Junglewise Threat Intelligence

CVE-2026-75699: Adobe Campaign Classic code injection vulnerability

CVE-2026-75699 · Severity: critical · CVSS 10 · Published 2026-09-22

Technologies: Microsoft Windows, Linux Kernel, Adobe Campaign Classic. Vendors: Microsoft, Linux, Adobe.

Executive brief

Adobe Campaign Classic, a marketing automation and customer engagement platform used by enterprises, contains a code injection vulnerability that allows attackers to execute arbitrary code with the privileges of the current user. An attacker can exploit this vulnerability remotely without requiring user interaction, potentially compromising sensitive campaign data, customer information, and business operations.

Technical details

An improper control of code generation flaw in Adobe Campaign Classic allows unauthenticated network-based code injection and arbitrary code execution in the context of the current user. The vulnerability requires no authentication or user interaction, indicating a network-accessible attack surface with direct impact to confidentiality, integrity, and availability.

Affected products

  • Adobe Campaign Classic

Timeline

  • 2026-09-22: disclosed

References

Related threats