ADOBE has released a critical security update for Adobe Campaign Classic addressing a vulnerability tracked as CVE-2026-48449, enabling remote code execution without user interaction (CVSS score: 10.0). Additionally, a high-severity SQL injection vulnerability (CVE-2026-48448, CVSS score: 8.6) was also patched. Both issues are resolved in version 7.4.3 build 9398 for Windows and Linux.
Adobe also addressed eight critical vulnerabilities in Adobe Bridge, with CVSS scores ranging from 7.8 to 8.6, affecting various types of security flaws, including incorrect authorization and path traversal.