Adobe patched 18 critical vulnerabilities in Campaign Classic, and the Netherlands NCSC said 10 of them can be reached remotely without authentication. Adobe-hosted environments are already patched, but self-hosted instances still need the update.
The flaws include code injection, OS command injection, SQL injection, improper authorization, and server-side request forgery (SSRF). In plain terms, a crafted request can hit the app before login, push it to run attacker-controlled commands or code, read files, or make outbound requests on the attacker’s behalf.
If Campaign Classic sits in front of customer-facing workflows or internal systems, the exposure is not just one app bug; it is a pre-auth entry point into whatever the platform can reach. The remaining risk lives wherever the instance is internet-facing and still on the old build.