External risk intelligence

Adobe Campaign Classic Authorization Flaw Allows Code Execution.

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-75728

Adobe Campaign Classic is an enterprise marketing platform typically deployed as an internet-facing application or integrated into web-facing infrastructure to manage campaigns, email services, and customer-facing interactions, making it a common candidate for external network exposure.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

Adobe Campaign Classic, a marketing platform, has an Incorrect Authorization vulnerability that could allow an attacker to execute arbitrary code without user interaction. This means an attacker could potentially gain control of systems running the software. The main concern is confirming relevance and exposure.

  • Unauthorized code execution is possible.
  • It affects a critical marketing and customer interaction tool.
  • Confirm if your Adobe Campaign Classic is exposed.

Attack Path

How an attacker could exploit the issue

An attacker could reach the Adobe Campaign Classic application over the network to trigger an authorization flaw. This flaw allows an attacker to execute arbitrary code with the privileges of the user running the application.

  • No authentication required.
  • Flaw in authorization logic.
  • Arbitrary code execution risk.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in Adobe Campaign Classic could allow an unauthenticated attacker to execute arbitrary code on the affected system without user interaction. This could potentially lead to the compromise of the underlying operating system or the application itself.

  • Arbitrary code execution in the current user context.
  • Exploitable over the network without authentication.
  • Potential system compromise or data theft.

Operational Fix

Recommended remediation, mitigation, and detection steps

Security and infrastructure teams are likely responsible for this Adobe Campaign Classic vulnerability, given its potential for arbitrary code execution and network exposure. The immediate priority is to identify all instances of the affected technology, confirm their reachability and business criticality, and then engage the accountable owner to plan remediation, potentially involving vendor coordination or temporary risk reduction measures.

  • Own by application and infrastructure teams.
  • Verify network exposure and business criticality.
  • Plan remediation with vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Adobe Campaign Classic?

Adobe Campaign Classic is an enterprise-grade marketing platform designed to automate and manage complex customer interactions, email marketing campaigns, and personalized messaging across multiple channels. It acts as a centralized hub for data-driven marketing, often integrating directly with customer databases and public-facing web infrastructure to coordinate large-scale communication workflows.

How does CVE-2026-75728 lead to code execution?

This vulnerability is classified as an Incorrect Authorization flaw (CWE-863). Essentially, the software fails to properly verify or enforce permissions for specific requests. Because the authorization logic is flawed, an unauthenticated attacker can bypass these checks and send commands that the application executes, effectively gaining the ability to run arbitrary code using the privileges of the application's service account.

Do I need to interact with the software to trigger this bug?

No. The vulnerability does not require any user interaction or authentication to initiate. An attacker simply needs network access to the application to send the malicious request. It is important to note that internal application actions performed by legitimate, authenticated administrators are distinct from the unauthorized request path used to exploit this specific flaw.

Why is this CVE considered high risk in Halo Surface Signal?

Halo Surface Signal identifies this as a likely risk because Adobe Campaign Classic is typically designed to interact with external networks to manage email services and customer-facing touchpoints. Because these platforms often require internet connectivity to function, they are frequently positioned in network zones that are reachable by remote attackers, increasing the likelihood of exposure.

How should I respond to this threat?

Your first step is to locate all instances of Adobe Campaign Classic within your environment. Once identified, evaluate whether these instances are accessible via the network and prioritize those that are internet-facing. Collaborate with your application owners to verify your current version against the affected releases and coordinate with the vendor to apply the necessary security updates or configuration changes.

References