External risk intelligence

Adobe Campaign Classic Code Injection Leads to Arbitrary Code Execution

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-84412

Adobe Campaign Classic is an enterprise marketing automation platform designed to manage and deliver public-facing web content, email campaigns, and external-facing APIs. These components are frequently deployed in internet-facing configurations to facilitate customer interaction and data collection.

Code Injection

Adobe Campaign

7.4.3 and earlier7.4.4

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

Adobe Campaign Classic, a marketing automation platform, has a critical vulnerability that allows attackers to execute arbitrary code without user interaction. This could potentially lead to a compromise of systems. The main concern is confirming relevance and exposure.

  • Code injection flaw in marketing software.
  • External attackers can run their own code.
  • Verify if our marketing platform is affected.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending a crafted request to Adobe Campaign Classic. This could allow them to execute arbitrary code on the affected system, potentially leading to a complete compromise of the user's context.

  • Requires network access.
  • Vulnerable component or feature is involved.
  • Arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in Adobe Campaign Classic could allow an attacker to execute arbitrary code on the system with the privileges of the current user, without requiring any interaction from the user. This could potentially affect the confidentiality, integrity, and availability of the system and its data.

  • System code execution.
  • Network-based remote code injection.
  • Compromise of system data and services.

Operational Fix

Recommended remediation, mitigation, and detection steps

The primary teams responsible for addressing this critical vulnerability in Adobe Campaign Classic are likely the Application Owners and Platform/Infrastructure Teams. The initial practical step involves identifying all instances of Adobe Campaign Classic, confirming their network exposure and business criticality, and then locating the accountable owner for each instance to prioritize and plan remediation.

  • Application owners must address the issue.
  • Verify network exposure and business criticality.
  • Plan coordinated remediation or risk reduction.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Adobe Campaign Classic?

Adobe Campaign Classic is an enterprise marketing automation platform. Organizations use it to manage customer data, orchestrate multi-channel email campaigns, and deliver public-facing web content. Because it integrates with customer-facing APIs and web interfaces, it often functions as the engine behind personalized digital interactions and data collection.

What does the code injection vulnerability in CVE-2026-84412 mean?

This vulnerability is classified as Improper Control of Generation of Code (CWE-94). It means the software fails to properly sanitize inputs, allowing an attacker to inject their own instructions into the application. If successful, the system executes this unauthorized code as if it were a legitimate part of the program, potentially granting the attacker control over the application's processes.

How is this Adobe Campaign Classic vulnerability triggered?

An attacker triggers this flaw by sending a specifically crafted network request to the application. The vulnerability does not require the target user to perform any actions or click any links to initiate the compromise. It is important to note that internal, non-networked functions that do not process external inputs are generally not the direct path for this type of network-based injection.

Why should I care about CVE-2026-84412?

According to Halo Surface Signal, this software is frequently deployed in internet-facing configurations to support public-facing APIs and customer interactions. Because the vulnerability is remotely exploitable, any instance of Adobe Campaign Classic connected to the internet faces a higher risk of being targeted by external actors compared to services restricted to an internal network.

How do I respond if I use this software?

Your first step is to inventory all instances of Adobe Campaign Classic in your environment to determine which are currently active. Once identified, verify their network connectivity and business role. Coordinate with your platform and infrastructure teams to confirm if your specific version is vulnerable based on the official vendor security guidance and prioritize these systems for remediation.

References