Adobe has released important security updates to fix several critical vulnerabilities affecting Adobe Campaign Classic (ACC) and Adobe Bridge.
The most serious issue, tracked as CVE-2026-48449, received the highest possible CVSS score of 10.0 and could allow attackers to execute arbitrary code on affected systems.
The vulnerability is caused by an incorrect authorization issue that lets an attacker run code in the context of the current user without requiring any user interaction. Adobe also fixed another high-severity flaw, CVE-2026-48448 (CVSS 8.6), which is caused by an SQL injection vulnerability that could allow arbitrary file reads.
According to Adobe, these vulnerabilities could lead to arbitrary code execution and unauthorized access to files. However, the company said it has no evidence that either flaw has been exploited in real-world attacks.
The security fixes are included in Adobe Campaign Classic v7.4.3 build 9398 for both Windows and Linux systems.
In addition, Adobe has released updates for Adobe Bridge, patching eight critical vulnerabilities that could be exploited for privilege escalation or arbitrary code execution. The affected flaws include CVE-2026-48395, CVE-2026-48396, CVE-2026-48390, CVE-2026-48391, CVE-2026-48374, CVE-2026-48392, CVE-2026-48393, and CVE-2026-48394. These issues involve untrusted search path vulnerabilities, incorrect authorization, path traversal, and out-of-bounds write bugs.
Adobe credited security researcher Kieran (“kaiksi”) for reporting five of the Adobe Bridge vulnerabilities, while researcher “yjdfy” reported the remaining three out-of-bounds write issues.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
Users and organizations running Adobe Campaign Classic or Adobe Bridge are strongly encouraged to install the latest security updates as soon as possible to protect their systems from potential attacks.





