Adobe has initiated a series of urgent security updates to address multiple high-risk vulnerabilities discovered within its enterprise marketing automation platform, Adobe Campaign Classic, and its creative asset management software, Adobe Bridge. The most concerning issue, tracked as CVE-2026-48449, carries a CVSS score of 10.0 and affects Campaign Classic. According to Security Affairs, this flaw stems from improper authorization protocols, potentially allowing unauthorized actors to perform remote code execution without requiring user interaction. Organizations are strongly urged to update to build 9398 on Windows and Linux platforms immediately to mitigate this risk.
In addition to the maximum-severity vulnerability in Campaign Classic, Adobe also rectified a high-severity SQL injection flaw, CVE-2026-48448, which could facilitate unauthorized file access. The update cycle further extended to Adobe Bridge, where developers patched eight critical vulnerabilities. These Bridge-related issues—ranging from path traversal to out-of-bounds write errors—could permit attackers to escalate privileges or execute arbitrary code. Researchers Kieran (kaiksi) and yjdfy were instrumental in identifying these specific flaws. While there are currently no known instances of these vulnerabilities being actively exploited in the wild, the complexity of the bugs necessitates immediate deployment of the latest security patches to ensure system integrity.
Reader Discussion & Insights