# Adobe patches 18 critical Campaign Classic flaws

Published: 2026-09-24 · Severity: high · Sectors: technology, retail, media
Canonical: https://vorant.io/reports/852eb6b3-b8a9-51e9-a02e-73077d69aee9/adobe-patches-18-critical-campaign-classic-flaws

> Adobe fixed 18 critical vulnerabilities in Campaign Classic, including 8 CVSS 10.0 unauthenticated RCE bugs; NCSC-NL urges upgrade to 7.4.4 build 9402.

NCSC-NL published an advisory summarizing Adobe's patch for 18 critical vulnerabilities in Adobe Campaign Classic, a marketing automation platform. The flaws span OS command injection, SQL injection, code injection, incorrect authorization, and Server-Side Request Forgery (SSRF). Ten of the eighteen vulnerabilities can be exploited remotely without authentication, and eight of these (CVE-2026-82004, CVE-2026-73369, CVE-2026-84412, CVE-2026-89275, CVE-2026-75723, CVE-2026-75699, CVE-2026-75703, CVE-2026-75721) carry the maximum CVSS score of 10.0, requiring no authentication or user interaction. Seven of these are noted by Adobe as capable of arbitrary code execution; CVE-2026-75703 is noted for Denial-of-Service impact.

Successful exploitation across the full set of vulnerabilities could result in arbitrary code execution, privilege escalation, security control bypass, arbitrary file read, and denial of service. Adobe-hosted (cloud) environments have already been patched by Adobe; self-hosted/on-premises customers must apply the update themselves. No evidence of in-the-wild exploitation is mentioned in this advisory, but given the unauthenticated, zero-click nature of multiple critical RCE flaws, defenders running self-managed Adobe Campaign Classic instances should prioritize patching.

Remediation: update Adobe Campaign Classic to version 7.4.4 build 9402. Defenders should verify patch status of any on-premises deployments immediately, monitor for anomalous authentication-free requests to Campaign Classic endpoints, and review logs for signs of command/SQL injection or SSRF attempts pending confirmation of patch application.

## Mentioned in this report

- Vulnerabilities: CVE-2026-73369, CVE-2026-75699, CVE-2026-75703, CVE-2026-75721, CVE-2026-75723, CVE-2026-75728, CVE-2026-82003, CVE-2026-82004, CVE-2026-82008, CVE-2026-82009, CVE-2026-82010, CVE-2026-82011, CVE-2026-82013, CVE-2026-82443, CVE-2026-83660, CVE-2026-84412, CVE-2026-89275, CVE-2026-89276

Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0393.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/852eb6b3-b8a9-51e9-a02e-73077d69aee9/adobe-patches-18-critical-campaign-classic-flaws.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
