Ravie LakshmananAug 01, 2026Vulnerability / Enterprise Security

Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution.

The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system.

It has been described as a case of incorrect authorization that could result in arbitrary code execution in the context of the current user without requiring any user interaction.

The update also resolves another high-severity flaw (CVE-2026-48448, CVSS score: 8.6) stemming from SQL injection that could pave the way for arbitrary file reads.