External risk intelligence

Adobe Campaign Classic SSRF Vulnerability Allows Arbitrary Code Execution

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-76193

Adobe Campaign Classic is an enterprise marketing automation platform frequently deployed as a web-facing service to manage public-facing email campaigns, landing pages, and web-based marketing workflows, making its components often reachable via the internet.

Server-Side Request Forgery

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

Adobe Campaign Classic is impacted by a critical security flaw allowing unauthenticated attackers to execute arbitrary code remotely by tricking the server into making unintended requests. This vulnerability could lead to a complete compromise of the affected system.

  • Flaw lets attackers run any code on the server.
  • Critical issue affects marketing automation platform.
  • Confirm relevance and exposure to business operations.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this flaw by sending specially crafted requests to Adobe Campaign Classic. This would allow them to make the server perform actions on their behalf, potentially leading to unauthorized code execution within the application.

  • Attackers can reach the vulnerable component over the network.
  • Specially crafted requests trigger the vulnerability.
  • Arbitrary code execution in the user's context.

Live Threat

Current exploitation, exposure, and threat context

A Server-Side Request Forgery vulnerability in Adobe Campaign Classic could allow an attacker to execute arbitrary code in the context of the current user. This could occur when supported by the advisory, potentially impacting system data and service behavior without requiring user interaction.

  • System data could be affected.
  • Attackers could exploit network access.
  • Arbitrary code execution may occur.

Operational Fix

Recommended remediation, mitigation, and detection steps

Given the SSRF vulnerability in Adobe Campaign Classic (ACC), ownership typically falls to the application owners or platform teams responsible for managing the marketing automation environment. The initial practical step is to identify all ACC instances, confirm their exposure and criticality, and then ascertain the specific accountable owner for each. This will inform a risk-based remediation plan, potentially involving vendor coordination and careful maintenance window planning.

  • Application or platform teams own.
  • Verify instance exposure and criticality.
  • Plan risk-based remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Adobe Campaign Classic?

Adobe Campaign Classic is an enterprise marketing automation platform. Organizations use it to manage large-scale email campaigns, build landing pages, and orchestrate complex, data-driven web marketing workflows that bridge the gap between customer data and digital delivery channels.

What does Server-Side Request Forgery mean in CVE-2026-76193?

This vulnerability is a Server-Side Request Forgery (CWE-918). It occurs when the software can be tricked into making unintended requests to internal or external systems. In this specific case, the flaw is critical because it enables an attacker to go beyond just making requests and execute arbitrary code on the underlying server.

How can an attacker trigger this vulnerability?

An attacker triggers this by sending specially crafted network requests to the Adobe Campaign Classic application. The vulnerability does not require any user interaction to succeed. It is important to note that standard, legitimate marketing traffic or routine database queries do not trigger this flaw; it specifically requires malformed input designed to exploit the request-handling process.

Is my Adobe Campaign Classic instance at risk?

Per Halo Surface Signal, this software is frequently deployed as a web-facing service to support public marketing assets, which often makes it reachable over the internet. If your instance is internet-facing, it is considered externally exposed. You should prioritize assessing instances that provide external services, as these are the most likely targets for network-based exploitation.

What should I do first to manage this CVE?

Your first step is to conduct a complete inventory to identify every instance of Adobe Campaign Classic running in your environment. Once identified, confirm which instances are internet-facing and verify who is responsible for their maintenance. Use this ownership data to coordinate with your platform teams to prepare for necessary vendor-provided updates or configuration changes.