ADOBE has released security patches for three critical flaws in Adobe Campaign Classic on August 25, 2026, all scoring maximum CVSS of 10.0. These vulnerabilities allow arbitrary code execution and affect on-premise installations (ACC v7 build 9400 and earlier) on both Windows and Linux. The flaws include OS command injection and a server-side request forgery bug, which could lead to severe impacts without requiring user interaction.
Currently, there are no confirmed exploitations, but Adobe recommends immediate updating to version 7.4.4 build 9401. The update has a Priority 1 rating due to the high risk involved.