Junglewise Threat Intelligence

CVE-2026-76193: Adobe Campaign Classic Server-Side Request Forgery to code execution

CVE-2026-76193 · Severity: critical · CVSS 10 · Published 2026-08-25

Technologies: Microsoft Windows, Linux Kernel, Adobe Campaign Classic. Vendors: Microsoft, Linux, Adobe.

Executive brief

Adobe Campaign Classic is a marketing automation platform used by enterprises to manage customer campaigns and communications. This vulnerability allows an attacker to bypass network restrictions and execute arbitrary code on the server without requiring user interaction, potentially compromising customer data, campaign infrastructure, and internal systems.

Technical details

Adobe Campaign Classic is affected by a Server-Side Request Forgery (SSRF) vulnerability that enables arbitrary code execution in the security context of the application. The SSRF flaw allows attackers to make requests to internal systems and resources that would normally be restricted, which in this case can be leveraged to achieve remote code execution. No user interaction is required for exploitation, and the scope is changed (indicating impact beyond the vulnerable component itself). The vulnerability is network-accessible, allowing remote exploitation by unauthenticated attackers.

Affected products

  • Adobe Campaign Classic <UNKNOWN>

Timeline

  • 2026-08-25: disclosed

References

Related threats