Cyber & AI intelligence
Wasteland.
Briefs indexed2842
Issues29
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-83660 2026-09-22

CVE-2026-83660: Critical SSRF in Adobe Campaign Classic Enables Privilege Escalation

"Adobe has disclosed a critical (CVSS 9.9) server-side request forgery flaw in Adobe Campaign Classic that, according to the vendor advisory, could result in privilege escalation. The CVSS vector describes a remote…"

Adobe has disclosed a critical (CVSS 9.9) server-side request forgery flaw in Adobe Campaign Classic that, according to the vendor advisory, could result in privilege escalation. The CVSS vector describes a remote, unauthenticated attack path requiring no user interaction; Adobe has not published exploitation details, and no public exploit or in-the-wild activity has been reported for this record.

What Is It

CVE-2026-83660 is a Server-Side Request Forgery vulnerability (CWE-918) in Adobe Campaign Classic (ACC). Per Adobe's advisory, the issue "could result in privilege escalation," and "exploitation of this issue does not require user interaction."

The CVSS 3.1 vector, AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L, carries a base score of 9.9 (CRITICAL), with an exploitability subscore of 3.9 and an impact subscore of 5.3. The vulnerability was published on 2026-09-22 and is currently in "Awaiting Analysis" status at NVD.

Why It Matters

Every factor that makes a vulnerability easy to exploit is present in the scoring: network attack vector, low attack complexity, no privileges required, and no user interaction. On paper, that combination means an attacker who can reach an ACC instance over the network would need nothing else to begin; though the score reflects Adobe's assessment of the flaw, not a demonstrated attack.

The scope is marked as Changed, meaning successful exploitation would affect resources beyond the vulnerable component's own security authority; a key reason this scores 9.9 rather than lower. Impact is rated High for confidentiality, with Low integrity and availability impact. SSRF that crosses a scope boundary and could yield privilege escalation is, as a class, a plausible route to internal services not otherwise exposed; the specific reachable targets in an ACC deployment have not been detailed publicly.

This CVE does not currently appear in the CISA Known Exploited Vulnerabilities catalog. No KEV entry and no confirmed active exploitation were supplied with this record, and no required-action deadline applies.

What's Vulnerable

Adobe lists the affected product as Adobe Campaign Classic, with a default status of unaffected except for the following:

No CPE configurations have been published by NVD yet, so automated scanner coverage may lag. Operators should verify build numbers directly rather than relying on major-version checks alone.

Patch Status

Adobe has shipped a fix. Upgrading Adobe Campaign Classic to 7.4.4 build 9402 remediates the issue. Given the critical rating and the unauthenticated, no-interaction profile described in the CVSS vector, administrators of internet-reachable ACC instances should prioritize this update. Consult Adobe security bulletin APSB26-142 for full upgrade guidance.

Sources


One thing you need to know outside the article: the h1_title note reached me truncated; it cut off at Frontmatter says "CVE-2026-83660: Critical SSRF in Adobe Campaign Classic E. I reconstructed the tail as "Enables Privilege Escalation," which is the most likely completion, but verify it against the actual frontmatter. Note that "Enables" asserts as fact what Adobe only states as "could result in," so if the real frontmatter title is hedged, use that instead.