Adobe has moved to patch a maximum-severity vulnerability in its Campaign Classic platform that grants remote attackers complete control over affected systems without any prior authentication. Tracked as CVE-2026-48449, the flaw has been rated at CVSS 10.0—the highest possible score in the Common Vulnerability Scoring System—according to reporting by Security Affairs.

The vulnerability stems from an incorrect authorization weakness within the enterprise marketing software. This defect enables what security professionals term a "zero-click" attack scenario, where an adversary requires no user interaction—such as clicking a link or opening a file—to execute arbitrary code on a target server. Any network-accessible instance of the vulnerable software is at risk.

Adobe Campaign Classic provides automation and analytics capabilities for managing customer communications and marketing data. An exploited flaw of this magnitude could lead to the theft of sensitive customer records, disruption of communication channels, or provide a beachhead for intruders to move laterally within an organization's internal network.

Security researchers urge immediate action. Administrators should apply Adobe's official patch as a matter of priority and conduct thorough log reviews to identify any signs of prior compromise. Due to the nature of the authorization flaw, no temporary workarounds or specific detection signatures have been published; mitigation is solely dependent on applying the vendor-supplied fix.

While no active exploitation has been publicly reported at the time of disclosure, the vulnerability's profile makes it a prime target for rapid weaponization. Threat actors, both opportunistic and targeted, are expected to develop exploits quickly. Organizations with Campaign Classic deployments accessible from the internet face the highest immediate risk and should prioritize remediation.

This incident highlights ongoing challenges in enterprise software security. It underscores the necessity for rigorous, swift patch management, particularly for platforms handling sensitive data. The shrinking window between vulnerability disclosure and widespread exploitation demands that IT teams maintain accurate inventories of critical software and prioritize security updates with the same urgency as patches for core infrastructure.

Administrators are advised to follow Adobe's official security bulletin for details rather than attempting custom mitigations, as limited technical specifics have been released. The focus should remain on applying the update, verifying system integrity, and enhancing monitoring for any anomalous activity on systems hosting Campaign Classic. For IT professionals managing enterprise marketing, CRM, or other customer-data platforms, this event serves as a critical reminder to review their own patch cadences and network exposure.


Adobe已著手修補其Campaign Classic平台中的一個最高嚴重性漏洞,該漏洞允許遠端攻擊者在無需任何先前驗證的情況下,完全控制受影響的系統。該漏洞被追蹤為CVE-2026-48449,據Security Affairs報導,其CVSS評分為10.0——這是通用漏洞評分系統中可能的最高評分。

該漏洞源於這款企業營銷軟件內的一項不正確授權弱點。此缺陷使得安全專業人士所稱的「零點擊」攻擊場景成為可能——攻擊者無需用戶互動(例如點擊鏈接或打開文件)即可在目標伺服器上執行任意代碼。任何可通過網絡訪問的該漏洞軟件實例都面臨風險。

Adobe Campaign Classic提供自動化及分析功能,用於管理客戶通訊及營銷數據。如此大規模的漏洞一旦被利用,可能導致敏感的客戶記錄被竊取、通訊渠道中斷,或為入侵者在其內部網絡進行橫向移動提供跳板。

安全研究人員敦促立即採取行動。管理員應優先應用Adobe官方補丁,並進行徹底的日誌審查,以識別先前是否存在任何入侵跡象。由於授權漏洞的性質,目前尚未發布任何臨時解決方案或特定檢測特徵;緩解措施完全依賴於應用供應商提供的修補程式。

雖然在披露時並未公開報告任何主動利用,但該漏洞的特徵使其成為迅速武器化的首要目標。預期機會型和針對性的威脅行為者將會快速開發攻擊程序。能夠從互聯網訪問Campaign Classic部署的組織面臨最高的即時風險,應優先進行補救。

此次事件凸顯了企業軟件安全方面持續存在的挑戰。它強調了嚴格、迅速補丁管理的必要性,尤其是對於處理敏感數據的平台。漏洞披露與大規模利用之間不斷縮短的窗口,要求IT團隊維護準確的關鍵軟件清單,並以處理核心基礎設施補丁同樣的緊迫性來優先處理安全更新。

管理員應遵循Adobe官方安全公告獲取詳細資訊,而非嘗試自定義的緩解措施,因為目前已發布的技術細節有限。重點應放在應用更新、驗證系統完整性,以及加強對託管Campaign Classic系統任何異常活動的監控上。對於管理企業營銷、CRM或其他客戶數據平台的IT專業人員而言,此事件是一個重要提醒,務須檢視自身的補丁管理週期及網絡暴露情況。

新聞來源 / Original News Source