A critical vulnerability (CVE-2026-71398) has been disclosed in Adobe Campaign Classic (ACC) and Adobe Campaign software. The flaw stems from incorrect authorization checks that could allow an unauthenticated attacker to execute arbitrary code in the context of the current user. This pre-authentication remote code execution vulnerability (CVSS 10.0) does not require user interaction, making it particularly dangerous for exposed systems. The vulnerability affects multiple versions of Adobe Campaign Classic and Adobe Campaign platform components. Successful exploitation could result in full system compromise, data exfiltration, or lateral movement within networks. Organizations operating affected software should apply vendor-provided patches immediately. Adobe has released security bulletins detailing affected versions and mitigation steps. In the absence of patches, network-level restrictions should be implemented to block external access to ACC services. System administrators are advised to review logs for anomalous activity and monitor for indicators of compromise. This vulnerability underscores the importance of timely patch management for enterprise messaging platforms.
CRITICAL
CVSS 10.0
CVE-2026-71398
2026-08-18
Critical Vulnerability in Adobe Campaign Classic Allows Arbitrary Code Execution (CVE-2026-71398)
Adobe Campaign Classic contains a critical authorization flaw (CVE-2026-71398) enabling remote code execution without user interaction. Immediate patching is required for all affected deployments.