cve-2026-82443">CVE-2026-82443</a>, <a href="#cve-2026-83660">CVE-2026-83660</a>, <a href="#cve-2026-84412">CVE-2026-84412</a>, <a href="#cve-2026-89275">CVE-2026-89275</a>, <a href="#cve-2026-89276">CVE-2026-89276</a>.</p>
<h2 id="cve-2026-82011">CVE-2026-82011</h2>
<p>Adobe Campaign Classic is vulnerable to an SQL injection vulnerability that allows low-privileged attackers to bypass security measures, resulting in unauthorized read and limited write access to the application data. The vulnerability does not require user interaction and impacts the overall security scope of the affected system.</p>
<p>Affected products:</p>
<ul>
<li>Campaign Classic</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-82011">https://nvd.nist.gov/vuln/detail/CVE-2026-82011</a></p>
<p>Related in this roundup: <a href="#cve-2026-82004">CVE-2026-82004</a>, <a href="#cve-2026-73369">CVE-2026-73369</a>, <a href="#cve-2026-75699">CVE-2026-75699</a>, <a href="#cve-2026-75703">CVE-2026-75703</a>, <a href="#cve-2026-75721">CVE-2026-75721</a>, <a href="#cve-2026-75723">CVE-2026-75723</a>, <a href="#cve-2026-75728">CVE-2026-75728</a>, <a href="#cve-2026-82008">CVE-2026-82008</a>, <a href="#cve-2026-82009">CVE-2026-82009</a>, <a href="#cve-2026-82010">CVE-2026-82010</a>, <a href="#cve-2026-82013">CVE-2026-82013</a>, <a href="#cve-2026-82443">CVE-2026-82443</a>, <a href="#cve-2026-83660">CVE-2026-83660</a>, <a href="#cve-2026-84412">CVE-2026-84412</a>, <a href="#cve-2026-89275">CVE-2026-89275</a>, <a href="#cve-2026-89276">CVE-2026-89276</a>.</p>
<h2 id="cve-2026-82013">CVE-2026-82013</h2>
<p>Adobe Campaign Classic (ACC) is vulnerable to a Server-Side Request Forgery (SSRF) flaw that allows low-privileged, unauthenticated attackers to perform privilege escalation. An attacker can leverage this vulnerability to gain unauthorized access to internal resources, with the exploit not requiring user interaction.</p>
<p>Affected products:</p>
<ul>
<li>Campaign Classic</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-82013">https://nvd.nist.gov/vuln/detail/CVE-2026-82013</a></p>
<p>Related in this roundup: <a href="#cve-2026-82004">CVE-2026-82004</a>, <a href="#cve-2026-73369">CVE-2026-73369</a>, <a href="#cve-2026-75699">CVE-2026-75699</a>, <a href="#cve-2026-75703">CVE-2026-75703</a>, <a href="#cve-2026-75721">CVE-2026-75721</a>, <a href="#cve-2026-75723">CVE-2026-75723</a>, <a href="#cve-2026-75728">CVE-2026-75728</a>, <a href="#cve-2026-82008">CVE-2026-82008</a>, <a href="#cve-2026-82009">CVE-2026-82009</a>, <a href="#cve-2026-82010">CVE-2026-82010</a>, <a href="#cve-2026-82011">CVE-2026-82011</a>, <a href="#cve-2026-82443">CVE-2026-82443</a>, <a href="#cve-2026-83660">CVE-2026-83660</a>, <a href="#cve-2026-84412">CVE-2026-84412</a>, <a href="#cve-2026-89275">CVE-2026-89275</a>, <a href="#cve-2026-89276">CVE-2026-89276</a>.</p>
<h2 id="cve-2026-82443">CVE-2026-82443</h2>
<p>Adobe Campaign Classic (ACC) is vulnerable to a Server-Side Request Forgery (SSRF) flaw that allows a low-privileged attacker to achieve privilege escalation. The vulnerability is exploitable remotely without user interaction and results in a change of security scope, potentially granting the attacker unauthorized access to internal resources.</p>
<p>Affected products:</p>
<ul>
<li>Campaign Classic</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-82443">https://nvd.nist.gov/vuln/detail/CVE-2026-82443</a></p>
<p>Related in this roundup: <a href="#cve-2026-82004">CVE-2026-82004</a>, <a href="#cve-2026-73369">CVE-2026-73369</a>, <a href="#cve-2026-75699">CVE-2026-75699</a>, <a href="#cve-2026-75703">CVE-2026-75703</a>, <a href="#cve-2026-75721">CVE-2026-75721</a>, <a href="#cve-2026-75723">CVE-2026-75723</a>, <a href="#cve-2026-75728">CVE-2026-75728</a>, <a href="#cve-2026-82008">CVE-2026-82008</a>, <a href="#cve-2026-82009">CVE-2026-82009</a>, <a href="#cve-2026-82010">CVE-2026-82010</a>, <a href="#cve-2026-82011">CVE-2026-82011</a>, <a href="#cve-2026-82013">CVE-2026-82013</a>, <a href="#cve-2026-83660">CVE-2026-83660</a>, <a href="#cve-2026-84412">CVE-2026-84412</a>, <a href="#cve-2026-89275">CVE-2026-89275</a>, <a href="#cve-2026-89276">CVE-2026-89276</a>.</p>
<h2 id="cve-2026-83660">CVE-2026-83660</h2>
<p>Adobe Campaign Classic (ACC) is vulnerable to a Server-Side Request Forgery (SSRF) flaw that can be exploited by a remote attacker without user interaction to achieve privilege escalation. Due to the changed scope of the vulnerability and the high CVSS score, it represents a significant risk to the integrity and authorization controls of the Campaign Classic environment.</p>
<p>Affected products:</p>
<ul>
<li>Campaign Classic</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-83660">https://nvd.nist.gov/vuln/detail/CVE-2026-83660</a></p>
<p>Related in this roundup: <a href="#cve-2026-82004">CVE-2026-82004</a>, <a href="#cve-2026-73369">CVE-2026-73369</a>, <a href="#cve-2026-75699">CVE-2026-75699</a>, <a href="#cve-2026-75703">CVE-2026-75703</a>, <a href="#cve-2026-75721">CVE-2026-75721</a>, <a href="#cve-2026-75723">CVE-2026-75723</a>, <a href="#cve-2026-75728">CVE-2026-75728</a>, <a href="#cve-2026-82008">CVE-2026-82008</a>, <a href="#cve-2026-82009">CVE-2026-82009</a>, <a href="#cve-2026-82010">CVE-2026-82010</a>, <a href="#cve-2026-82011">CVE-2026-82011</a>, <a href="#cve-2026-82013">CVE-2026-82013</a>, <a href="#cve-2026-82443">CVE-2026-82443</a>, <a href="#cve-2026-84412">CVE-2026-84412</a>, <a href="#cve-2026-89275">CVE-2026-89275</a>, <a href="#cve-2026-89276">CVE-2026-89276</a>.</p>
<h2 id="cve-2026-84412">CVE-2026-84412</h2>
<p>Adobe Campaign Classic (ACC) is susceptible to a code injection vulnerability that allows an unauthenticated remote attacker to execute arbitrary code within the context of the current user. The vulnerability does not require user interaction and involves a change in scope, carrying a CVSS base score of 10.0.</p>
<p>Affected products:</p>
<ul>
<li>Campaign Classic</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-84412">https://nvd.nist.gov/vuln/detail/CVE-2026-84412</a></p>
<p>Related in this roundup: <a href="#cve-2026-82004">CVE-2026-82004</a>, <a href="#cve-2026-73369">CVE-2026-73369</a>, <a href="#cve-2026-75699">CVE-2026-75699</a>, <a href="#cve-2026-75703">CVE-2026-75703</a>, <a href="#cve-2026-75721">CVE-2026-75721</a>, <a href="#cve-2026-75723">CVE-2026-75723</a>, <a href="#cve-2026-75728">CVE-2026-75728</a>, <a href="#cve-2026-82008">CVE-2026-82008</a>, <a href="#cve-2026-82009">CVE-2026-82009</a>, <a href="#cve-2026-82010">CVE-2026-82010</a>, <a href="#cve-2026-82011">CVE-2026-82011</a>, <a href="#cve-2026-82013">CVE-2026-82013</a>, <a href="#cve-2026-82443">CVE-2026-82443</a>, <a href="#cve-2026-83660">CVE-2026-83660</a>, <a href="#cve-2026-89275">CVE-2026-89275</a>, <a href="#cve-2026-89276">CVE-2026-89276</a>.</p>
<h2 id="cve-2026-89275">CVE-2026-89275</h2>
<p>Adobe Campaign Classic (ACC) is vulnerable to a code injection vulnerability, classified as CVE-2026-89275, which allows an unauthenticated attacker to achieve remote code execution in the context of the current user. The vulnerability does not require user interaction and involves a change in scope, carrying a CVSS v3.1 base score of 10.0.</p>
<p>Affected products:</p>
<ul>
<li>Campaign Classic</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-89275">https://nvd.nist.gov/vuln/detail/CVE-2026-89275</a></p>
<p>Related in this roundup: <a href="#cve-2026-82004">CVE-2026-82004</a>, <a href="#cve-2026-73369">CVE-2026-73369</a>, <a href="#cve-2026-75699">CVE-2026-75699</a>, <a href="#cve-2026-75703">CVE-2026-75703</a>, <a href="#cve-2026-75721">CVE-2026-75721</a>, <a href="#cve-2026-75723">CVE-2026-75723</a>, <a href="#cve-2026-75728">CVE-2026-75728</a>, <a href="#cve-2026-82008">CVE-2026-82008</a>, <a href="#cve-2026-82009">CVE-2026-82009</a>, <a href="#cve-2026-82010">CVE-2026-82010</a>, <a href="#cve-2026-82011">CVE-2026-82011</a>, <a href="#cve-2026-82013">CVE-2026-82013</a>, <a href="#cve-2026-82443">CVE-2026-82443</a>, <a href="#cve-2026-83660">CVE-2026-83660</a>, <a href="#cve-2026-84412">CVE-2026-84412</a>, <a href="#cve-2026-89276">CVE-2026-89276</a>.</p>
<h2 id="cve-2026-89276">CVE-2026-89276</h2>
<p>CVE-2026-89276 is a critical code injection vulnerability in Adobe Campaign Classic that allows a low-privileged attacker to achieve remote code execution without user interaction. The vulnerability results in a change of scope, and successful exploitation grants the attacker the execution privileges of the current user context.</p>
<p>Affected products:</p>
<ul>
<li>Campaign Classic</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-89276">https://nvd.nist.gov/vuln/detail/CVE-2026-89276</a></p>
<p>Related in this roundup: <a href="#cve-2026-82004">CVE-2026-82004</a>, <a href="#cve-2026-73369">CVE-2026-73369</a>, <a href="#cve-2026-75699">CVE-2026-75699</a>, <a href="#cve-2026-75703">CVE-2026-75703</a>, <a href="#cve-2026-75721">CVE-2026-75721</a>, <a href="#cve-2026-75723">CVE-2026-75723</a>, <a href="#cve-2026-75728">CVE-2026-75728</a>, <a href="#cve-2026-82008">CVE-2026-82008</a>, <a href="#cve-2026-82009">CVE-2026-82009</a>, <a href="#cve-2026-82010">CVE-2026-82010</a>, <a href="#cve-2026-82011">CVE-2026-82011</a>, <a href="#cve-2026-82013">CVE-2026-82013</a>, <a href="#cve-2026-82443">CVE-2026-82443</a>, <a href="#cve-2026-83660">CVE-2026-83660</a>, <a href="#cve-2026-84412">CVE-2026-84412</a>, <a href="#cve-2026-89275">CVE-2026-89275</a>.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>roundup</category></item></channel></rss>