Adobe patches critical vulnerability in Campaign Classic (CVSS 10.0) and eight in Bridge

Adobe patched a critical CVSS 10.0 RCE flaw in Campaign Classic and eight critical vulnerabilities in Adobe Bridge. Update immediately.

Adobe patches critical vulnerability in Campaign Classic (CVSS 10.0) and eight in Bridge
Vulnerabilities

Illustrative image generated with AI

On August 1, 2026, Adobe released security updates for two key products: Campaign Classic, an enterprise marketing automation platform, and Bridge, a digital asset management software. The most urgent fix addresses Campaign Classic, where an authorization vulnerability (CVE-2026-48449) received a CVSS score of 10.0 and allows arbitrary code execution with no user interaction. Adobe also patched eight critical vulnerabilities in Bridge. These range from code execution to privilege escalation.

The Campaign Classic flaw: CVE-2026-48449 and CVE-2026-48448

CVE-2026-48449 is an authorization flaw with the highest severity rating. It allows a remote attacker to execute arbitrary code in the context of the user running Campaign Classic. No victim interaction is needed: no clicks, no attachments to open. A malicious network packet can be enough to compromise the system.

At the same time, Adobe addressed CVE-2026-48448, an SQL injection (CVSS 8.6) that enables an attacker with limited privileges to read arbitrary files on the server’s file system. While having a lower impact, the flaw can expose credentials and configuration data, facilitating a broader attack. At the time of the advisory release, the company had not detected active exploits for either vulnerability.

Adobe Bridge: eight critical vulnerabilities

The update for Bridge resolves eight CVEs, all rated critical with CVSS scores between 7.8 and 8.6. The types vary and mostly lead to code execution:

  • Untrusted search path (CVE-2026-48395, CVE-2026-48396)
  • Path traversal (CVE-2026-48374)
  • Improper authorization (CVE-2026-48390, CVE-2026-48391)
  • Out-of-bounds write (CVE-2026-48392, CVE-2026-48393, CVE-2026-48394)

The out-of-bounds write and search path vulnerabilities can be exploited by convincing a user to open a malicious file or visit a webpage containing malicious code. Once code execution is achieved, an attacker can escalate their privileges by exploiting inadequate permission handling.

Mitigations and recommended actions

Adobe recommends applying the updates immediately:

  • Campaign Classic: install version 7.4.3 build 9398 (available for Windows and Linux).
  • Adobe Bridge: apply the latest version via automatic update or the vendor’s support page.

As an additional countermeasure, least privilege policies should be reviewed. Limiting the execution rights of accounts that interact with the two software reduces the attack surface and can prevent an exploit from gaining administrator privileges. Prompt updating remains the primary defense.

Read next

Sources

This article is an original reworking based on the sources below.

CVEs covered in this article

Back to home

Latest Cybersecurity News

All cybersecurity news →