Junglewise Threat Intelligence

CVE-2026-73369: Adobe Campaign Classic code injection vulnerability

CVE-2026-73369 · Severity: critical · CVSS 10 · Published 2026-09-22

Technologies: Microsoft Windows, Linux Kernel, Adobe Campaign Classic. Vendors: Microsoft, Linux, Adobe.

Executive brief

Adobe Campaign Classic, a marketing automation and customer data platform used by enterprises, contains a code injection flaw that allows an attacker to execute arbitrary code with the privileges of the affected user. An attacker can exploit this vulnerability remotely without requiring any user interaction, potentially gaining control over the application and accessing sensitive customer data or campaign information.

Technical details

This is an improper control of code generation (CWE-94) vulnerability in Adobe Campaign Classic that enables arbitrary code execution in the context of the current user. The vulnerability is network-exploitable without authentication or user interaction required, and impacts system confidentiality, integrity, and availability with changed scope.

Affected products

  • Adobe Campaign Classic

Timeline

  • 2026-09-22: disclosed

References

Related threats