Adobe Campaign Classic Gets a Trust-Breaking Flaw Cluster
Adobe Campaign Classic is not dealing with one isolated bug. It has a cluster of no-interaction flaws that can push an exposed instance from simple request handling into code execution, privilege escalation, and database abuse.
NCSC says the advisory covers seven CVEs, including SSRF that enables privilege escalation without user interaction, template-engine and eval injection that allow arbitrary code execution, multiple SQL injection flaws, incorrect authorization, and a security-bypass issue. Adobe has released updates, and NCSC says this is a new advisory, not an update to the earlier one.
For teams running Campaign Classic, the risk is a remote takeover path on a platform that already sits close to customer data and outbound communications. That makes patch status the immediate question, not just whether a single account or page is affected.