NCSC-2026-0273 [1.00] [M/H] Vulnerabilities patched in Adobe Campaign Classic
Adobe has patched vulnerabilities in Adobe Campaign Classic (ACC). The first vulnerability concerns an Incorrect Authorization in the core authorization mechanisms of ACC, which allows an attacker to execute arbitrary code without any user interaction. This means the attacker can perform actions outside the intended permissions. The second vulnerability is a SQL injection that enables attackers to execute unauthorized queries, read files from the system, and access sensitive memory information. This vulnerability can also be exploited without user interaction. Adobe indicates that the vulnerabilities in the cloud version of Campaign Classic have already been patched. Therefore, the vulnerability information is particularly relevant for organizations running Campaign Classic in fully on-premise configurations or using a hybrid solution.
CSIRTS triage
- What
- Two vulnerabilities in Adobe Campaign Classic enable unauthenticated code execution via authorization bypass and SQL injection for data exfiltration.
- Who is affected
- On-premise and hybrid Adobe Campaign Classic deployments; cloud instances are already patched.
- Urgency
- High severity; unauthenticated RCE in authorization mechanisms poses critical risk.
- Action
- Apply Adobe patches for CVE-2026-48449 and CVE-2026-48448 immediately for on-premise instances.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Adobe Campaign Classic
Get an email when a new Adobe Campaign Classic advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0273
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-484490.54% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 43% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-484480.37% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-48449 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48448 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for Adobe Campaign Classic
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownNCSC-2026-0278 [1.00] [M/H] Vulnerabilities patched in Adobe Campaign Classicncsc-nl · 2026-08-06
- highCVE-2026-48399: Adobe Campaign Classic (ACC) is affected by a Violation of Secure Design Principles vulnerabil…nvd · 2026-08-03
- criticalCVE-2026-48333: Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that coul…nvd · 2026-08-03
- criticalCVE-2026-48331: Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability…nvd · 2026-08-03
- criticalCVE-2026-48330: Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements use…nvd · 2026-08-03
- criticalCVE-2026-48326: Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements use…nvd · 2026-08-03
More from NCSC-NL Advisories
- unknownNCSC-2026-0279 [1.00] [M/H] Vulnerabilities patched in Cisco IOS XE Software2026-08-07
- unknownNCSC-2026-0275 [1.01] [M/H] Vulnerabilities patched in N-able N-central2026-08-07
- unknownNCSC-2026-0278 [1.00] [M/H] Vulnerabilities patched in Adobe Campaign Classic2026-08-06
- unknownNCSC-2026-0277 [1.00] [M/H] Vulnerabilities patched in Cisco Catalyst SD-WAN2026-08-06
- unknownNCSC-2026-0276 [1.00] [M/H] Vulnerabilities patched in Veeam Service Provider Console2026-08-05