External risk intelligence

Adobe Campaign Classic Code Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-89275

Adobe Campaign Classic is an enterprise marketing automation platform frequently deployed as a web-accessible application to manage campaigns, APIs, and external-facing web content, making it a common target for internet-reachable deployment.

Code Injection

Adobe Campaign

7.4.3 and earlier7.4.4

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

Adobe Campaign Classic is impacted by a critical vulnerability that could allow an attacker to execute arbitrary code without any user interaction. This could potentially affect the integrity and availability of systems running this marketing automation software. The main concern at this stage is to confirm if our organization utilizes this specific Adobe product and assess any potential exposure.

  • Code injection allows unauthorized code execution.
  • Critical flaw could impact business operations.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker can reach the Adobe Campaign Classic product via the network without needing any special access or user interaction. This allows them to inject malicious code into the application, potentially leading to the execution of arbitrary code on the system.

  • Entry condition: Network access.
  • Trigger point: Vulnerable code injection.
  • Resulting risk: Arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in Adobe Campaign Classic could allow an attacker to execute arbitrary code on a system. This means an attacker could potentially run any command or program, leading to a compromise of the affected system and its data, without any action required from a user.

  • Arbitrary code execution on the system.
  • Exploited through network access.
  • Complete system compromise possible.

Operational Fix

Recommended remediation, mitigation, and detection steps

Understanding who owns Adobe Campaign Classic (ACC) and where it's deployed is crucial for immediate action. Responsibility likely falls to application owners, potentially supported by infrastructure or platform teams, with vendor management involved for coordination. The first step is to pinpoint all ACC instances, assess their reachability and business criticality, identify the direct accountable owner, and then develop a remediation plan prioritized by risk.

  • Application owners are primarily responsible.
  • Verify instance reachability and criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Adobe Campaign Classic?

Adobe Campaign Classic is an enterprise-grade marketing automation platform. Organizations use it to design, execute, and manage complex cross-channel marketing campaigns, handle customer data, and power external-facing web content and APIs.

How does CVE-2026-89275 work?

This CVE involves a vulnerability known as Code Injection (CWE-94). It occurs when software improperly handles data, allowing an attacker to inject and execute their own unauthorized commands. In this case, the flaw allows the attacker's code to run as if it were a legitimate part of the application.

Do I need to interact with the system to trigger this bug?

No. A key characteristic of this vulnerability is that it does not require any user interaction or authenticated access. The condition for exploitation is simply having network access to the target instance of Adobe Campaign Classic.

Is my Adobe Campaign Classic instance at risk?

Halo Surface Signal indicates that Adobe Campaign Classic is often deployed as a web-accessible application for external marketing content. If your instance is reachable over the internet, it is more likely to be accessible to an attacker. You should prioritize checking any public-facing deployments.

When should I take action for CVE-2026-89275?

You should act immediately by identifying all instances of Adobe Campaign Classic within your environment. Verify who owns these applications and assess their network connectivity. Once instances are located, work with your infrastructure and application teams to apply the vendor's guidance to secure the systems.

References