What is CVE-2026-48449?
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
Timeline
- 2026-07-30Published to the U.S. National Vulnerability Database (NVD)
- 2026-08-02First covered in a defend.network daily briefing
- 2026-08-05NVD record last updated
Affected product
Adobe Campaign (also: Linux, Microsoft)
NVD also lists CPE entries for: Adobe Campaign, Linux Kernel, Microsoft Windows
Remediation Steps
- Apply the vendor security update for Adobe Campaign Classic as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References
Referenced in our briefings & reports
- Vulnerability Priority Report – Week 1 of August 2026 (August 3 – 9)
- Vulnerability Priority Report – Week 4 of July 2026 (July 27 – August 2)
- Coldcard firmware flaw linked to $70M Bitcoin theft; Adform supply-chain attack (2026-08-03)
- Adobe Campaign CVSS 10.0 exploit, Coldcard $70M theft, Adform supply-chain attack (2026-08-02)
Browse all tracked CVEs in the defend.network CVE database →
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.