Skip to content
Security Alerts

CVE-2026-76193, 76195, 76197: three CVSS 10 flaws in Adobe Campaign Classic leading to code execution

Adobe Campaign Classic has three vulnerabilities scored CVSS 10.0 — one SSRF and two OS command injections. Each leads to arbitrary code execution and none requires user interaction...

Summary

ParameterValue
CVE IDCVE-2026-76193, CVE-2026-76195, CVE-2026-76197
Alert SourceGitHub Advisory - critical vulnerability (CNA: Adobe PSIRT)
CVE Publication Year2026
Date Published2026-08-25
VendorAdobe
ProductAdobe Campaign Classic (ACC)
Vendor bulletinAPSB26-134
CVSS Score10.0 (Critical) — each of the three
EPSS ScoreNo data (CVEs published 2026-08-25)
CISA KEVNo
RansomwareNot confirmed

Vulnerability Description

Adobe published bulletin APSB26-134 covering three independent vulnerabilities in Adobe Campaign Classic. All three carry the maximum CVSS 10.0 score and all three lead to arbitrary code execution in the context of the current user. None requires user interaction, and in each case the scope changes — the impact extends beyond the component containing the flaw.

CVEVulnerability class
CVE-2026-76193Server-Side Request Forgery (SSRF) leading to code execution
CVE-2026-76195OS Command Injection (CWE-78)
CVE-2026-76197OS Command Injection (CWE-78)

Adobe Campaign Classic is a marketing automation platform — it drives email, SMS and push campaigns, and its databases hold customer personal data, contact history and marketing consents. Compromising an ACC server is therefore simultaneously a security incident and a personal data breach.

SSRF is especially dangerous in this architecture: the ACC server normally reaches internal databases, queues and services that are unreachable from outside. Exploiting SSRF lets an attacker issue requests from inside the segment — and combined with command injection that becomes full host takeover.

Adobe did not report active exploitation at the time of publication, but the combination of “CVSS 10 + no user interaction + internet-facing product” has historically shortened the time to a working exploit to days.

Required Actions

  1. Apply the fixes listed in Adobe bulletin APSB26-134. Check which version applies to your deployment — Adobe ships separate builds for the ACC v7 and v8 branches.
  2. Inventory exposure: determine whether the ACC console and application servers are reachable from the public internet. The tracking server and application server are often internet-facing because they handle opens and clicks in campaign sends.
  3. Until you patch, restrict inbound traffic to the necessary addresses and paths, and restrict outbound traffic from ACC servers to known destinations — this directly mitigates the SSRF vector.
  4. Review segmentation: the ACC server should not have unrestricted network reach into the rest of the environment. With SSRF, the host’s network reach determines the blast radius.
  5. Review logs for unusual requests to ACC endpoints and for unexpected child processes spawned by the Campaign service account.

Who Is Affected?

Organisations running Adobe Campaign Classic on-premise or in a managed hosting model. It is deployed primarily by large B2C companies running mass customer communication — telecommunications, retail banking, insurance, retail chains and e-commerce. These are enterprise deployments, chosen where audience size and compliance requirements rule out simpler sending tools.

ACC is typically owned by marketing rather than IT, and that is the practical difficulty with this alert. The platform often sits outside the standard infrastructure patch cycle even though it processes personal data for the entire customer base. Treat this bulletin as an opportunity to confirm who formally owns ACC updates.

Sources


Need help securing your systems? nFlo team offers vulnerability management and 24/7 SOC services. Contact us.

Learn More

Share:

Talk to an expert

Have questions about this topic? Get in touch with our specialist.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Response within 24 hours
Free consultation
Individual approach

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist