Adobe Broadens Fixes Beyond Campaign Classic

Adobe has shifted this from a single critical Campaign Classic flaw to a routine patching job across ACC and Bridge. The key point is that the current user context still matters, but Adobe says it has no known exploitation, so the issue is remediation rather than containment. ACC v7.4.3 build 9398 fixes CVE-2026-48449, the CVSS 10.0 incorrect-authorization flaw, and CVE-2026-48448, a SQL injection issue tied to arbitrary file reads. Adobe also shipped fixes for eight critical Bridge bugs, including incorrect authorization, untrusted search path, path traversal, and out-of-bounds write issues. The forward risk is operational, not acute. Teams running Adobe Campaign Classic on Windows or Linux, and enterprise fleets using Adobe Bridge, need to verify they are on the fixed builds and treat the exposed versions as part of normal patch hygiene.

Part of the PlainSec briefing for 2026-08-01

Sources