CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

NCSC-2026-0278 [1.00] [M/H] Vulnerabilities patched in Adobe Campaign Classic

unknownCVE-2026-48331CVE-2026-48323CVE-2026-48330CVE-2026-48326CVE-2026-48333CVE-2026-48317
Adobe has patched multiple vulnerabilities in Adobe Campaign Classic. The vulnerabilities in Adobe Campaign Classic include a Server-Side Request Forgery (SSRF) that enables privilege escalation without user interaction, improper neutralization of special elements in the template engine that leads to arbitrary code execution, and multiple SQL injection issues that enable execution of arbitrary SQL commands. Additionally, there is an incorrect authorization control that allows privilege escalation, an Eval Injection vulnerability that enables arbitrary code execution by low-privileged attackers, and a design principle violation that allows bypassing security measures and unauthorized read access to sensitive information. All these vulnerabilities can be exploited without any user interaction, which increases the likelihood of automated or remote attacks. Note: This is not an update to the previous advisory NCSC-2026-0273 (https://advisories.ncsc.nl/2026/ncsc-2026-0273.html). This advisory concerns newly discovered vulnerabilities.

CSIRTS triage

What
Multiple vulnerabilities including SSRF with privilege escalation, arbitrary code execution via template injection and eval injection, SQL injection, authorization bypass, and information disclosure.
Who is affected
All Adobe Campaign Classic deployments are affected; exploitation requires no user interaction.
Urgency
High severity; multiple unauthenticated code execution paths with no user interaction required increases automated attack likelihood.
Action
Apply Adobe Campaign Classic security patches immediately and review Campaign deployment access logs for exploitation attempts.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Campaign Classic

Get an email when a new Campaign Classic advisory drops — max one per day, one-click unsubscribe.

Details

Source
NCSC-NL Advisories (NL · national-cert · site)
Severity
unknown
Published
2026-08-06
Exploitation
Not in CISA KEV at last sync
Language
Machine-translated to English — verify against the original

Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0278

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-48331coverage & exploitation statusNVD · CVE.org
CVE-2026-48323coverage & exploitation statusNVD · CVE.org
CVE-2026-48330coverage & exploitation statusNVD · CVE.org
CVE-2026-48326coverage & exploitation statusNVD · CVE.org
CVE-2026-48333coverage & exploitation statusNVD · CVE.org
CVE-2026-48317coverage & exploitation statusNVD · CVE.org
CVE-2026-48399coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for Adobe Campaign Classic

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from NCSC-NL Advisories