External risk intelligence

Adobe Campaign Classic Code Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-75721

Adobe Campaign Classic is an enterprise marketing automation platform frequently deployed as a web-based application or API-connected service to manage marketing campaigns, often requiring network or web accessibility to function in its intended role.

Code Injection

Adobe Campaign

7.4.3 and earlier7.4.4

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

Adobe Campaign Classic has a critical vulnerability that could allow an attacker to run unauthorized code on a system, potentially leading to widespread compromise. This issue impacts a core marketing automation platform, underscoring the need to confirm its relevance to our environment.

  • Code execution flaw in marketing software.
  • Critical flaw impacts a core business platform.
  • Confirm exposure and relevance to our systems.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending specially crafted data to Adobe Campaign Classic, a marketing automation platform. This could allow them to execute arbitrary code on the affected system without needing any user interaction. The vulnerability's scope is changed, meaning it could impact components beyond the immediate application.

  • No user interaction required for exploitation.
  • Triggered by specially crafted data to the application.
  • Allows arbitrary code execution, impacting the user.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, this vulnerability could allow an unauthenticated attacker to execute arbitrary code on the affected system. This could lead to a complete compromise of the system's integrity and confidentiality.

  • Arbitrary code execution in user context.
  • Exploitation through network access, no interaction.
  • Potential for full system compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

Given that Adobe Campaign Classic is often deployed as a network-accessible application for marketing automation, the Platform team or Application owner is likely responsible for addressing this vulnerability. The first practical step is to identify all instances of Adobe Campaign Classic, confirm their network exposure and business criticality, and then engage the vendor for a solution or plan remediation based on risk.

  • Platform or application owners should lead remediation.
  • Verify all Adobe Campaign Classic instances.
  • Coordinate vendor support and plan risk reduction.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Adobe Campaign Classic?

Adobe Campaign Classic is an enterprise-grade platform used by marketing teams to manage and automate cross-channel marketing campaigns. It typically functions as a web-based application or an API-connected service, allowing organizations to coordinate messaging and customer data at scale.

How does CVE-2026-75721 cause a code injection weakness?

This vulnerability falls under the CWE-94 weakness class, which refers to improper control of code generation. In simple terms, the software fails to properly sanitize or validate incoming data, allowing an attacker to inject their own instructions. The system then mistakenly treats this malicious input as legitimate executable code, leading to unauthorized actions.

What triggers the vulnerability in Adobe Campaign Classic?

An attacker triggers this flaw by sending specially crafted data packets to the application over the network. Crucially, the system does not require any human interaction, such as clicking a link or opening a file, for the code to execute. This vulnerability is not triggered by standard, legitimate marketing traffic or normal platform usage.

How do I know if my environment is at risk according to Halo Surface Signal?

Halo Surface Signal identifies this as a higher-relevance issue because Adobe Campaign Classic is often designed to be web-accessible or API-connected to perform its marketing functions. Because it is frequently internet-facing to communicate with external services, it may be accessible to unauthorized parties, increasing the potential for exploitation.

What is the first step to address this CVE?

You should immediately identify every instance of Adobe Campaign Classic running in your infrastructure. Once identified, evaluate whether these instances are exposed to the network and determine their business criticality. Engage with your vendor support channels to obtain the official security update or guidance required to mitigate this risk.

References