External risk intelligence

Adobe Campaign Classic Code Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-73369

Adobe Campaign Classic is an enterprise-grade marketing automation and campaign management platform. These systems are commonly deployed as web-based applications, often integrated with public-facing marketing assets, APIs, and customer engagement portals, making their management interfaces or associated service endpoints frequently accessible via the internet or edge network environments.

Code Injection

Adobe Campaign

7.4.3 and earlier7.4.4

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

Adobe Campaign Classic contains a critical vulnerability allowing attackers to execute arbitrary code without user interaction by exploiting a code injection flaw. This means an attacker could potentially take control of systems running this software remotely. The main concern is confirming whether our environment is affected and understanding the potential exposure.

  • Code injection vulnerability affects Adobe Campaign Classic.
  • Attackers can remotely execute code without user interaction.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker could exploit a code injection vulnerability in Adobe Campaign Classic to execute arbitrary code on the affected system. This could occur without any user interaction, allowing an attacker to compromise the system by sending specially crafted requests to the vulnerable component. The vulnerability allows for arbitrary code execution, potentially leading to a full system compromise.

  • No user interaction required.
  • Specially crafted requests to vulnerable component.
  • Arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

An attacker could execute arbitrary code on the system when this vulnerability is exploited in Adobe Campaign Classic. This could allow them to perform actions as if they were the current user, potentially impacting system data and service behavior.

  • System data and service behavior at risk.
  • Arbitrary code execution by attackers.
  • Compromised system integrity and availability.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in Adobe Campaign Classic (ACC) requires immediate attention from the platform or application owners responsible for its deployment and ongoing maintenance. The first practical step is to locate all instances of ACC, assess their exposure (especially if internet-facing), and identify the business-criticality of each deployment to prioritize remediation efforts.

  • Platform or application owners should manage.
  • Verify ACC instances and exposure first.
  • Plan risk-based remediation or vendor engagement.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Adobe Campaign Classic?

Adobe Campaign Classic is an enterprise marketing automation platform designed to manage and orchestrate cross-channel customer campaigns. It functions as a centralized engine for coordinating marketing workflows, data, and communications across large organizations, often serving as a backend hub for various customer engagement portals and APIs.

What is the code injection weakness in CVE-2026-73369?

This vulnerability, classified as CWE-94, occurs when an application improperly handles user-supplied data, allowing it to be interpreted as executable code. In the context of CVE-2026-73369, this flaw allows an attacker to inject and run unauthorized commands directly on the server, effectively gaining the same privileges as the software process itself.

How is this Adobe Campaign Classic vulnerability triggered?

An attacker triggers this flaw by sending specially crafted network requests to the vulnerable component. Because the vulnerability does not require any user interaction—such as clicking a link or logging in—the system is susceptible simply by being reachable, provided the attacker can reach the specific, vulnerable service endpoint.

Do I need to worry if my Adobe Campaign Classic instance is internal?

While internal systems are generally safer, Halo Surface Signal notes that this software is frequently deployed with public-facing interfaces, APIs, and web-based endpoints. You should prioritize assessing any instance that is connected to, or reachable from, the internet or edge network environments, as these are the primary targets for this remote vulnerability.

When should I take action for CVE-2026-73369?

You should act immediately by identifying all active instances of Adobe Campaign Classic within your environment. Once identified, evaluate the network accessibility and business importance of each deployment to prioritize your patching or configuration updates, ensuring that the most exposed and critical assets are secured first.

References