NCSC-2026-0278 [1.00] [M/H] Vulnerabilities patched in Adobe Campaign Classic
Adobe has patched multiple vulnerabilities in Adobe Campaign Classic. The vulnerabilities in Adobe Campaign Classic include a Server-Side Request Forgery (SSRF) that enables privilege escalation without user interaction, improper neutralization of special elements in the template engine that leads to arbitrary code execution, and multiple SQL injection issues that enable execution of arbitrary SQL commands. Additionally, there is an incorrect authorization control that allows privilege escalation, an Eval Injection vulnerability that enables arbitrary code execution by low-privileged attackers, and a design principle violation that allows bypassing security measures and unauthorized read access to sensitive information. All these vulnerabilities can be exploited without any user interaction, which increases the likelihood of automated or remote attacks. Note: This is not an update to the previous advisory NCSC-2026-0273 (https://advisories.ncsc.nl/2026/ncsc-2026-0273.html). This advisory concerns newly discovered vulnerabilities.
CSIRTS triage
- What
- Multiple vulnerabilities including SSRF with privilege escalation, arbitrary code execution via template injection and eval injection, SQL injection, authorization bypass, and information disclosure.
- Who is affected
- All Adobe Campaign Classic deployments are affected; exploitation requires no user interaction.
- Urgency
- High severity; multiple unauthenticated code execution paths with no user interaction required increases automated attack likelihood.
- Action
- Apply Adobe Campaign Classic security patches immediately and review Campaign deployment access logs for exploitation attempts.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Campaign Classic
Get an email when a new Campaign Classic advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0278
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-483310.47% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-483230.62% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 47% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-483300.68% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 49% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-483260.48% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-483330.47% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-483170.48% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-483990.48% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-48331 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48323 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48330 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48326 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48333 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48317 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48399 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highCVE-2026-48399: Adobe Campaign Classic (ACC) is affected by a Violation of Secure Design Principles vulnerabil…nvd
- criticalCVE-2026-48333: Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that coul…nvd
- criticalCVE-2026-48331: Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability…nvd
- criticalCVE-2026-48330: Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements use…nvd
- criticalCVE-2026-48326: Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements use…nvd
- criticalCVE-2026-48323: Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Use…nvd
- criticalCVE-2026-48317: Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Directives in Dynami…nvd
Recent advisories for Adobe Campaign Classic
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-48399: Adobe Campaign Classic (ACC) is affected by a Violation of Secure Design Principles vulnerabil…nvd · 2026-08-03
- criticalCVE-2026-48333: Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that coul…nvd · 2026-08-03
- criticalCVE-2026-48331: Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability…nvd · 2026-08-03
- criticalCVE-2026-48330: Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements use…nvd · 2026-08-03
- criticalCVE-2026-48326: Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements use…nvd · 2026-08-03
- criticalCVE-2026-48323: Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Use…nvd · 2026-08-03
More from NCSC-NL Advisories
- unknownNCSC-2026-0279 [1.00] [M/H] Vulnerabilities patched in Cisco IOS XE Software2026-08-07
- unknownNCSC-2026-0275 [1.01] [M/H] Vulnerabilities patched in N-able N-central2026-08-07
- unknownNCSC-2026-0277 [1.00] [M/H] Vulnerabilities patched in Cisco Catalyst SD-WAN2026-08-06
- unknownNCSC-2026-0276 [1.00] [M/H] Vulnerabilities patched in Veeam Service Provider Console2026-08-05
- unknownNCSC-2026-0268 [1.01] [M/H] Vulnerability patched in SQLite by SQLite Consortium (withdrawn)2026-08-03