Cyber & AI intelligence
Wasteland.
Briefs indexed2842
Issues29
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-75728 2026-09-22

CVE-2026-75728: Critical Authorization Flaw in Adobe Campaign Classic Could Allow Remote Code Execution

"Adobe has disclosed a critical (CVSS 9.1) incorrect authorization vulnerability in Adobe Campaign Classic that, per Adobe's advisory, could allow an unauthenticated, remote attacker to execute arbitrary code without any…"

Adobe has disclosed a critical (CVSS 9.1) incorrect authorization vulnerability in Adobe Campaign Classic that, per Adobe's advisory, could allow an unauthenticated, remote attacker to execute arbitrary code without any user interaction.

What Is It

CVE-2026-75728 is an Incorrect Authorization flaw (CWE-863) in Adobe Campaign Classic (ACC). According to Adobe's PSIRT advisory, the weakness "could result in arbitrary code execution in the context of the current user." Adobe's advisory indicates that exploitation would not require user interaction, and the scored vector assumes no prior authentication. Adobe has not published exploitation details or a proof of concept, so the practical reliability of an attack against a given deployment is not publicly established.

The CVSS 3.1 vector, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N, describes the worst practical combination for an internet-reachable application: network attack vector, low attack complexity, no privileges required, and no user interaction, yielding a maximum exploitability subscore of 3.9. Impact is high to both confidentiality and integrity, with no availability impact. The resulting base score is 9.1, rated CRITICAL.

The record was published 2026-09-22 and is still marked "Awaiting Analysis" in NVD, so enrichment such as CPE mappings has not yet been completed.

Why It Matters

An authorization bypass that reaches code execution with zero authentication and zero user interaction would collapse the exploitation chain to a single step. Adobe Campaign Classic is a marketing orchestration platform that typically holds large volumes of customer contact and campaign data and integrates with surrounding delivery infrastructure, which raises the value of a successful compromise beyond the host itself.

Neither Adobe's advisory nor the NVD record cited here reports active exploitation, and this brief makes no determination about the vulnerability's status in CISA's Known Exploited Vulnerabilities catalog; defenders tracking KEV-driven deadlines should check the catalog directly for the current entry status. Regardless of that status, the scored attack profile argues for treating this on a short internal remediation timeline.

What's Vulnerable

Per Adobe's affected-product data:

Adobe lists a default status of "unaffected," meaning only the enumerated range above is in scope.

Patch Status

A fix is available. Upgrading Adobe Campaign Classic to 7.4.4 build 9402 or later remediates the issue. No workarounds or mitigations are described in the supplied source material. Because ACC build numbers are the deciding factor here, verify the exact build rather than the marketing version when confirming remediation.

Sources