Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Summary

Adobe has released security updates for its Campaign Classic platform to address a critical vulnerability, CVE-2026-48449. This flaw has a CVSS score of 10.0 and allows for arbitrary code execution without user interaction.

IFF Assessment

FOE

A maximum severity vulnerability allowing arbitrary code execution is bad news for defenders as it presents a high risk of compromise.

Severity

10.0 Critical

The article explicitly states the CVSS score is 10.0 and describes it as a maximum-severity flaw that could result in arbitrary code execution without user interaction, indicating a critical level of exploitability and impact.

Defender Context

Defenders need to prioritize patching Adobe Campaign Classic instances immediately due to the critical CVSS 10.0 score, which indicates a severe risk of arbitrary code execution. This vulnerability could allow attackers to take full control of affected systems, leading to data breaches or further network compromise.

Read Full Story →