NCSC-2026-0291 [1.00] [M/H] Vulnerabilities patched in Adobe Campaign Classic
Adobe has patched vulnerabilities in Adobe Campaign Classic. The vulnerabilities make it possible for an attacker to execute arbitrary code without user interaction. One of the vulnerabilities concerns improper authorization, allowing an attacker to perform actions outside the intended permissions. Another vulnerability concerns SQL injection, where the attack is partly dependent on factors outside the attacker's control. Through these vulnerabilities, an attacker can obtain elevated privileges and execute unauthorized code within the product.
CSIRTS triage
- What
- Multiple vulnerabilities including remote code execution, improper authorization, and SQL injection allow attackers to execute arbitrary code and obtain elevated privileges.
- Who is affected
- All deployments of Adobe Campaign Classic.
- Urgency
- High; remote code execution without user interaction is immediately exploitable.
- Action
- Apply the latest Adobe Campaign Classic security patches covering CVE-2026-27302, CVE-2026-48381, and CVE-2026-71398.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Campaign Classic
Get an email when a new Campaign Classic advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0291
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-273020.71% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 51% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-483810.58% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 45% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-713980.79% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 54% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-27302 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48381 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-71398 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[UPDATE] [high] Adobe Connect: Multiple Vulnerabilitiescert-bund
- criticalCVE-2026-71398: Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that coul…nvd
- criticalCVE-2026-48381: Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements use…nvd
- criticalCVE-2026-27302: Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that coul…nvd
Recent advisories for Adobe Campaign Classic
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- criticalCVE-2026-76197: Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements use…nvd · 2026-08-25
- criticalCVE-2026-76195: Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements use…nvd · 2026-08-25
- criticalCVE-2026-76193: Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability…nvd · 2026-08-25
- criticalCVE-2026-71398: Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that coul…nvd · 2026-08-11
- criticalCVE-2026-48381: Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements use…nvd · 2026-08-11
- criticalCVE-2026-27302: Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that coul…nvd · 2026-08-11
More from NCSC-NL Advisories
- unknownNCSC-2026-0303 [1.01] [M/H] Vulnerabilities patched in GitLab by GitLab Inc.2026-08-25
- unknownNCSC-2026-0326 [1.00] [M/H] Vulnerabilities patched in Keycloak2026-08-25
- unknownNCSC-2026-0325 [1.00] [M/H] Vulnerabilities patched in Atlassian products2026-08-24
- unknownNCSC-2026-0324 [1.00] [M/H] Vulnerability fixed in Zimbra Collaboration Suite2026-08-23
- unknownNCSC-2026-0323 [1.00] [M/H] Vulnerabilities fixed in Cisco Secure Workload2026-08-21