External risk intelligence

Adobe Campaign Classic Code Injection leads to Arbitrary Code Execution

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-75703

Adobe Campaign Classic is an enterprise-grade marketing automation and campaign management platform. These solutions are commonly deployed as internet-facing web applications or API-driven services to manage customer interactions, campaigns, and web-based tracking, making them reachable and exposed to the public internet in typical deployment patterns.

Code Injection

Adobe Campaign

7.4.3 and earlier7.4.4

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

Adobe Campaign Classic, a platform for managing customer interactions and marketing campaigns, has a critical vulnerability that could allow attackers to execute arbitrary code remotely without any user interaction. The main concern is confirming if your organization uses this specific Adobe product.

  • Code execution flaw found in Adobe Campaign Classic.
  • Critical remote code execution vulnerability exists.
  • Confirm if Adobe Campaign Classic is in use.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending a specially crafted request to Adobe Campaign Classic. This could lead to arbitrary code execution within the context of the current user, potentially allowing the attacker to compromise the affected system. No user interaction is required for exploitation, and the vulnerability's scope is changed, indicating a broader impact.

  • No authentication or user interaction needed.
  • Triggered via specially crafted network requests.
  • Allows arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in Adobe Campaign Classic could allow an attacker to execute arbitrary code on a system without any user interaction. This could affect the integrity and availability of the application and potentially any data it processes or manages.

  • Arbitrary code execution on the server.
  • Exploited via network without interaction.
  • Compromise of application and its data.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Adobe Campaign Classic (ACC) platform, often deployed externally for marketing and customer interaction management, requires immediate attention from application owners and infrastructure teams. The initial focus should be on identifying all ACC instances, assessing their reachability and business criticality, and locating the accountable owner to plan a risk-based remediation strategy.

  • Application owners must take charge.
  • Verify ACC instance exposure and criticality.
  • Plan remediation based on assessed risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Adobe Campaign Classic?

Adobe Campaign Classic is an enterprise marketing automation platform. Organizations use it to orchestrate customer interactions, manage cross-channel campaigns, and handle data-driven marketing workflows across various digital touchpoints.

What does CWE-94 mean for CVE-2026-75703?

CWE-94, or Improper Control of Generation of Code, describes a vulnerability where an application fails to properly sanitize user-supplied input before executing it as code. In this CVE, it allows an attacker to inject and run unauthorized commands on the server.

How is CVE-2026-75703 triggered?

This vulnerability is triggered when an attacker sends a specially crafted network request to the application. It does not require any user interaction, such as clicking a link or logging in, to execute the malicious code.

Why does Halo Surface Signal flag this as external?

Halo Surface Signal labels this as external because Adobe Campaign Classic is typically deployed as an internet-facing web application or API-driven service. This deployment pattern makes the software reachable from the public internet, increasing its accessibility to potential threats.

Is my instance of Adobe Campaign Classic vulnerable?

You should first verify if your organization runs Adobe Campaign Classic versions up to 7.4.3, or specific builds within 7.4.4. If you use these, identify the system's business criticality and consult official vendor guidance to plan your next steps.

References