Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
What happened
Adobe released security updates for Campaign Classic to address CVE-2026-48449, a maximum-severity flaw with a CVSS score of 10.0. The vulnerability involves incorrect authorization that could allow unauthenticated attackers to achieve arbitrary code execution.
Why it ranks #1
Highest priority due to the critical nature of a CVSS 10.0 RCE in enterprise infrastructure, representing immediate high-impact exposure.
Who should care
Application security teams, IT and platform operations
What to do
Apply Adobe Campaign Classic security updates immediately.
- Impact
- high
- Urgency
- near-term
- Confidence
- high
- Scope
- enterprise
- Status
- disclosed