CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

NCSC-2026-0291 [1.00] [M/H] Vulnerabilities patched in Adobe Campaign Classic

unknownCVE-2026-27302CVE-2026-48381CVE-2026-71398
Adobe has patched vulnerabilities in Adobe Campaign Classic. The vulnerabilities make it possible for an attacker to execute arbitrary code without user interaction. One of the vulnerabilities concerns improper authorization, allowing an attacker to perform actions outside the intended permissions. Another vulnerability concerns SQL injection, where the attack is partly dependent on factors outside the attacker's control. Through these vulnerabilities, an attacker can obtain elevated privileges and execute unauthorized code within the product.

CSIRTS triage

What
Multiple vulnerabilities including remote code execution, improper authorization, and SQL injection allow attackers to execute arbitrary code and obtain elevated privileges.
Who is affected
All deployments of Adobe Campaign Classic.
Urgency
High; remote code execution without user interaction is immediately exploitable.
Action
Apply the latest Adobe Campaign Classic security patches covering CVE-2026-27302, CVE-2026-48381, and CVE-2026-71398.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Campaign Classic

Get an email when a new Campaign Classic advisory drops — max one per day, one-click unsubscribe.

Details

Source
NCSC-NL Advisories (NL · national-cert · site)
Severity
unknown
Published
2026-08-12
Exploitation
Not in CISA KEV at last sync
Language
Machine-translated to English — verify against the original

Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0291

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-27302coverage & exploitation statusNVD · CVE.org
CVE-2026-48381coverage & exploitation statusNVD · CVE.org
CVE-2026-71398coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for Adobe Campaign Classic

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from NCSC-NL Advisories