{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aadobecoldfusion2023update23/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:adobe:commerce:*:*:*:*:*:*:*:*","cpe:2.3:a:adobe:commerce:2.4.4:-:*:*:*:*:*:*","cpe:2.3:a:adobe:commerce:2.4.4:p1:*:*:*:*:*:*","cpe:2.3:a:adobe:commerce:2.4.4:p10:*:*:*:*:*:*","cpe:2.3:a:adobe:commerce:2.4.4:p11:*:*:*:*:*:*","cpe:2.3:a:adobe:commerce:2.4.4:p12:*:*:*:*:*:*","cpe:2.3:a:adobe:commerce:2.4.4:p13:*:*:*:*:*:*","cpe:2.3:a:adobe:commerce:2.4.4:p14:*:*:*:*:*:*","cpe:2.3:a:adobe:commerce:2.4.4:p15:*:*:*:*:*:*","cpe:2.3:a:adobe:commerce:2.4.4:p16:*:*:*:*:*:*","cpe:2.3:a:adobe:commerce:2.4.4:p17:*:*:*:*:*:*","cpe:2.3:a:adobe:commerce:2.4.4:p18:*:*:*:*:*:*","cpe:2.3:a:adobe:commerce:2.4.4:p2:*:*:*:*:*:*","cpe:2.3:a:adobe:commerce:2.4.4:p3:*:*:*:*:*:*","cpe:2.3:a:adobe:commerce:2.4.4:p4:*:*:*:*:*:*","cpe:2.3:a:adobe:commerce:2.4.4:p5:*:*:*:*:*:*","cpe:2.3:a:adobe:commerce:2.4.4:p6:*:*:*:*:*:*","cpe:2.3:a:adobe:commerce:2.4.4:p7:*:*:*:*:*:*","cpe:2.3:a:adobe:commerce:2.4.4:p8:*:*:*:*:*:*","cpe:2.3:a:adobe:commerce:2.4.4:p9:*:*:*:*:*:*","cpe:2.3:a:adobe:magento:*:*:*:*:open_source:*:*:*","cpe:2.3:a:adobe:magento:2.4.7:-:*:*:open_source:*:*:*","cpe:2.3:a:adobe:magento:2.4.7:b1:*:*:open_source:*:*:*","cpe:2.3:a:adobe:magento:2.4.7:b2:*:*:open_source:*:*:*","cpe:2.3:a:adobe:magento:2.4.7:beta3:*:*:open_source:*:*:*","cpe:2.3:a:adobe:magento:2.4.7:p1:*:*:open_source:*:*:*","cpe:2.3:a:adobe:magento:2.4.7:p10:*:*:open_source:*:*:*","cpe:2.3:a:adobe:magento:2.4.7:p2:*:*:open_source:*:*:*","cpe:2.3:a:adobe:magento:2.4.7:p3:*:*:open_source:*:*:*","cpe:2.3:a:adobe:magento:2.4.7:p4:*:*:open_source:*:*:*","cpe:2.3:a:adobe:magento:2.4.7:p5:*:*:open_source:*:*:*","cpe:2.3:a:adobe:magento:2.4.7:p6:*:*:open_source:*:*:*","cpe:2.3:a:adobe:magento:2.4.7:p7:*:*:open_source:*:*:*","cpe:2.3:a:adobe:magento:2.4.7:p8:*:*:open_source:*:*:*","cpe:2.3:a:adobe:magento:2.4.7:p9:*:*:open_source:*:*:*","cpe:2.3:a:adobe:magento:2.4.8:-:*:*:open_source:*:*:*","cpe:2.3:a:adobe:magento:2.4.8:beta1:*:*:open_source:*:*:*","cpe:2.3:a:adobe:magento:2.4.8:beta2:*:*:open_source:*:*:*","cpe:2.3:a:adobe:magento:2.4.8:p1:*:*:open_source:*:*:*","cpe:2.3:a:adobe:magento:2.4.8:p2:*:*:open_source:*:*:*","cpe:2.3:a:adobe:campaign:*:*:*:*:classic:*:*:*","cpe:2.3:a:adobe:campaign:7.4.4:9400:*:*:classic:*:*:*","cpe:2.3:a:adobe:campaign:7.4.4:9401:*:*:classic:*:*:*","cpe:2.3:a:adobe:coldfusion:2023:-:*:*:*:*:*:*","cpe:2.3:a:adobe:coldfusion:2023:update1:*:*:*:*:*:*","cpe:2.3:a:adobe:coldfusion:2023:update10:*:*:*:*:*:*","cpe:2.3:a:adobe:coldfusion:2023:update11:*:*:*:*:*:*","cpe:2.3:a:adobe:coldfusion:2023:update12:*:*:*:*:*:*","cpe:2.3:a:adobe:coldfusion:2023:update13:*:*:*:*:*:*","cpe:2.3:a:adobe:coldfusion:2023:update14:*:*:*:*:*:*","cpe:2.3:a:adobe:coldfusion:2023:update15:*:*:*:*:*:*","cpe:2.3:a:adobe:coldfusion:2023:update16:*:*:*:*:*:*","cpe:2.3:a:adobe:coldfusion:2023:update17:*:*:*:*:*:*","cpe:2.3:a:adobe:coldfusion:2023:update18:*:*:*:*:*:*","cpe:2.3:a:adobe:coldfusion:2023:update19:*:*:*:*:*:*","cpe:2.3:a:adobe:coldfusion:2023:update2:*:*:*:*:*:*","cpe:2.3:a:adobe:coldfusion:2023:update20:*:*:*:*:*:*","cpe:2.3:a:adobe:coldfusion:2023:update21:*:*:*:*:*:*","cpe:2.3:a:adobe:coldfusion:2023:update22:*:*:*:*:*:*","cpe:2.3:a:adobe:coldfusion:2023:update23:*:*:*:*:*:*","cpe:2.3:a:adobe:coldfusion:2023:update3:*:*:*:*:*:*","cpe:2.3:a:adobe:coldfusion:2023:update4:*:*:*:*:*:*","cpe:2.3:a:adobe:coldfusion:2023:update5:*:*:*:*:*:*","cpe:2.3:a:adobe:experience_manager:*:-:*:*:lts:*:*:*","cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:*","cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:*","cpe:2.3:a:adobe:experience_manager:6.5:-:*:*:lts:*:*:*","cpe:2.3:a:adobe:experience_manager:6.5:sp1:*:*:lts:*:*:*","cpe:2.3:a:adobe:experience_manager:6.5:sp2:*:*:lts:*:*:*","cpe:2.3:a:adobe:substance_3d_sampler:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-83959"},{"cvss":9.3,"id":"CVE-2026-76200"},{"cvss":9.3,"id":"CVE-2026-76201"},{"cvss":10,"id":"CVE-2026-82004"},{"cvss":9.9,"id":"CVE-2026-19232"},{"cvss":9.9,"id":"CVE-2026-48273"},{"cvss":9.1,"id":"CVE-2026-75746"},{"cvss":10,"id":"CVE-2026-75699"},{"cvss":10,"id":"CVE-2026-75723"},{"cvss":9.1,"id":"CVE-2026-82009"},{"cvss":9.9,"id":"CVE-2026-82010"},{"cvss":10,"id":"CVE-2026-89275"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["high"],"_cs_tags":["roundup"],"_cs_type":"threat","_cs_vendors":["Adobe"],"content_html":"\u003cp\u003eThis roundup covers 24 Adobe security vulnerabilities. CVSS base scores range from 7.8 to 10.0. None are reported as actively exploited at the time of release. The issues affect Adobe Commerce, Campaign Classic, ColdFusion, Commerce, Experience Manager, Substance 3D Sampler.\u003c/p\u003e\n\u003ch2 id=\"summary\"\u003eSummary\u003c/h2\u003e\n\u003ctable\u003e\n\t\u003cthead\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003cth\u003eCVE\u003c/th\u003e\n\t\t\t\t\t\u003cth\u003eProduct\u003c/th\u003e\n\t\t\t\t\t\u003cth\u003eSeverity\u003c/th\u003e\n\t\t\t\t\t\u003cth\u003eCVSS\u003c/th\u003e\n\t\t\t\t\t\u003cth\u003eEPSS\u003c/th\u003e\n\t\t\t\t\t\u003cth\u003eKEV\u003c/th\u003e\n\t\t\t\t\t\u003cth\u003eSource\u003c/th\u003e\n\t\t\t\u003c/tr\u003e\n\t\u003c/thead\u003e\n\t\u003ctbody\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"#cve-2026-83959\"\u003eCVE-2026-83959\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eSubstance 3D Sampler\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eHigh\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e7.8\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e0.17%\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eno\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-83959\"\u003eNVD\u003c/a\u003e (authoritative)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"#cve-2026-75650\"\u003eCVE-2026-75650\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eAdobe Commerce\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eno\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-75650\"\u003eNVD\u003c/a\u003e (authoritative)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"#cve-2026-76200\"\u003eCVE-2026-76200\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eCommerce\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eCritical\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e9.3\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e0.46%\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eno\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-76200\"\u003eNVD\u003c/a\u003e (authoritative)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"#cve-2026-76201\"\u003eCVE-2026-76201\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eCommerce\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eCritical\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e9.3\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e0.46%\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eno\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-76201\"\u003eNVD\u003c/a\u003e (authoritative)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"#cve-2026-82004\"\u003eCVE-2026-82004\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eCampaign Classic\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eCritical\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e10.0\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e1.44%\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eno\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-82004\"\u003eNVD\u003c/a\u003e (authoritative)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"#cve-2026-19232\"\u003eCVE-2026-19232\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eExperience Manager\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eCritical\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e9.9\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e0.57%\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eno\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-19232\"\u003eNVD\u003c/a\u003e (authoritative)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"#cve-2026-48273\"\u003eCVE-2026-48273\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eColdFusion\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eCritical\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e9.9\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e1.90%\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eno\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-48273\"\u003eNVD\u003c/a\u003e (authoritative)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"#cve-2026-75746\"\u003eCVE-2026-75746\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eColdFusion\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eCritical\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e9.1\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e1.07%\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eno\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-75746\"\u003eNVD\u003c/a\u003e (authoritative)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"#cve-2026-73369\"\u003eCVE-2026-73369\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eCampaign Classic\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eno\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-73369\"\u003eNVD\u003c/a\u003e (authoritative)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"#cve-2026-75699\"\u003eCVE-2026-75699\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eCampaign Classic\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eCritical\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e10.0\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eno\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-75699\"\u003eNVD\u003c/a\u003e (authoritative)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"#cve-2026-75703\"\u003eCVE-2026-75703\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eCampaign Classic\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eno\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-75703\"\u003eNVD\u003c/a\u003e (authoritative)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"#cve-2026-75721\"\u003eCVE-2026-75721\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eCampaign Classic\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eno\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-75721\"\u003eNVD\u003c/a\u003e (authoritative)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"#cve-2026-75723\"\u003eCVE-2026-75723\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eCampaign Classic\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eCritical\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e10.0\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eno\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-75723\"\u003eNVD\u003c/a\u003e (authoritative)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"#cve-2026-75728\"\u003eCVE-2026-75728\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eCampaign Classic\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eno\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-75728\"\u003eNVD\u003c/a\u003e (authoritative)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"#cve-2026-82008\"\u003eCVE-2026-82008\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eCampaign Classic\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eno\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-82008\"\u003eNVD\u003c/a\u003e (authoritative)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"#cve-2026-82009\"\u003eCVE-2026-82009\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eCampaign Classic\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eCritical\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e9.1\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eno\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-82009\"\u003eNVD\u003c/a\u003e (authoritative)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"#cve-2026-82010\"\u003eCVE-2026-82010\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eCampaign Classic\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eCritical\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e9.9\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eno\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-82010\"\u003eNVD\u003c/a\u003e (authoritative)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"#cve-2026-82011\"\u003eCVE-2026-82011\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eCampaign Classic\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eno\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-82011\"\u003eNVD\u003c/a\u003e (authoritative)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"#cve-2026-82013\"\u003eCVE-2026-82013\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eCampaign Classic\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eno\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-82013\"\u003eNVD\u003c/a\u003e (authoritative)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"#cve-2026-82443\"\u003eCVE-2026-82443\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eCampaign Classic\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eno\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-82443\"\u003eNVD\u003c/a\u003e (authoritative)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"#cve-2026-83660\"\u003eCVE-2026-83660\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eCampaign Classic\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eno\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-83660\"\u003eNVD\u003c/a\u003e (authoritative)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"#cve-2026-84412\"\u003eCVE-2026-84412\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eCampaign Classic\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eno\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-84412\"\u003eNVD\u003c/a\u003e (authoritative)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"#cve-2026-89275\"\u003eCVE-2026-89275\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eCampaign Classic\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eno\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-89275\"\u003eNVD\u003c/a\u003e (authoritative)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"#cve-2026-89276\"\u003eCVE-2026-89276\u003c/a\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eCampaign Classic\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eno\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e\u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-89276\"\u003eNVD\u003c/a\u003e (authoritative)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch2 id=\"cve-2026-83959\"\u003eCVE-2026-83959\u003c/h2\u003e\n\u003cp\u003eAdobe Substance 3D Sampler contains a heap-based buffer overflow vulnerability triggered by opening a malicious file. Successful exploitation allows an attacker to achieve arbitrary code execution in the context of the current user, requiring user interaction to open the crafted file.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eSubstance 3D Sampler\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-83959\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-83959\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"cve-2026-75650\"\u003eCVE-2026-75650\u003c/h2\u003e\n\u003cp\u003eAdobe Commerce contains a vulnerability involving improper neutralization of special elements used in a template engine, which allows an unauthenticated attacker to execute arbitrary code. The vulnerability is categorized as remote code execution, does not require user interaction, and impacts the integrity and availability of the system.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdobe Commerce\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-75650\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-75650\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"cve-2026-76200\"\u003eCVE-2026-76200\u003c/h2\u003e\n\u003cp\u003eAdobe Commerce contains a stored Cross-Site Scripting (XSS) vulnerability allowing attackers to inject malicious JavaScript into form fields. When a victim accesses the affected page, the script executes within the victim's session, potentially leading to unauthorized account access or session hijacking.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eCommerce\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-76200\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-76200\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eRelated in this roundup: \u003ca href=\"#cve-2026-76201\"\u003eCVE-2026-76201\u003c/a\u003e.\u003c/p\u003e\n\u003ch2 id=\"cve-2026-76201\"\u003eCVE-2026-76201\u003c/h2\u003e\n\u003cp\u003eAdobe Commerce contains a stored Cross-Site Scripting (XSS) vulnerability allowing an attacker to inject malicious scripts into form fields. When a victim accesses the affected page, the script executes in their browser, potentially leading to session hijacking or unauthorized account access.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eCommerce\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-76201\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-76201\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eRelated in this roundup: \u003ca href=\"#cve-2026-76200\"\u003eCVE-2026-76200\u003c/a\u003e.\u003c/p\u003e\n\u003ch2 id=\"cve-2026-82004\"\u003eCVE-2026-82004\u003c/h2\u003e\n\u003cp\u003eAdobe Campaign Classic (ACC) is vulnerable to an OS command injection flaw (CVE-2026-82004) that allows unauthenticated attackers to achieve remote code execution in the context of the current user without requiring user interaction. The vulnerability has a CVSS v3.1 base score of 10.0 and involves a changed scope, indicating potential impact beyond the affected service.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eCampaign Classic\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-82004\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-82004\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eRelated in this roundup: \u003ca href=\"#cve-2026-73369\"\u003eCVE-2026-73369\u003c/a\u003e, \u003ca href=\"#cve-2026-75699\"\u003eCVE-2026-75699\u003c/a\u003e, \u003ca href=\"#cve-2026-75703\"\u003eCVE-2026-75703\u003c/a\u003e, \u003ca href=\"#cve-2026-75721\"\u003eCVE-2026-75721\u003c/a\u003e, \u003ca href=\"#cve-2026-75723\"\u003eCVE-2026-75723\u003c/a\u003e, \u003ca href=\"#cve-2026-75728\"\u003eCVE-2026-75728\u003c/a\u003e, \u003ca href=\"#cve-2026-82008\"\u003eCVE-2026-82008\u003c/a\u003e, \u003ca href=\"#cve-2026-82009\"\u003eCVE-2026-82009\u003c/a\u003e, \u003ca href=\"#cve-2026-82010\"\u003eCVE-2026-82010\u003c/a\u003e, \u003ca href=\"#cve-2026-82011\"\u003eCVE-2026-82011\u003c/a\u003e, \u003ca href=\"#cve-2026-82013\"\u003eCVE-2026-82013\u003c/a\u003e, \u003ca href=\"#cve-2026-82443\"\u003eCVE-2026-82443\u003c/a\u003e, \u003ca href=\"#cve-2026-83660\"\u003eCVE-2026-83660\u003c/a\u003e, \u003ca href=\"#cve-2026-84412\"\u003eCVE-2026-84412\u003c/a\u003e, \u003ca href=\"#cve-2026-89275\"\u003eCVE-2026-89275\u003c/a\u003e, \u003ca href=\"#cve-2026-89276\"\u003eCVE-2026-89276\u003c/a\u003e.\u003c/p\u003e\n\u003ch2 id=\"cve-2026-19232\"\u003eCVE-2026-19232\u003c/h2\u003e\n\u003cp\u003eAdobe Experience Manager is vulnerable to an incorrect authorization flaw that allows a low-privileged attacker to achieve arbitrary code execution. The vulnerability does not require user interaction and can result in the attacker gaining elevated access or control over a victim's session, leading to a full compromise of the affected account scope.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eExperience Manager\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-19232\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-19232\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"cve-2026-48273\"\u003eCVE-2026-48273\u003c/h2\u003e\n\u003cp\u003eAdobe ColdFusion is vulnerable to an improper neutralization of directives in dynamically evaluated code (Eval Injection), which allows a low-privileged attacker to achieve remote code execution without user interaction. The vulnerability results in a change of scope, significantly increasing the impact of successful exploitation.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eColdFusion\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-48273\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-48273\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eRelated in this roundup: \u003ca href=\"#cve-2026-75746\"\u003eCVE-2026-75746\u003c/a\u003e.\u003c/p\u003e\n\u003ch2 id=\"cve-2026-75746\"\u003eCVE-2026-75746\u003c/h2\u003e\n\u003cp\u003eAdobe ColdFusion is vulnerable to a high-severity SQL injection flaw (CVE-2026-75746) that allows a highly privileged attacker to achieve remote code execution. The vulnerability does not require user interaction and impacts the integrity and availability of the application environment.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eColdFusion\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-75746\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-75746\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eRelated in this roundup: \u003ca href=\"#cve-2026-48273\"\u003eCVE-2026-48273\u003c/a\u003e.\u003c/p\u003e\n\u003ch2 id=\"cve-2026-73369\"\u003eCVE-2026-73369\u003c/h2\u003e\n\u003cp\u003eAdobe Campaign Classic (ACC) is vulnerable to a code injection vulnerability (CVE-2026-73369) that allows for remote code execution in the context of the current user. The vulnerability does not require user interaction for exploitation and is classified as having a CVSS v3.1 base score of 10.0.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eCampaign Classic\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-73369\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-73369\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eRelated in this roundup: \u003ca href=\"#cve-2026-82004\"\u003eCVE-2026-82004\u003c/a\u003e, \u003ca href=\"#cve-2026-75699\"\u003eCVE-2026-75699\u003c/a\u003e, \u003ca href=\"#cve-2026-75703\"\u003eCVE-2026-75703\u003c/a\u003e, \u003ca href=\"#cve-2026-75721\"\u003eCVE-2026-75721\u003c/a\u003e, \u003ca href=\"#cve-2026-75723\"\u003eCVE-2026-75723\u003c/a\u003e, \u003ca href=\"#cve-2026-75728\"\u003eCVE-2026-75728\u003c/a\u003e, \u003ca href=\"#cve-2026-82008\"\u003eCVE-2026-82008\u003c/a\u003e, \u003ca href=\"#cve-2026-82009\"\u003eCVE-2026-82009\u003c/a\u003e, \u003ca href=\"#cve-2026-82010\"\u003eCVE-2026-82010\u003c/a\u003e, \u003ca href=\"#cve-2026-82011\"\u003eCVE-2026-82011\u003c/a\u003e, \u003ca href=\"#cve-2026-82013\"\u003eCVE-2026-82013\u003c/a\u003e, \u003ca href=\"#cve-2026-82443\"\u003eCVE-2026-82443\u003c/a\u003e, \u003ca href=\"#cve-2026-83660\"\u003eCVE-2026-83660\u003c/a\u003e, \u003ca href=\"#cve-2026-84412\"\u003eCVE-2026-84412\u003c/a\u003e, \u003ca href=\"#cve-2026-89275\"\u003eCVE-2026-89275\u003c/a\u003e, \u003ca href=\"#cve-2026-89276\"\u003eCVE-2026-89276\u003c/a\u003e.\u003c/p\u003e\n\u003ch2 id=\"cve-2026-75699\"\u003eCVE-2026-75699\u003c/h2\u003e\n\u003cp\u003eAdobe Campaign Classic (ACC) contains a code injection vulnerability that allows an unauthenticated attacker to execute arbitrary code with the privileges of the application user. This issue is categorized as a critical risk with a CVSS score of 10.0, as it does not require user interaction and impacts the overall system integrity and confidentiality.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eCampaign Classic\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-75699\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-75699\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eRelated in this roundup: \u003ca href=\"#cve-2026-82004\"\u003eCVE-2026-82004\u003c/a\u003e, \u003ca href=\"#cve-2026-73369\"\u003eCVE-2026-73369\u003c/a\u003e, \u003ca href=\"#cve-2026-75703\"\u003eCVE-2026-75703\u003c/a\u003e, \u003ca href=\"#cve-2026-75721\"\u003eCVE-2026-75721\u003c/a\u003e, \u003ca href=\"#cve-2026-75723\"\u003eCVE-2026-75723\u003c/a\u003e, \u003ca href=\"#cve-2026-75728\"\u003eCVE-2026-75728\u003c/a\u003e, \u003ca href=\"#cve-2026-82008\"\u003eCVE-2026-82008\u003c/a\u003e, \u003ca href=\"#cve-2026-82009\"\u003eCVE-2026-82009\u003c/a\u003e, \u003ca href=\"#cve-2026-82010\"\u003eCVE-2026-82010\u003c/a\u003e, \u003ca href=\"#cve-2026-82011\"\u003eCVE-2026-82011\u003c/a\u003e, \u003ca href=\"#cve-2026-82013\"\u003eCVE-2026-82013\u003c/a\u003e, \u003ca href=\"#cve-2026-82443\"\u003eCVE-2026-82443\u003c/a\u003e, \u003ca href=\"#cve-2026-83660\"\u003eCVE-2026-83660\u003c/a\u003e, \u003ca href=\"#cve-2026-84412\"\u003eCVE-2026-84412\u003c/a\u003e, \u003ca href=\"#cve-2026-89275\"\u003eCVE-2026-89275\u003c/a\u003e, \u003ca href=\"#cve-2026-89276\"\u003eCVE-2026-89276\u003c/a\u003e.\u003c/p\u003e\n\u003ch2 id=\"cve-2026-75703\"\u003eCVE-2026-75703\u003c/h2\u003e\n\u003cp\u003eCVE-2026-75703 identifies an improper control of generation of code vulnerability in Adobe Campaign Classic (ACC). The vulnerability allows a remote, unauthenticated attacker to execute arbitrary code in the context of the current user without requiring user interaction. The impact includes a full compromise of the service integrity and availability (CVSS 10.0), necessitating immediate patching.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eCampaign Classic\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-75703\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-75703\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eRelated in this roundup: \u003ca href=\"#cve-2026-82004\"\u003eCVE-2026-82004\u003c/a\u003e, \u003ca href=\"#cve-2026-73369\"\u003eCVE-2026-73369\u003c/a\u003e, \u003ca href=\"#cve-2026-75699\"\u003eCVE-2026-75699\u003c/a\u003e, \u003ca href=\"#cve-2026-75721\"\u003eCVE-2026-75721\u003c/a\u003e, \u003ca href=\"#cve-2026-75723\"\u003eCVE-2026-75723\u003c/a\u003e, \u003ca href=\"#cve-2026-75728\"\u003eCVE-2026-75728\u003c/a\u003e, \u003ca href=\"#cve-2026-82008\"\u003eCVE-2026-82008\u003c/a\u003e, \u003ca href=\"#cve-2026-82009\"\u003eCVE-2026-82009\u003c/a\u003e, \u003ca href=\"#cve-2026-82010\"\u003eCVE-2026-82010\u003c/a\u003e, \u003ca href=\"#cve-2026-82011\"\u003eCVE-2026-82011\u003c/a\u003e, \u003ca href=\"#cve-2026-82013\"\u003eCVE-2026-82013\u003c/a\u003e, \u003ca href=\"#cve-2026-82443\"\u003eCVE-2026-82443\u003c/a\u003e, \u003ca href=\"#cve-2026-83660\"\u003eCVE-2026-83660\u003c/a\u003e, \u003ca href=\"#cve-2026-84412\"\u003eCVE-2026-84412\u003c/a\u003e, \u003ca href=\"#cve-2026-89275\"\u003eCVE-2026-89275\u003c/a\u003e, \u003ca href=\"#cve-2026-89276\"\u003eCVE-2026-89276\u003c/a\u003e.\u003c/p\u003e\n\u003ch2 id=\"cve-2026-75721\"\u003eCVE-2026-75721\u003c/h2\u003e\n\u003cp\u003eAdobe Campaign Classic is vulnerable to an Improper Control of Generation of Code ('Code Injection') vulnerability, allowing an unauthenticated remote attacker to execute arbitrary code within the context of the application user. The vulnerability carries a CVSS base score of 10.0 and does not require user interaction to exploit.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eCampaign Classic\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-75721\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-75721\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eRelated in this roundup: \u003ca href=\"#cve-2026-82004\"\u003eCVE-2026-82004\u003c/a\u003e, \u003ca href=\"#cve-2026-73369\"\u003eCVE-2026-73369\u003c/a\u003e, \u003ca href=\"#cve-2026-75699\"\u003eCVE-2026-75699\u003c/a\u003e, \u003ca href=\"#cve-2026-75703\"\u003eCVE-2026-75703\u003c/a\u003e, \u003ca href=\"#cve-2026-75723\"\u003eCVE-2026-75723\u003c/a\u003e, \u003ca href=\"#cve-2026-75728\"\u003eCVE-2026-75728\u003c/a\u003e, \u003ca href=\"#cve-2026-82008\"\u003eCVE-2026-82008\u003c/a\u003e, \u003ca href=\"#cve-2026-82009\"\u003eCVE-2026-82009\u003c/a\u003e, \u003ca href=\"#cve-2026-82010\"\u003eCVE-2026-82010\u003c/a\u003e, \u003ca href=\"#cve-2026-82011\"\u003eCVE-2026-82011\u003c/a\u003e, \u003ca href=\"#cve-2026-82013\"\u003eCVE-2026-82013\u003c/a\u003e, \u003ca href=\"#cve-2026-82443\"\u003eCVE-2026-82443\u003c/a\u003e, \u003ca href=\"#cve-2026-83660\"\u003eCVE-2026-83660\u003c/a\u003e, \u003ca href=\"#cve-2026-84412\"\u003eCVE-2026-84412\u003c/a\u003e, \u003ca href=\"#cve-2026-89275\"\u003eCVE-2026-89275\u003c/a\u003e, \u003ca href=\"#cve-2026-89276\"\u003eCVE-2026-89276\u003c/a\u003e.\u003c/p\u003e\n\u003ch2 id=\"cve-2026-75723\"\u003eCVE-2026-75723\u003c/h2\u003e\n\u003cp\u003eAdobe Campaign Classic (ACC) is vulnerable to an incorrect authorization flaw that allows an attacker to achieve arbitrary code execution. The vulnerability does not require user interaction and impacts the system scope, presenting a high risk for potential exploitation.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eCampaign Classic\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-75723\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-75723\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eRelated in this roundup: \u003ca href=\"#cve-2026-82004\"\u003eCVE-2026-82004\u003c/a\u003e, \u003ca href=\"#cve-2026-73369\"\u003eCVE-2026-73369\u003c/a\u003e, \u003ca href=\"#cve-2026-75699\"\u003eCVE-2026-75699\u003c/a\u003e, \u003ca href=\"#cve-2026-75703\"\u003eCVE-2026-75703\u003c/a\u003e, \u003ca href=\"#cve-2026-75721\"\u003eCVE-2026-75721\u003c/a\u003e, \u003ca href=\"#cve-2026-75728\"\u003eCVE-2026-75728\u003c/a\u003e, \u003ca href=\"#cve-2026-82008\"\u003eCVE-2026-82008\u003c/a\u003e, \u003ca href=\"#cve-2026-82009\"\u003eCVE-2026-82009\u003c/a\u003e, \u003ca href=\"#cve-2026-82010\"\u003eCVE-2026-82010\u003c/a\u003e, \u003ca href=\"#cve-2026-82011\"\u003eCVE-2026-82011\u003c/a\u003e, \u003ca href=\"#cve-2026-82013\"\u003eCVE-2026-82013\u003c/a\u003e, \u003ca href=\"#cve-2026-82443\"\u003eCVE-2026-82443\u003c/a\u003e, \u003ca href=\"#cve-2026-83660\"\u003eCVE-2026-83660\u003c/a\u003e, \u003ca href=\"#cve-2026-84412\"\u003eCVE-2026-84412\u003c/a\u003e, \u003ca href=\"#cve-2026-89275\"\u003eCVE-2026-89275\u003c/a\u003e, \u003ca href=\"#cve-2026-89276\"\u003eCVE-2026-89276\u003c/a\u003e.\u003c/p\u003e\n\u003ch2 id=\"cve-2026-75728\"\u003eCVE-2026-75728\u003c/h2\u003e\n\u003cp\u003eAdobe Campaign Classic (ACC) contains an incorrect authorization vulnerability that allows an unauthenticated attacker to achieve arbitrary code execution. The vulnerability does not require user interaction, making it a critical risk for deployments of the affected software.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eCampaign Classic\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-75728\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-75728\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eRelated in this roundup: \u003ca href=\"#cve-2026-82004\"\u003eCVE-2026-82004\u003c/a\u003e, \u003ca href=\"#cve-2026-73369\"\u003eCVE-2026-73369\u003c/a\u003e, \u003ca href=\"#cve-2026-75699\"\u003eCVE-2026-75699\u003c/a\u003e, \u003ca href=\"#cve-2026-75703\"\u003eCVE-2026-75703\u003c/a\u003e, \u003ca href=\"#cve-2026-75721\"\u003eCVE-2026-75721\u003c/a\u003e, \u003ca href=\"#cve-2026-75723\"\u003eCVE-2026-75723\u003c/a\u003e, \u003ca href=\"#cve-2026-82008\"\u003eCVE-2026-82008\u003c/a\u003e, \u003ca href=\"#cve-2026-82009\"\u003eCVE-2026-82009\u003c/a\u003e, \u003ca href=\"#cve-2026-82010\"\u003eCVE-2026-82010\u003c/a\u003e, \u003ca href=\"#cve-2026-82011\"\u003eCVE-2026-82011\u003c/a\u003e, \u003ca href=\"#cve-2026-82013\"\u003eCVE-2026-82013\u003c/a\u003e, \u003ca href=\"#cve-2026-82443\"\u003eCVE-2026-82443\u003c/a\u003e, \u003ca href=\"#cve-2026-83660\"\u003eCVE-2026-83660\u003c/a\u003e, \u003ca href=\"#cve-2026-84412\"\u003eCVE-2026-84412\u003c/a\u003e, \u003ca href=\"#cve-2026-89275\"\u003eCVE-2026-89275\u003c/a\u003e, \u003ca href=\"#cve-2026-89276\"\u003eCVE-2026-89276\u003c/a\u003e.\u003c/p\u003e\n\u003ch2 id=\"cve-2026-82008\"\u003eCVE-2026-82008\u003c/h2\u003e\n\u003cp\u003eAdobe Campaign Classic (ACC) is vulnerable to an improper input validation flaw that allows a low-privileged attacker to achieve remote code execution in the context of the current user without requiring user interaction. The vulnerability is considered high severity due to the potential for arbitrary code execution.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eCampaign Classic\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-82008\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-82008\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eRelated in this roundup: \u003ca href=\"#cve-2026-82004\"\u003eCVE-2026-82004\u003c/a\u003e, \u003ca href=\"#cve-2026-73369\"\u003eCVE-2026-73369\u003c/a\u003e, \u003ca href=\"#cve-2026-75699\"\u003eCVE-2026-75699\u003c/a\u003e, \u003ca href=\"#cve-2026-75703\"\u003eCVE-2026-75703\u003c/a\u003e, \u003ca href=\"#cve-2026-75721\"\u003eCVE-2026-75721\u003c/a\u003e, \u003ca href=\"#cve-2026-75723\"\u003eCVE-2026-75723\u003c/a\u003e, \u003ca href=\"#cve-2026-75728\"\u003eCVE-2026-75728\u003c/a\u003e, \u003ca href=\"#cve-2026-82009\"\u003eCVE-2026-82009\u003c/a\u003e, \u003ca href=\"#cve-2026-82010\"\u003eCVE-2026-82010\u003c/a\u003e, \u003ca href=\"#cve-2026-82011\"\u003eCVE-2026-82011\u003c/a\u003e, \u003ca href=\"#cve-2026-82013\"\u003eCVE-2026-82013\u003c/a\u003e, \u003ca href=\"#cve-2026-82443\"\u003eCVE-2026-82443\u003c/a\u003e, \u003ca href=\"#cve-2026-83660\"\u003eCVE-2026-83660\u003c/a\u003e, \u003ca href=\"#cve-2026-84412\"\u003eCVE-2026-84412\u003c/a\u003e, \u003ca href=\"#cve-2026-89275\"\u003eCVE-2026-89275\u003c/a\u003e, \u003ca href=\"#cve-2026-89276\"\u003eCVE-2026-89276\u003c/a\u003e.\u003c/p\u003e\n\u003ch2 id=\"cve-2026-82009\"\u003eCVE-2026-82009\u003c/h2\u003e\n\u003cp\u003eAdobe Campaign Classic (ACC) is vulnerable to a high-severity SQL injection flaw (CVE-2026-82009) that allows authenticated attackers with high privileges to execute arbitrary SQL commands. Successful exploitation can lead to arbitrary code execution within the context of the current user without requiring user interaction.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eCampaign Classic\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-82009\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-82009\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eRelated in this roundup: \u003ca href=\"#cve-2026-82004\"\u003eCVE-2026-82004\u003c/a\u003e, \u003ca href=\"#cve-2026-73369\"\u003eCVE-2026-73369\u003c/a\u003e, \u003ca href=\"#cve-2026-75699\"\u003eCVE-2026-75699\u003c/a\u003e, \u003ca href=\"#cve-2026-75703\"\u003eCVE-2026-75703\u003c/a\u003e, \u003ca href=\"#cve-2026-75721\"\u003eCVE-2026-75721\u003c/a\u003e, \u003ca href=\"#cve-2026-75723\"\u003eCVE-2026-75723\u003c/a\u003e, \u003ca href=\"#cve-2026-75728\"\u003eCVE-2026-75728\u003c/a\u003e, \u003ca href=\"#cve-2026-82008\"\u003eCVE-2026-82008\u003c/a\u003e, \u003ca href=\"#cve-2026-82010\"\u003eCVE-2026-82010\u003c/a\u003e, \u003ca href=\"#cve-2026-82011\"\u003eCVE-2026-82011\u003c/a\u003e, \u003ca href=\"#cve-2026-82013\"\u003eCVE-2026-82013\u003c/a\u003e, \u003ca href=\"#cve-2026-82443\"\u003eCVE-2026-82443\u003c/a\u003e, \u003ca href=\"#cve-2026-83660\"\u003eCVE-2026-83660\u003c/a\u003e, \u003ca href=\"#cve-2026-84412\"\u003eCVE-2026-84412\u003c/a\u003e, \u003ca href=\"#cve-2026-89275\"\u003eCVE-2026-89275\u003c/a\u003e, \u003ca href=\"#cve-2026-89276\"\u003eCVE-2026-89276\u003c/a\u003e.\u003c/p\u003e\n\u003ch2 id=\"cve-2026-82010\"\u003eCVE-2026-82010\u003c/h2\u003e\n\u003cp\u003eAdobe Campaign Classic (ACC) contains an SQL injection vulnerability that can be exploited by a low-privileged attacker to achieve arbitrary code execution. The vulnerability does not require user interaction and impacts the overall scope of the target application.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eCampaign Classic\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-82010\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-82010\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eRelated in this roundup: \u003ca href=\"#cve-2026-82004\"\u003eCVE-2026-82004\u003c/a\u003e, \u003ca href=\"#cve-2026-73369\"\u003eCVE-2026-73369\u003c/a\u003e, \u003ca href=\"#cve-2026-75699\"\u003eCVE-2026-75699\u003c/a\u003e, \u003ca href=\"#cve-2026-75703\"\u003eCVE-2026-75703\u003c/a\u003e, \u003ca href=\"#cve-2026-75721\"\u003eCVE-2026-75721\u003c/a\u003e, \u003ca href=\"#cve-2026-75723\"\u003eCVE-2026-75723\u003c/a\u003e, \u003ca href=\"#cve-2026-75728\"\u003eCVE-2026-75728\u003c/a\u003e, \u003ca href=\"#cve-2026-82008\"\u003eCVE-2026-82008\u003c/a\u003e, \u003ca href=\"#cve-2026-82009\"\u003eCVE-2026-82009\u003c/a\u003e, \u003ca href=\"#cve-2026-82011\"\u003eCVE-2026-82011\u003c/a\u003e, \u003ca href=\"#cve-2026-82013\"\u003eCVE-2026-82013\u003c/a\u003e, \u003ca href=\"#cve-2026-82443\"\u003eCVE-2026-82443\u003c/a\u003e, \u003ca href=\"#cve-2026-83660\"\u003eCVE-2026-83660\u003c/a\u003e, \u003ca href=\"#cve-2026-84412\"\u003eCVE-2026-84412\u003c/a\u003e, \u003ca href=\"#cve-2026-89275\"\u003eCVE-2026-89275\u003c/a\u003e, \u003ca href=\"#cve-2026-89276\"\u003eCVE-2026-89276\u003c/a\u003e.\u003c/p\u003e\n\u003ch2 id=\"cve-2026-82011\"\u003eCVE-2026-82011\u003c/h2\u003e\n\u003cp\u003eAdobe Campaign Classic is vulnerable to an SQL injection vulnerability that allows low-privileged attackers to bypass security measures, resulting in unauthorized read and limited write access to the application data. The vulnerability does not require user interaction and impacts the overall security scope of the affected system.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eCampaign Classic\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-82011\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-82011\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eRelated in this roundup: \u003ca href=\"#cve-2026-82004\"\u003eCVE-2026-82004\u003c/a\u003e, \u003ca href=\"#cve-2026-73369\"\u003eCVE-2026-73369\u003c/a\u003e, \u003ca href=\"#cve-2026-75699\"\u003eCVE-2026-75699\u003c/a\u003e, \u003ca href=\"#cve-2026-75703\"\u003eCVE-2026-75703\u003c/a\u003e, \u003ca href=\"#cve-2026-75721\"\u003eCVE-2026-75721\u003c/a\u003e, \u003ca href=\"#cve-2026-75723\"\u003eCVE-2026-75723\u003c/a\u003e, \u003ca href=\"#cve-2026-75728\"\u003eCVE-2026-75728\u003c/a\u003e, \u003ca href=\"#cve-2026-82008\"\u003eCVE-2026-82008\u003c/a\u003e, \u003ca href=\"#cve-2026-82009\"\u003eCVE-2026-82009\u003c/a\u003e, \u003ca href=\"#cve-2026-82010\"\u003eCVE-2026-82010\u003c/a\u003e, \u003ca href=\"#cve-2026-82013\"\u003eCVE-2026-82013\u003c/a\u003e, \u003ca href=\"#cve-2026-82443\"\u003eCVE-2026-82443\u003c/a\u003e, \u003ca href=\"#cve-2026-83660\"\u003eCVE-2026-83660\u003c/a\u003e, \u003ca href=\"#cve-2026-84412\"\u003eCVE-2026-84412\u003c/a\u003e, \u003ca href=\"#cve-2026-89275\"\u003eCVE-2026-89275\u003c/a\u003e, \u003ca href=\"#cve-2026-89276\"\u003eCVE-2026-89276\u003c/a\u003e.\u003c/p\u003e\n\u003ch2 id=\"cve-2026-82013\"\u003eCVE-2026-82013\u003c/h2\u003e\n\u003cp\u003eAdobe Campaign Classic (ACC) is vulnerable to a Server-Side Request Forgery (SSRF) flaw that allows low-privileged, unauthenticated attackers to perform privilege escalation. An attacker can leverage this vulnerability to gain unauthorized access to internal resources, with the exploit not requiring user interaction.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eCampaign Classic\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-82013\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-82013\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eRelated in this roundup: \u003ca href=\"#cve-2026-82004\"\u003eCVE-2026-82004\u003c/a\u003e, \u003ca href=\"#cve-2026-73369\"\u003eCVE-2026-73369\u003c/a\u003e, \u003ca href=\"#cve-2026-75699\"\u003eCVE-2026-75699\u003c/a\u003e, \u003ca href=\"#cve-2026-75703\"\u003eCVE-2026-75703\u003c/a\u003e, \u003ca href=\"#cve-2026-75721\"\u003eCVE-2026-75721\u003c/a\u003e, \u003ca href=\"#cve-2026-75723\"\u003eCVE-2026-75723\u003c/a\u003e, \u003ca href=\"#cve-2026-75728\"\u003eCVE-2026-75728\u003c/a\u003e, \u003ca href=\"#cve-2026-82008\"\u003eCVE-2026-82008\u003c/a\u003e, \u003ca href=\"#cve-2026-82009\"\u003eCVE-2026-82009\u003c/a\u003e, \u003ca href=\"#cve-2026-82010\"\u003eCVE-2026-82010\u003c/a\u003e, \u003ca href=\"#cve-2026-82011\"\u003eCVE-2026-82011\u003c/a\u003e, \u003ca href=\"#cve-2026-82443\"\u003eCVE-2026-82443\u003c/a\u003e, \u003ca href=\"#cve-2026-83660\"\u003eCVE-2026-83660\u003c/a\u003e, \u003ca href=\"#cve-2026-84412\"\u003eCVE-2026-84412\u003c/a\u003e, \u003ca href=\"#cve-2026-89275\"\u003eCVE-2026-89275\u003c/a\u003e, \u003ca href=\"#cve-2026-89276\"\u003eCVE-2026-89276\u003c/a\u003e.\u003c/p\u003e\n\u003ch2 id=\"cve-2026-82443\"\u003eCVE-2026-82443\u003c/h2\u003e\n\u003cp\u003eAdobe Campaign Classic (ACC) is vulnerable to a Server-Side Request Forgery (SSRF) flaw that allows a low-privileged attacker to achieve privilege escalation. The vulnerability is exploitable remotely without user interaction and results in a change of security scope, potentially granting the attacker unauthorized access to internal resources.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eCampaign Classic\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-82443\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-82443\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eRelated in this roundup: \u003ca href=\"#cve-2026-82004\"\u003eCVE-2026-82004\u003c/a\u003e, \u003ca href=\"#cve-2026-73369\"\u003eCVE-2026-73369\u003c/a\u003e, \u003ca href=\"#cve-2026-75699\"\u003eCVE-2026-75699\u003c/a\u003e, \u003ca href=\"#cve-2026-75703\"\u003eCVE-2026-75703\u003c/a\u003e, \u003ca href=\"#cve-2026-75721\"\u003eCVE-2026-75721\u003c/a\u003e, \u003ca href=\"#cve-2026-75723\"\u003eCVE-2026-75723\u003c/a\u003e, \u003ca href=\"#cve-2026-75728\"\u003eCVE-2026-75728\u003c/a\u003e, \u003ca href=\"#cve-2026-82008\"\u003eCVE-2026-82008\u003c/a\u003e, \u003ca href=\"#cve-2026-82009\"\u003eCVE-2026-82009\u003c/a\u003e, \u003ca href=\"#cve-2026-82010\"\u003eCVE-2026-82010\u003c/a\u003e, \u003ca href=\"#cve-2026-82011\"\u003eCVE-2026-82011\u003c/a\u003e, \u003ca href=\"#cve-2026-82013\"\u003eCVE-2026-82013\u003c/a\u003e, \u003ca href=\"#cve-2026-83660\"\u003eCVE-2026-83660\u003c/a\u003e, \u003ca href=\"#cve-2026-84412\"\u003eCVE-2026-84412\u003c/a\u003e, \u003ca href=\"#cve-2026-89275\"\u003eCVE-2026-89275\u003c/a\u003e, \u003ca href=\"#cve-2026-89276\"\u003eCVE-2026-89276\u003c/a\u003e.\u003c/p\u003e\n\u003ch2 id=\"cve-2026-83660\"\u003eCVE-2026-83660\u003c/h2\u003e\n\u003cp\u003eAdobe Campaign Classic (ACC) is vulnerable to a Server-Side Request Forgery (SSRF) flaw that can be exploited by a remote attacker without user interaction to achieve privilege escalation. Due to the changed scope of the vulnerability and the high CVSS score, it represents a significant risk to the integrity and authorization controls of the Campaign Classic environment.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eCampaign Classic\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-83660\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-83660\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eRelated in this roundup: \u003ca href=\"#cve-2026-82004\"\u003eCVE-2026-82004\u003c/a\u003e, \u003ca href=\"#cve-2026-73369\"\u003eCVE-2026-73369\u003c/a\u003e, \u003ca href=\"#cve-2026-75699\"\u003eCVE-2026-75699\u003c/a\u003e, \u003ca href=\"#cve-2026-75703\"\u003eCVE-2026-75703\u003c/a\u003e, \u003ca href=\"#cve-2026-75721\"\u003eCVE-2026-75721\u003c/a\u003e, \u003ca href=\"#cve-2026-75723\"\u003eCVE-2026-75723\u003c/a\u003e, \u003ca href=\"#cve-2026-75728\"\u003eCVE-2026-75728\u003c/a\u003e, \u003ca href=\"#cve-2026-82008\"\u003eCVE-2026-82008\u003c/a\u003e, \u003ca href=\"#cve-2026-82009\"\u003eCVE-2026-82009\u003c/a\u003e, \u003ca href=\"#cve-2026-82010\"\u003eCVE-2026-82010\u003c/a\u003e, \u003ca href=\"#cve-2026-82011\"\u003eCVE-2026-82011\u003c/a\u003e, \u003ca href=\"#cve-2026-82013\"\u003eCVE-2026-82013\u003c/a\u003e, \u003ca href=\"#cve-2026-82443\"\u003eCVE-2026-82443\u003c/a\u003e, \u003ca href=\"#cve-2026-84412\"\u003eCVE-2026-84412\u003c/a\u003e, \u003ca href=\"#cve-2026-89275\"\u003eCVE-2026-89275\u003c/a\u003e, \u003ca href=\"#cve-2026-89276\"\u003eCVE-2026-89276\u003c/a\u003e.\u003c/p\u003e\n\u003ch2 id=\"cve-2026-84412\"\u003eCVE-2026-84412\u003c/h2\u003e\n\u003cp\u003eAdobe Campaign Classic (ACC) is susceptible to a code injection vulnerability that allows an unauthenticated remote attacker to execute arbitrary code within the context of the current user. The vulnerability does not require user interaction and involves a change in scope, carrying a CVSS base score of 10.0.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eCampaign Classic\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-84412\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-84412\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eRelated in this roundup: \u003ca href=\"#cve-2026-82004\"\u003eCVE-2026-82004\u003c/a\u003e, \u003ca href=\"#cve-2026-73369\"\u003eCVE-2026-73369\u003c/a\u003e, \u003ca href=\"#cve-2026-75699\"\u003eCVE-2026-75699\u003c/a\u003e, \u003ca href=\"#cve-2026-75703\"\u003eCVE-2026-75703\u003c/a\u003e, \u003ca href=\"#cve-2026-75721\"\u003eCVE-2026-75721\u003c/a\u003e, \u003ca href=\"#cve-2026-75723\"\u003eCVE-2026-75723\u003c/a\u003e, \u003ca href=\"#cve-2026-75728\"\u003eCVE-2026-75728\u003c/a\u003e, \u003ca href=\"#cve-2026-82008\"\u003eCVE-2026-82008\u003c/a\u003e, \u003ca href=\"#cve-2026-82009\"\u003eCVE-2026-82009\u003c/a\u003e, \u003ca href=\"#cve-2026-82010\"\u003eCVE-2026-82010\u003c/a\u003e, \u003ca href=\"#cve-2026-82011\"\u003eCVE-2026-82011\u003c/a\u003e, \u003ca href=\"#cve-2026-82013\"\u003eCVE-2026-82013\u003c/a\u003e, \u003ca href=\"#cve-2026-82443\"\u003eCVE-2026-82443\u003c/a\u003e, \u003ca href=\"#cve-2026-83660\"\u003eCVE-2026-83660\u003c/a\u003e, \u003ca href=\"#cve-2026-89275\"\u003eCVE-2026-89275\u003c/a\u003e, \u003ca href=\"#cve-2026-89276\"\u003eCVE-2026-89276\u003c/a\u003e.\u003c/p\u003e\n\u003ch2 id=\"cve-2026-89275\"\u003eCVE-2026-89275\u003c/h2\u003e\n\u003cp\u003eAdobe Campaign Classic (ACC) is vulnerable to a code injection vulnerability, classified as CVE-2026-89275, which allows an unauthenticated attacker to achieve remote code execution in the context of the current user. The vulnerability does not require user interaction and involves a change in scope, carrying a CVSS v3.1 base score of 10.0.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eCampaign Classic\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-89275\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-89275\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eRelated in this roundup: \u003ca href=\"#cve-2026-82004\"\u003eCVE-2026-82004\u003c/a\u003e, \u003ca href=\"#cve-2026-73369\"\u003eCVE-2026-73369\u003c/a\u003e, \u003ca href=\"#cve-2026-75699\"\u003eCVE-2026-75699\u003c/a\u003e, \u003ca href=\"#cve-2026-75703\"\u003eCVE-2026-75703\u003c/a\u003e, \u003ca href=\"#cve-2026-75721\"\u003eCVE-2026-75721\u003c/a\u003e, \u003ca href=\"#cve-2026-75723\"\u003eCVE-2026-75723\u003c/a\u003e, \u003ca href=\"#cve-2026-75728\"\u003eCVE-2026-75728\u003c/a\u003e, \u003ca href=\"#cve-2026-82008\"\u003eCVE-2026-82008\u003c/a\u003e, \u003ca href=\"#cve-2026-82009\"\u003eCVE-2026-82009\u003c/a\u003e, \u003ca href=\"#cve-2026-82010\"\u003eCVE-2026-82010\u003c/a\u003e, \u003ca href=\"#cve-2026-82011\"\u003eCVE-2026-82011\u003c/a\u003e, \u003ca href=\"#cve-2026-82013\"\u003eCVE-2026-82013\u003c/a\u003e, \u003ca href=\"#cve-2026-82443\"\u003eCVE-2026-82443\u003c/a\u003e, \u003ca href=\"#cve-2026-83660\"\u003eCVE-2026-83660\u003c/a\u003e, \u003ca href=\"#cve-2026-84412\"\u003eCVE-2026-84412\u003c/a\u003e, \u003ca href=\"#cve-2026-89276\"\u003eCVE-2026-89276\u003c/a\u003e.\u003c/p\u003e\n\u003ch2 id=\"cve-2026-89276\"\u003eCVE-2026-89276\u003c/h2\u003e\n\u003cp\u003eCVE-2026-89276 is a critical code injection vulnerability in Adobe Campaign Classic that allows a low-privileged attacker to achieve remote code execution without user interaction. The vulnerability results in a change of scope, and successful exploitation grants the attacker the execution privileges of the current user context.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eCampaign Classic\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-89276\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-89276\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eRelated in this roundup: \u003ca href=\"#cve-2026-82004\"\u003eCVE-2026-82004\u003c/a\u003e, \u003ca href=\"#cve-2026-73369\"\u003eCVE-2026-73369\u003c/a\u003e, \u003ca href=\"#cve-2026-75699\"\u003eCVE-2026-75699\u003c/a\u003e, \u003ca href=\"#cve-2026-75703\"\u003eCVE-2026-75703\u003c/a\u003e, \u003ca href=\"#cve-2026-75721\"\u003eCVE-2026-75721\u003c/a\u003e, \u003ca href=\"#cve-2026-75723\"\u003eCVE-2026-75723\u003c/a\u003e, \u003ca href=\"#cve-2026-75728\"\u003eCVE-2026-75728\u003c/a\u003e, \u003ca href=\"#cve-2026-82008\"\u003eCVE-2026-82008\u003c/a\u003e, \u003ca href=\"#cve-2026-82009\"\u003eCVE-2026-82009\u003c/a\u003e, \u003ca href=\"#cve-2026-82010\"\u003eCVE-2026-82010\u003c/a\u003e, \u003ca href=\"#cve-2026-82011\"\u003eCVE-2026-82011\u003c/a\u003e, \u003ca href=\"#cve-2026-82013\"\u003eCVE-2026-82013\u003c/a\u003e, \u003ca href=\"#cve-2026-82443\"\u003eCVE-2026-82443\u003c/a\u003e, \u003ca href=\"#cve-2026-83660\"\u003eCVE-2026-83660\u003c/a\u003e, \u003ca href=\"#cve-2026-84412\"\u003eCVE-2026-84412\u003c/a\u003e, \u003ca href=\"#cve-2026-89275\"\u003eCVE-2026-89275\u003c/a\u003e.\u003c/p\u003e\n","date_modified":"2026-09-22T18:39:18Z","date_published":"2026-09-03T19:22:39Z","id":"https://feed.craftedsignal.io/briefs/2026-09-adobe-security-updates/","summary":"Roundup of Adobe security advisories published in September 2026.","title":"Adobe Security Updates - September 2026","url":"https://feed.craftedsignal.io/briefs/2026-09-adobe-security-updates/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:adobe:coldfusion:2023:update23:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}