Junglewise Threat Intelligence

CVE-2026-76197: Adobe Campaign Classic OS command injection

CVE-2026-76197 · Severity: critical · CVSS 10 · Published 2026-08-25

Technologies: Microsoft Windows, Linux Kernel, Adobe Campaign Classic. Vendors: Microsoft, Linux, Adobe.

Executive brief

Adobe Campaign Classic is a marketing automation and customer communications platform used by organizations to manage customer interactions and campaigns. A critical vulnerability allows unauthenticated attackers to execute arbitrary code on affected systems without user interaction, potentially leading to complete system compromise, data theft, or installation of malware.

Technical details

Adobe Campaign Classic is vulnerable to OS command injection through improper neutralization of special elements in OS commands. The vulnerability allows an attacker on the network to inject arbitrary shell commands that are executed in the context of the Campaign application. No user interaction or authentication is required to exploit this vulnerability. A successful exploit grants an attacker arbitrary code execution, enabling them to take full control of the affected server. Patches are expected to be available from Adobe; users should apply security updates as soon as they become available.

Affected products

  • Adobe Campaign Classic <UNKNOWN>

Timeline

  • 2026-08-25: disclosed

References

Related threats