Adobe Patches Critical RCE Flaw in Campaign Classic, Multiple Vulnerabilities in Bridge
Adobe has released urgent security updates to address a maximum-severity vulnerability in its enterprise marketing automation platform, **Campaign Classic (ACC)**, which could lead to arbitrary code execution. Separately, the company also patched eight critical flaws in **Adobe Bridge**, impacting privilege escalation and code execution. IT security professionals and users are strongly advised to apply these updates immediately.
Adobe is urging users to update their software following the discovery and patching of several critical vulnerabilities across its product suite, most notably in **Campaign Classic (ACC)** and **Adobe Bridge**.
### Maximum-Severity Flaw in Campaign Classic
A flaw, tracked as **CVE-2026-48449**, in **Adobe Campaign Classic** has been assigned a **CVSS score of 10.0**, indicating maximum severity. This critical vulnerability stems from incorrect authorization and could allow for arbitrary code execution in the context of the current user, requiring no user interaction.
Alongside **CVE-2026-48449**, Adobe also addressed **CVE-2026-48448**, a high-severity SQL injection vulnerability (CVSS score: 8.6) that could facilitate arbitrary file reads. Both issues have been resolved in **ACC v7: 7.4.3 build 9398** for both Windows and Linux.
Adobe stated in its advisory that it is currently unaware of any active exploitation of these vulnerabilities in the wild, but prompt patching is crucial to prevent potential attacks.
### Multiple Critical Flaws in Adobe Bridge
Separately, Adobe has also shipped updates for **Adobe Bridge**, remediating eight critical-rated flaws that could lead to privilege escalation and arbitrary code execution. These vulnerabilities include:
* **CVE-2026-48395** (CVSS score: 8.6): An untrusted search path vulnerability leading to arbitrary code execution.
* **CVE-2026-48396** (CVSS score: 8.6): An incorrect authorization vulnerability leading to arbitrary code execution.
* **CVE-2026-48390** (CVSS score: 8.6): An incorrect authorization vulnerability leading to privilege escalation.
* **CVE-2026-48391** (CVSS score: 8.2): An untrusted search path vulnerability leading to arbitrary code execution.
* **CVE-2026-48374** (CVSS score: 7.8): A path traversal vulnerability leading to arbitrary code execution.
* **CVE-2026-48392** (CVSS score: 7.8): An out-of-bounds write vulnerability leading to arbitrary code execution.
* **CVE-2026-48393** (CVSS score: 7.8): An out-of-bounds write vulnerability leading to arbitrary code execution.
* **CVE-2026-48394** (CVSS score: 7.8): An out-of-bounds write vulnerability leading to arbitrary code execution.
Adobe acknowledged security researcher Kieran ("kaiksi") for discovering and reporting **CVE-2026-48390**, **CVE-2026-48391**, **CVE-2026-48395**, **CVE-2026-48396**, and **CVE-2026-48374**. Additionally, "yjdfy" was credited for reporting **CVE-2026-48392**, **CVE-2026-48393**, and **CVE-2026-48394**.
Users are strongly advised to apply the latest updates for **Adobe Campaign Classic** and **Adobe Bridge** to ensure optimal protection against these critical vulnerabilities.