Act nowDisclosed

Advisory · CVE-2026-75699

Adobe Campaign Classic code injection flaw enables unauthenticated RCE (CVE-2026-75699)

Adobe Campaign Classic is affected by an unauthenticated improper code-generation flaw that can lead to arbitrary code execution with scope changed. CVSS 10.0.

Vendor
Adobe
Product
Adobe Campaign Classic
Identifier / CWE
CVE-2026-75699
CWE-94
Action timing
Immediate
ELI5

Explain it like I’m five

A form letter machine trusts whatever text you feed it. An attacker feeds it instructions instead of a letter, and the machine carries them out with its own authority.

SIMPLIFIED_ATTACK_PATH04 STEPS
  1. 01Target identified

    An attacker reaches an internet-facing Adobe Campaign Classic instance with no credentials.

  2. 02Malicious input

    They submit input that the application fails to control during code generation.

  3. 03Code executes

    The injected code runs in the context of the current user with changed scope.

  4. 04Impact

    Arbitrary code execution on the Campaign server, no user interaction required.

What happened

Adobe security bulletin APSB26-142 addresses multiple critical flaws in Adobe Campaign Classic. CVE-2026-75699 is an improper control of code generation (CWE-94) that an unauthenticated, remote attacker can exploit without user interaction, resulting in arbitrary code execution. Adobe Campaign Classic builds up to and including 7.4.4 build 9401; fixed in 7.4.4 build 9402. NVD rates it CVSS 10.0 (v3.1).

What to do

  1. Upgrade Adobe Campaign Classic to 7.4.4 build 9402 or later.
  2. Restrict network access to Campaign servers to trusted administrators while patching.
  3. Review application and system logs for unexpected process execution or web requests.

Management note

This is one of several unauthenticated RCE flaws fixed in the same Adobe bulletin. One patch cycle covers them all, so the risk is entirely in how long the upgrade waits.