External risk intelligence

Adobe Campaign Classic OS Command Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-76195

Adobe Campaign Classic is an enterprise marketing automation platform. While typically deployed within internal network segments or behind strict access controls to manage sensitive customer data, it can be exposed to the internet in specific configurations to facilitate external marketing workflows, making remote reachability possible but not the default or standard design for all deployments.

OS Command Injection

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

Adobe Campaign Classic, a marketing automation platform, has a critical vulnerability that could allow an attacker to run unauthorized code without user interaction. While typically protected, certain configurations might expose it to remote exploitation, posing a risk to sensitive customer data and operational integrity.

  • Unchecked input allows attackers to run commands.
  • Critical remote code execution risk for marketing platform.
  • Confirm if your Adobe Campaign Classic is exposed.

Attack Path

How an attacker could exploit the issue

An attacker could exploit a vulnerability in Adobe Campaign Classic by sending a specially crafted request over the network. This request would target a component that does not properly neutralize special characters in operating system commands. Successful exploitation could lead to the execution of arbitrary code with the privileges of the affected user, potentially allowing the attacker to take control of the system.

  • No authentication required.
  • OS command injection via network request.
  • Arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in Adobe Campaign Classic could allow an attacker to execute arbitrary code on the affected system, potentially leading to the compromise of system data and service behavior. This could occur if the application is exposed to the internet, enabling an attacker to send specially crafted commands.

  • System data could be affected.
  • Arbitrary code execution is possible.
  • Compromise of system data and behavior.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in Adobe Campaign Classic, an OS Command Injection flaw, necessitates immediate attention from teams responsible for application security and infrastructure. The first practical step is to locate all instances of Adobe Campaign Classic, determine their external reachability and business criticality, identify the specific system owner, and then prioritize remediation efforts.

  • Identify application and infrastructure owners.
  • Verify external reachability and criticality.
  • Plan risk-based remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Adobe Campaign Classic?

Adobe Campaign Classic is an enterprise-grade marketing automation platform designed to help organizations manage cross-channel marketing campaigns, customer databases, and personalized communication workflows. It serves as a central hub for orchestrating large-scale interactions, often processing significant volumes of sensitive customer information and operational data.

What does OS Command Injection mean for CVE-2026-76195?

This vulnerability is classified as CWE-78, which occurs when software does not properly filter special characters from user-supplied input before passing it to the underlying operating system. Because the input is treated as a command, an attacker can trick the system into executing unauthorized instructions. In the context of CVE-2026-76195, this allows a remote party to run arbitrary code on the server without needing to log in or interact with a legitimate user.

How does an attacker trigger this vulnerability?

An attacker triggers this flaw by sending a specially crafted network request to the Adobe Campaign Classic platform. The system processes this malicious input, which then forces the operating system to execute commands defined by the attacker. This vulnerability does not trigger through normal user actions, nor does it require any pre-existing authentication or session privileges to succeed.

Why should I care about my exposure to this CVE?

According to Halo Surface Signal, this software is often hosted internally to protect customer data. However, if your specific configuration has placed this instance on the internet to support external marketing workflows, it becomes reachable by remote attackers. You should care because this vulnerability provides a direct, unauthenticated path for an outsider to gain control over the platform and potentially access the sensitive data it manages.

What are the first steps to address this threat?

Your priority is to identify every instance of Adobe Campaign Classic within your environment. Once you have a complete inventory, verify the network placement of each server to determine which instances are internet-facing. After assessing the business criticality and reachability of these systems, coordinate with the infrastructure owners to prioritize remediation based on their risk profile and accessibility.