Executive summary
What is confirmed
Adobe bulletin APSB26-114 identifies CVE-2026-48449 as a critical Incorrect Authorization vulnerability in Adobe Campaign Classic v7. Adobe assigns a CVSS 3.1 base score of 10.0 and states that successful exploitation could result in arbitrary code execution.
Scope matters
The bulletin applies to fully on-premises Adobe Campaign Classic deployments and the on-premises components of hybrid deployments. Adobe-hosted instances have already been remediated and require no customer action.
| Affected | Adobe Campaign Classic v7, version 7.4.3 build 9397 and earlier, on Windows and Linux. |
|---|---|
| Updated version | Adobe Campaign Classic v7, version 7.4.3 build 9398. |
| Attack conditions | Network-accessible, low complexity, no privileges and no user interaction according to Adobe's published CVSS vector. |
| Observed exploitation | Adobe stated it was not aware of exploitation in the wild when the bulletin was updated on 30 July 2026. |
| NVD status | Awaiting NVD enrichment at the time of publication; the vendor assessment is currently the substantive source. |
Recommended response
Actions for administrators
Confirm deployment responsibility
Determine whether the environment is Adobe-hosted, fully on-premises or hybrid. Confirm which team or supplier owns the on-premises components.
Inventory versions
Identify every affected instance and supporting node. Do not assume the primary application record represents the complete deployment.
Apply Adobe's update
Prioritise build 9398 using an emergency change path proportionate to the service's exposure and criticality. Follow Adobe's release notes and preserve rollback readiness.
Reduce exposure while change is pending
Restrict network access to required administrative and application paths. Review internet exposure, reverse-proxy controls and unnecessary connectivity.
Review available evidence
Examine application, operating-system, proxy and security telemetry for unusual access or execution. Absence of an alert does not prove absence of compromise.
Verify and document
Confirm the updated build on every in-scope component, record any exception and monitor Adobe and NVD for revised guidance.
RACF-CC context
Why this is more than a patching task
This advisory connects to Domain 3 through exposure restriction, Domain 4 through inventory and verified remediation, Domain 6 through evidence review and Domain 8 through emergency change and exception governance.
Primary sources
Follow the live advisories
Threat information changes. Recheck the vendor bulletin before making production decisions.
Voluntary support
Found this useful? Support Trends4You
Trends4You's practical guides, RACF-CC resources and downloadable tools are provided free of charge. If they've helped you or your organisation, you can support the time and hosting that keeps them freely available.
Support is optional, handled securely by Stripe and does not provide additional access.
