CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-71398

criticalCVSS 10covered by 2 sourcesfirst seen 2026-08-11
Adobe has patched vulnerabilities in Adobe Campaign Classic. The vulnerabilities make it possible for an attacker to execute arbitrary code without user interaction. One of the vulnerabilities concerns improper authorization, allowing an attacker to perform actions outside the intended permissions. Another vulnerability concerns SQL injection, where the attack is partly dependent on factors outside the attacker's control. Through these vulnerabilities, an attacker can obtain elevated privileges and execute unauthorized code within the product.

CSIRTS triage

What
Multiple vulnerabilities including remote code execution, improper authorization, and SQL injection allow attackers to execute arbitrary code and obtain elevated privileges.
Who is affected
All deployments of Adobe Campaign Classic.
Urgency
High; remote code execution without user interaction is immediately exploitable.
Action
Apply the latest Adobe Campaign Classic security patches covering CVE-2026-27302, CVE-2026-48381, and CVE-2026-71398.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-71398

Get an email if CVE-2026-71398 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-71398

CVE.org record

Embed the live status

CVE-2026-71398 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-71398 status](https://www.csirts.com/badge/CVE-2026-71398)](https://www.csirts.com/cve/CVE-2026-71398)