Adobe has released security patches to address a maximum-severity vulnerability in Campaign Classic (ACC), its enterprise marketing automation platform, which could lead to arbitrary code execution This article explores vulnerabilities adobe. . The flaw, identified as CVE-2026-48449, is rated at 10.0 on the CVSS scoring system and involves incorrect authorization that allows for arbitrary code execution without requiring user interaction.
Additionally, another high-severity SQL injection flaw (CVE-2026-48448, CVSS score: 8.6) has been resolved by Adobe, which could enable arbitrary file reads. Adobe has released a critical update addressing vulnerabilities that could permit arbitrary code execution and unauthorized file system access, as stated in their advisory. The company hasn't encountered any exploits of these flaws in the wild.
Both issues have been resolved in version 7: 7.4.3 build 9398 for Windows and Linux systems. Additionally, Adobe has provided updates to mitigate eight critical vulnerabilities in Adobe Bridge that could lead to elevated privileges and arbitrary code execution - CVE-2026-48395 (CVSS score: 8.6), CVE-2026-48396 (CVSS score: 8.6), and CVE-2026-48390 (CVSS score: 8.6). The untrusted file path vulnerability leading to arbitrary code execution is called CVE-2026-48391 (CVSS score: 8.2), while the incorrect authorization flaw causing privilege escalation is known as CVE-2026-48374 (CVSS score: 7.8).
An unverified search path issue that results in arbitrary code execution is referred to as CVE-2026-48392 (CVSS score: 7.8), and a path traversal vulnerability that leads to unauthorized code execution is called CVE-2026-48393 (CVSS score: 7.8).
Lastly, an out-of-bounds write flaw leading to arbitrary code execution is identified by CVE-2026-48394 (CVSS score: 7.8). The security researcher Kieran ("kaiksi") discovered and reported these vulnerabilities - CVE-2026-48390, CVE-2026-48391, CVE-2026-48395, CVE-2026-48396, and CVE-2026-48374. Meanwhile, "yjdfy" found and reported the out-of-bounds write flaws - CVE-2026-48392, CVE-2026-48393, and CVE-2026-48394 to Adobe.
Users are advised to install the latest patches for maximum protection.












