Vulnerabilities & Exploits · Web App Attack

Adobe Campaign Classic Fixed Pre-Auth Critical Flaws

Adobe patched 18 critical vulnerabilities in Campaign Classic, and the Netherlands NCSC said 10 of them can be reached remotely without authentication. Adobe-hosted environments are already patched, but self-hosted instances still need the update.

The flaws include code injection, OS command injection, SQL injection, improper authorization, and server-side request forgery (SSRF). In plain terms, a crafted request can hit the app before login, push it to run attacker-controlled commands or code, read files, or make outbound requests on the attacker’s behalf.

If Campaign Classic sits in front of customer-facing workflows or internal systems, the exposure is not just one app bug; it is a pre-auth entry point into whatever the platform can reach. The remaining risk lives wherever the instance is internet-facing and still on the old build.

1 source · 11h ago

CVEs in this update

10 CVEs

Across Adobe Campaign Classic.

9 critical · 1 high · 0 medium · 0 low

0 in CISA KEV · 9 with EPSS above 1%

Highest severity: CVE-2026-82004 · 10.0 CRITICAL

Highest EPSS: CVE-2026-82004 · 3.3%

Timeline

Sources

Part of the PlainSec briefing for 2026-09-24

Every edition of this story: Adobe Campaign Classic Fixed Pre-Auth Critical Flaws

More from today