Cyber & AI intelligence
Wasteland.
Briefs indexed2842
Issues29
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-89275 2026-09-22

CVE-2026-89275: Adobe Campaign Classic Code Injection Scores a Perfect 10.0

"Adobe Campaign Classic contains an unauthenticated code injection flaw that allows arbitrary code execution with no user interaction, rated CVSS 3.1 10.0 CRITICAL."

Adobe Campaign Classic contains an unauthenticated code injection flaw that allows arbitrary code execution with no user interaction, rated CVSS 3.1 10.0 CRITICAL.

What Is It

CVE-2026-89275 is an Improper Control of Generation of Code ('Code Injection') vulnerability (CWE-94) in Adobe Campaign Classic (ACC). Per Adobe's advisory data, the flaw "could result in arbitrary code execution in the context of the current user," and "exploitation of this issue does not require user interaction."

The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, network-reachable, low attack complexity, no privileges required, no user interaction, and a changed scope with high impact to confidentiality, integrity, and availability. That combination produces the maximum base score of 10.0, with an exploitability subscore of 3.9 and an impact subscore of 6.0.

Why It Matters

Nearly every barrier an attacker normally has to clear appears to be absent here, at least as the CVSS metrics describe it. There is no authentication requirement, no user to phish, and no complexity penalty; the attack is reachable over the network against an exposed instance.

The scope change is the detail worth dwelling on. A changed scope means the impact extends beyond the vulnerable component itself, so successful exploitation is likely not contained to the Campaign Classic process boundary. Combined with code execution and high impact across all three CIA dimensions, this reads as a full-compromise primitive.

The CVE was published 2026-09-22 and NVD lists it as "Awaiting Analysis," so the record has not yet been enriched with CPEs or secondary scoring.

What's Vulnerable

Adobe lists Adobe Campaign Classic as affected at all versions up to and including 7.4.4 build 9401. Build 7.4.4 build 9402 is listed as unaffected. No CPE records are present in the NVD entry yet.

Patch Status

A fixed build exists: 7.4.4 build 9402. Operators running 9401 or earlier should upgrade to build 9402 or later. Adobe's advisory APSB26-142 is the authoritative reference.

As of publication, this CVE does not appear in the CISA Known Exploited Vulnerabilities catalog, so there is no federal remediation deadline attached to it and no publicly confirmed report of exploitation in the wild. Absence from the KEV catalog is not itself evidence that exploitation is not occurring; it reflects only what CISA has catalogued to date, and operators should check the catalog directly for the current status.

Sources