{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aadobedimension/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:adobe:dimension:*:*:*:*:*:*:*:*","cpe:2.3:a:adobe:indesign:*:*:*:*:*:*:*:*","cpe:2.3:a:adobe:after_effects:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.8,"id":"CVE-2024-41865"},{"cvss":5.5,"id":"CVE-2024-41866"},{"cvss":5.5,"id":"CVE-2024-41867"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Campaign Classic"],"_cs_severities":["high"],"_cs_tags":["vulnerability","remote-code-execution","adobe","ssrf"],"_cs_type":"advisory","_cs_vendors":["Adobe"],"content_html":"\u003cp\u003eThe NCSC-NL has identified three critical vulnerabilities in Adobe Campaign Classic, carrying a maximum CVSS score of 10.0. These flaws include Server-Side Request Forgery (SSRF) and OS Command Injection, both of which can be triggered without user interaction by an unauthenticated attacker. The exploitation of these vulnerabilities allows for remote code execution and unauthorized access to the underlying server infrastructure. Given the high potential for system compromise, organizations running Adobe Campaign Classic are advised to apply the latest security patches provided by Adobe as a matter of urgency. The vulnerabilities are identified as CVE-2024-41865, CVE-2024-41866, and CVE-2024-41867.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities results in unauthorized remote access to the host server running Adobe Campaign Classic. This allows attackers to execute arbitrary commands, exfiltrate sensitive data, or pivot into the internal network. The NCSC-NL assesses the potential damage to organizations as 'high'.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately apply the security updates provided by Adobe to remediate CVE-2024-41865, CVE-2024-41866, and CVE-2024-41867.\u003c/li\u003e\n\u003cli\u003eReview web server logs for suspicious requests involving anomalous URI parameters or outbound connections originating from the Adobe Campaign Classic application server that may indicate exploitation attempts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-27T12:40:00Z","date_published":"2026-08-27T12:40:00Z","id":"https://feed.craftedsignal.io/briefs/2026-08-adobe-campaign-classic/","summary":"Adobe Campaign Classic is affected by three critical vulnerabilities, including SSRF and OS Command Injection, which allow unauthenticated remote attackers to achieve full system compromise.","title":"Critical Vulnerabilities in Adobe Campaign Classic","url":"https://feed.craftedsignal.io/briefs/2026-08-adobe-campaign-classic/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:adobe:dimension:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}