Summary
| Parameter | Value |
|---|---|
| CVE ID | CVE-2026-76193, CVE-2026-76195, CVE-2026-76197 |
| Alert Source | GitHub Advisory - critical vulnerability (CNA: Adobe PSIRT) |
| CVE Publication Year | 2026 |
| Date Published | 2026-08-25 |
| Vendor | Adobe |
| Product | Adobe Campaign Classic (ACC) |
| Vendor bulletin | APSB26-134 |
| CVSS Score | 10.0 (Critical) — each of the three |
| EPSS Score | No data (CVEs published 2026-08-25) |
| CISA KEV | No |
| Ransomware | Not confirmed |
Vulnerability Description
Adobe published bulletin APSB26-134 covering three independent vulnerabilities in Adobe Campaign Classic. All three carry the maximum CVSS 10.0 score and all three lead to arbitrary code execution in the context of the current user. None requires user interaction, and in each case the scope changes — the impact extends beyond the component containing the flaw.
| CVE | Vulnerability class |
|---|---|
| CVE-2026-76193 | Server-Side Request Forgery (SSRF) leading to code execution |
| CVE-2026-76195 | OS Command Injection (CWE-78) |
| CVE-2026-76197 | OS Command Injection (CWE-78) |
Adobe Campaign Classic is a marketing automation platform — it drives email, SMS and push campaigns, and its databases hold customer personal data, contact history and marketing consents. Compromising an ACC server is therefore simultaneously a security incident and a personal data breach.
SSRF is especially dangerous in this architecture: the ACC server normally reaches internal databases, queues and services that are unreachable from outside. Exploiting SSRF lets an attacker issue requests from inside the segment — and combined with command injection that becomes full host takeover.
Adobe did not report active exploitation at the time of publication, but the combination of “CVSS 10 + no user interaction + internet-facing product” has historically shortened the time to a working exploit to days.
Required Actions
- Apply the fixes listed in Adobe bulletin APSB26-134. Check which version applies to your deployment — Adobe ships separate builds for the ACC v7 and v8 branches.
- Inventory exposure: determine whether the ACC console and application servers are reachable from the public internet. The tracking server and application server are often internet-facing because they handle opens and clicks in campaign sends.
- Until you patch, restrict inbound traffic to the necessary addresses and paths, and restrict outbound traffic from ACC servers to known destinations — this directly mitigates the SSRF vector.
- Review segmentation: the ACC server should not have unrestricted network reach into the rest of the environment. With SSRF, the host’s network reach determines the blast radius.
- Review logs for unusual requests to ACC endpoints and for unexpected child processes spawned by the Campaign service account.
Who Is Affected?
Organisations running Adobe Campaign Classic on-premise or in a managed hosting model. It is deployed primarily by large B2C companies running mass customer communication — telecommunications, retail banking, insurance, retail chains and e-commerce. These are enterprise deployments, chosen where audience size and compliance requirements rule out simpler sending tools.
ACC is typically owned by marketing rather than IT, and that is the practical difficulty with this alert. The platform often sits outside the standard infrastructure patch cycle even though it processes personal data for the entire customer base. Treat this bulletin as an opportunity to confirm who formally owns ACC updates.
Sources
Need help securing your systems? nFlo team offers vulnerability management and 24/7 SOC services. Contact us.
