Cyber & AI intelligence
Wasteland.
Briefs indexed2842
Issues29
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-89276 2026-09-22

CVE-2026-89276: Critical Code Injection in Adobe Campaign Classic

"Adobe disclosed a critical code injection flaw (CVSS 9.9) in Adobe Campaign Classic that lets a low-privileged, network-based attacker execute arbitrary code without any user interaction."

Adobe disclosed a critical code injection flaw (CVSS 9.9) in Adobe Campaign Classic that lets a low-privileged, network-based attacker execute arbitrary code without any user interaction.

What Is It

CVE-2026-89276 is an Improper Control of Generation of Code vulnerability (CWE-94) in Adobe Campaign Classic (ACC). Per Adobe's advisory, the flaw "could result in arbitrary code execution in the context of the current user," and "a low-privileged attacker could exploit this vulnerability to execute arbitrary code." Exploitation does not require user interaction, and the CVSS scope is marked as changed; meaning impact can extend beyond the vulnerable component's own security boundary.

The CVSS 3.1 vector is AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L, producing a base score of 9.9 (CRITICAL) with an exploitability subscore of 3.1 and an impact subscore of 6.0. The record was published 2026-09-22 by Adobe PSIRT and is currently in "Awaiting Analysis" status at NVD.

Why It Matters

Everything about this vector favors the attacker: network reachable, low attack complexity, no user interaction, and only low privileges required. Any authenticated account on an exposed ACC instance is a viable launch point. Confidentiality and integrity impacts are both rated High, with Low availability impact, and the changed scope pushes the score to near-maximum.

CISA's Known Exploited Vulnerabilities catalog, version 2026.09.22, released 2026-09-22, 1,721 entries, contains no entry for CVE-2026-89276. There is accordingly no KEV-mandated federal remediation deadline, and no public confirmation of active exploitation at the time of writing. Defenders should treat the severity of the vector, not KEV status, as the basis for prioritization here.

What's Vulnerable

Per Adobe's affected-products data:

The vendor default status for other versions is "unaffected." NVD has not yet published CPE match data for this CVE.

Patch Status

A fixed build exists. Adobe's data identifies ACC 7.4.4 build 9402 as the first unaffected version, so upgrading to build 9402 or later is the remediation path. Full guidance is in Adobe security bulletin APSB26-142. Adobe describes no workarounds or mitigations beyond the update.

Sources