VULNERABILITY OVERVIEW
An incorrect authorization flaw (CWE-863) in on-premises Adobe Campaign Classic allows unauthenticated remote attackers to bypass authorization checks and execute arbitrary code in the context of the current user, with a CVSS vector reflecting no authentication or user interaction required and a scope change. Adobe-hosted instances were patched server-side and require no customer action. Adobe has stated no exploits in the wild have been identified, but assigned its highest Priority 1 rating given the attack surface and history of ColdFusion-class products being weaponized within hours of disclosure. Patch is ACC v7: 7.4.3 build 9397, released June 30, 2026.
CVSS BREAKDOWN
↗
Attack Vector
NETWORK
△
Attack Complexity
LOW
⚷
Privs Required
NONE
◈
User Interaction
NONE
⊕
Scope / Impact
CHANGED
C:H · I:H · A:H
AFFECTED VERSIONS
Adobe Campaign Classic v7: 7.4.3 build 9396 and earlier (Windows and Linux); on-premises and hybrid deployments onlyCITATIONS
- → https://helpx.adobe.com/security/products/campaign/apsb26-68.html
- → https://thehackernews.com/2026/07/adobe-patches-7-cvss-100-flaws-in.html
- → https://www.bleepingcomputer.com/news/security/adobe-patches-seven-max-severity-coldfusion-campaign-flaws/
- → https://www.securityweek.com/adobe-patches-critical-coldfusion-campaign-classic-vulnerabilities/