What is CVE-2026-48449?
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
Timeline
- 2026-07-30Published to the U.S. National Vulnerability Database (NVD)
- 2026-08-02First covered in a defend.network daily briefing
Affected product
See advisory
Remediation Steps
- Apply the latest security update from Adobe for Campaign Classic
- Review access controls and authorization policies in ACC instances
- Monitor ACC application logs for unauthorized access attempts
- Restrict network access to ACC services to trusted networks only
References
Referenced in our briefings & reports
- Vulnerability Priority Report – Week 4 of July 2026 (July 27 – August 2)
- Adobe Campaign CVSS 10.0 exploit, Coldcard $70M theft, Adform supply-chain attack (2026-08-02)
Browse all tracked CVEs in the defend.network CVE database →
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.