Cyber & AI intelligence
Wasteland.
Briefs indexed2597
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-82004 2026-09-08

CVE-2026-82004: Critical OS Command Injection in Adobe Campaign Classic

"Adobe Campaign Classic contains an unauthenticated OS command injection flaw that allows arbitrary code execution over the network with no user interaction, rated CVSS 10.0."

Adobe Campaign Classic contains an unauthenticated OS command injection flaw that allows arbitrary code execution over the network with no user interaction, rated CVSS 10.0.

What Is It

CVE-2026-82004 is an Improper Neutralization of Special Elements used in an OS Command vulnerability (CWE-78) affecting Adobe Campaign Classic (ACC). Special characters passed into an OS command are not properly neutralized, allowing an attacker to execute arbitrary code in the context of the current user. Adobe's PSIRT published the advisory on 2026-09-08; the NVD record remains in "Undergoing Analysis" status.

Why It Matters

The vulnerability carries a CVSS 3.1 base score of 10.0 (CRITICAL) with vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. Every exploitability factor is worst-case: the attack is remotely reachable over the network, requires low attack complexity, needs no privileges, and requires no user interaction. The UI:N component of the vector published in Adobe's advisory is the basis for the no-user-interaction assessment.

The scope is marked as changed, meaning successful exploitation impacts resources beyond the vulnerable component's security authority; a compromise is not contained to the ACC process itself. Confidentiality, integrity, and availability impacts are all rated High, giving the maximum exploitability subscore of 3.9 and an impact subscore of 6.0.

Adobe Campaign Classic is a marketing campaign management platform that typically holds large volumes of customer contact data, making arbitrary code execution on these hosts a high-value outcome for an attacker.

What's Vulnerable

Per Adobe's affected-product data:

No CPE match data has been published in the NVD record yet.

Patch Status

Adobe has released a fixed build. Upgrading Adobe Campaign Classic to 7.4.4 build 9402 or later remediates the issue. Refer to Adobe Security Bulletin APSB26-142 for full upgrade guidance.

CVE-2026-82004 does not appear in the CISA Known Exploited Vulnerabilities catalog at this time; there is no confirmed evidence of active exploitation in the wild, and therefore no federally mandated remediation deadline. Given the 10.0 score and the absence of any authentication or interaction requirement, this should still be treated as an urgent patch regardless of KEV status.

Sources