DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:07:52ZSOURCES: 14CRITICAL: 34
⚠ ACTIVE ALERTS
@AlvieriD CRITICAL — CORRELATED | Actor '888' listing on PwnForums: claims 35GB of Accenture source code,… /// @DarkWebInformer CRITICAL — CORRELATED | Prinz Eugen ransomware operation — actor ROOTBOY (aka avtokz / GERMANIA)… /// @MalwareHunterTeam CRITICAL — CORRELATED | PolinRider (DPRK / Famous Chollima / Contagious Interview) supply chain… /// @GossiTheDog CRITICAL — CORRELATED | CVE-2026-8037 Progress Kemp LoadMaster pre-auth RCE — exploitation attempts… /// @FalconFeedsio CRITICAL — CORRELATED | Tracking '888' forum listing for Accenture data (July 6, 2026). Dataset:…
34Critical Threats
19Active CVEs
10IOCs Tracked
7New Advisories
TLP:WHITEVULNERABILITY BRIEF // CVE-2026-48286PUBLISHED: 2026-07-01
CRITICALCVE-2026-48286

Adobe Campaign Classic Incorrect Authorization Unauthenticated RCE

VENDOR: Adobe//PRODUCT: Adobe Campaign Classic (on-premises)
10
CRITICAL
CVSS 3.1
PATCH STATUS
PATCH AVAILABLE
EXPLOIT STATUS
NO KNOWN EXPLOIT

An incorrect authorization flaw (CWE-863) in on-premises Adobe Campaign Classic allows unauthenticated remote attackers to bypass authorization checks and execute arbitrary code in the context of the current user, with a CVSS vector reflecting no authentication or user interaction required and a scope change. Adobe-hosted instances were patched server-side and require no customer action. Adobe has stated no exploits in the wild have been identified, but assigned its highest Priority 1 rating given the attack surface and history of ColdFusion-class products being weaponized within hours of disclosure. Patch is ACC v7: 7.4.3 build 9397, released June 30, 2026.

Attack Vector
NETWORK
Attack Complexity
LOW
Privs Required
NONE
User Interaction
NONE
Scope / Impact
CHANGED
C:H · I:H · A:H
AFFECTED VERSIONSAdobe Campaign Classic v7: 7.4.3 build 9396 and earlier (Windows and Linux); on-premises and hybrid deployments only
  • https://helpx.adobe.com/security/products/campaign/apsb26-68.html
  • https://thehackernews.com/2026/07/adobe-patches-7-cvss-100-flaws-in.html
  • https://www.bleepingcomputer.com/news/security/adobe-patches-seven-max-severity-coldfusion-campaign-flaws/
  • https://www.securityweek.com/adobe-patches-critical-coldfusion-campaign-classic-vulnerabilities/
SHARE BRIEF:✕ Post on Xin Share on LinkedIn