External risk intelligence

Adobe Campaign Classic Code Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-75699

Adobe Campaign Classic is an enterprise marketing automation platform designed to manage and deliver multi-channel campaigns, often requiring web-facing interfaces, API integrations, and communication gateways that are typically accessible via the public internet to facilitate campaign management and data processing.

Code Injection

Adobe Campaign

7.4.3 and earlier7.4.4

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

Adobe Campaign Classic is impacted by a critical code injection vulnerability that could allow an attacker to execute arbitrary code without user interaction. This issue is particularly concerning as it affects a marketing automation platform, potentially exposing sensitive campaign data and operational integrity. The main concern at this stage is to confirm if this technology is in use and assess any potential exposure.

  • Attackers can run unauthorized code.
  • Affects marketing automation, a critical business function.
  • Verify if Adobe Campaign Classic is in use.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending a crafted request to an exposed Adobe Campaign Classic instance. This could allow them to inject and execute arbitrary code on the server, potentially leading to a compromise of the system and its data.

  • No user interaction needed.
  • Network-accessible code injection.
  • Arbitrary code execution and data compromise.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in Adobe Campaign Classic could allow an attacker to execute arbitrary code on the system without user interaction, potentially affecting system data and service behavior when the product is exposed to the network.

  • System code execution.
  • Network access enables exploitation.
  • Unauthorized system control.

Operational Fix

Recommended remediation, mitigation, and detection steps

Technical leaders and security teams should prioritize identifying all instances of Adobe Campaign Classic within their environment. Given the potential for arbitrary code execution and the external exposure of this technology, confirming its reachability and business criticality is essential. The first practical step is to locate accountable owners for these deployments and then develop a remediation plan aligned with identified risks.

  • Application owners should manage remediation efforts.
  • Verify external exposure and business criticality first.
  • Plan and coordinate vendor-supported updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Adobe Campaign Classic?

Adobe Campaign Classic is an enterprise-grade marketing automation platform. Organizations use it to design, manage, and deliver multi-channel campaigns, handling complex tasks like customer data processing and large-scale message distribution across email, mobile, and web channels.

What does the code injection vulnerability in CVE-2026-75699 mean?

This vulnerability is classified as Improper Control of Generation of Code (CWE-94). In plain terms, it means the software fails to properly filter instructions provided to it. An attacker can supply malicious commands that the system mistakenly runs as if they were legitimate internal instructions, granting the attacker unauthorized control over the server.

How is this vulnerability triggered?

An attacker triggers this flaw by sending a specially crafted network request to the application. Because the system accepts and processes this input without requiring any action from a user, the attack can occur automatically. The vulnerability is triggered by the processing of these requests, not by typical user navigation or standard data entry.

Why should I care about this CVE if I use this software?

According to Halo Surface Signal, Adobe Campaign Classic is often deployed with web-facing interfaces or API integrations to enable campaign management. Because these components are typically accessible via the public internet, they are prime targets for external attackers to gain unauthorized access to your marketing data and infrastructure.

What are the first steps to take if I run Adobe Campaign Classic?

Begin by identifying all active instances of the software and their assigned owners within your organization. Confirm whether these specific deployments are reachable from the internet, as this increases the risk. Once mapped, coordinate with your technical teams to plan for vendor-provided updates to secure your environment.

References