ON
← Back to feed
Adobe Campaign Classic is threatened by a critical malware vulnerability
Germany🏛️ Politics21 days ago

Adobe Campaign Classic is threatened by a critical malware vulnerability

Ein Sicherheitsupdate für Adobe Campaign Classic (ACC) und Adobe Bridge deckt mehrere kritische Sicherheitslücken auf. Die Lücke CVE-2026-48449 in ACC wird als 'kritisch' bewertet und ermöglicht Angreifern, Schadcode auszuführen, ohne dass ein Opfer aktiv handeln muss. Eine weitere Schwachstelle (CVE-2026-48448) ermöglicht SQL-Injections. Für Adobe Bridge wurden acht Sicherheitslücken identifiziert, wovon sieben zu voller Kontrollübernahme führen können. Die Probleme wurden in den Versionen ACC v7.4.3 build 9398 und Bridge 15.1.7 (LTS)/16.0.6 behoben. Adobe hat seinen Patchzyklus angepasst und veröffentlicht nun monatlich zwei Updates.

Adobe has issued urgent security patches after identifying two critical vulnerabilities in its Campaign Classic (ACC) software, which could allow attackers to execute malicious code remotely without user interaction. The flaws affect both ACC and Adobe Bridge, with one vulnerability rated as critical with a CVSS score of 10 out of 10 (CVE-2026-48449). This means the flaw poses a severe risk to systems running Linux or Windows operating systems. According to reports, attackers can exploit this vulnerability through authentication errors to run arbitrary code in the context of a legitimate user, without needing to trick users into taking action. At present, there are no known attacks exploiting these issues. The first vulnerability, CVE-2026-48449, was addressed in ACC version 7.4.3 build 9398. It allows remote execution of malicious code due to improper handling of authentication processes. The second vulnerability, CVE-2026-48448, is classified as high severity and involves a SQL injection flaw that enables unauthorized access to system files. These updates were released alongside fixes for other issues, including eight separate vulnerabilities affecting Adobe Bridge. Among these, seven allow attackers to deploy and execute malicious code, potentially granting them full control over affected systems. One additional flaw, CVE-2026-48390, enables attackers to escalate their privileges within the system, increasing the potential damage of an attack. Adobe has also patched several other vulnerabilities in Bridge, with versions 15.1.7 (LTS) and 16.0.6 providing protection against these threats. These updates address multiple high-severity issues, including CVE-2026-48395, which allows remote code execution. The company has adjusted its patching schedule since July of this year, releasing security updates twice monthly instead of once. This change aims to improve response times and ensure more frequent protection against emerging threats. The vulnerabilities highlight ongoing challenges in maintaining secure software environments, particularly in enterprise applications used for data management and marketing automation. Adobe Campaign Classic is widely used by organizations for managing customer interactions, making it a valuable target for cybercriminals. While Adobe has not reported any confirmed exploitation attempts, the potential impact of these flaws underscores the importance of timely patching and proactive security measures. Organizations using Adobe products are advised to apply the latest updates immediately to mitigate risks. Security researchers have noted that the nature of these vulnerabilities, allowing code execution without user input, makes them particularly dangerous. Such flaws can be exploited in targeted attacks or as part of broader campaigns aimed at compromising corporate networks. The lack of public information on how these exploits might be carried out suggests that attackers may still be experimenting with methods to leverage these weaknesses effectively. As Adobe continues to monitor the situation, industry experts recommend that businesses conduct regular security audits and maintain up-to-date software configurations. The recent changes to Adobe’s update cycle reflect a growing awareness of the need for rapid responses to evolving cybersecurity threats. With the release of these patches, users are encouraged to verify that they are running the latest versions of Adobe Bridge and Campaign Classic to protect their systems from potential exploitation.

Go to the primary sources (2)

The official sources this coverage is built on. Read them directly to bypass framing.

1 reports

heise online logoheise onlineIndependentCenterFactual 85Objective 8021 days ago
Adobe Campaign Classic is threatened by a critical malware vulnerability

Ein Sicherheitsupdate für Adobe Campaign Classic (ACC) und Adobe Bridge deckt mehrere kritische Sicherheitslücken auf. Die Lücke CVE-2026-48449 in ACC wird als 'kritisch' bewertet und ermöglicht Angreifern, Schadcode auszuführen, ohne dass ein Opfer aktiv handeln muss. Eine weitere Schwachstelle (CVE-2026-48448) ermöglicht SQL-Injections. Für Adobe Bridge wurden acht Sicherheitslücken identifiziert, wovon sieben zu voller Kontrollübernahme führen können. Die Probleme wurden in den Versionen ACC v7.4.3 build 9398 und Bridge 15.1.7 (LTS)/16.0.6 behoben. Adobe hat seinen Patchzyklus angepasst und veröffentlicht nun monatlich zwei Updates.

Bias read (Center): Der Artikel berichtet objektiv über technische Sicherheitslücken in Softwareprodukten von Adobe. Es wird keine politische Haltung oder Meinung vertreten, sondern nur Fakten zur Sicherheit und den damit verbundenen Risiken. Der Ton bleibt sachlich und informativ, ohne eine klare parteiengesinnete Hör

Why factuality (85): The article reports on multiple security vulnerabilities in Adobe products based on official CVE identifiers (CVE-2026-48449, CVE-2026-48448, etc.) and mentions specific versions where patches were released. It aligns with typical cybersecurity reporting standards and does not contradict any known i

Why objectivity (80): The tone remains professional and informative, focusing on technical details without overt bias. However, there is some subtle emphasis on the severity of the vulnerabilities (e.g., 'kritisch' and 'maximaler CVSS Score'), which may slightly lean toward highlighting the risk, though this is common in

How each side covered it

The same event, grouped by the political lean of the outlets covering it.

How each side covered it

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Covered around the world

The same event as reported in other countries.

Covered around the world

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Claims check

Key factual claims, and how many sources assert vs dispute each.

Claims check

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Keep the news honest.

ObjectiveNews is reader-funded and ad-free — we show you the bias instead of hiding it. Support independent journalism for €4/month.

Become a Supporter

Related stories