MEDIUMVulnerability
Global

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

·Source: The Hacker News

Updated:

Executive Summary

Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system. It has been described as a case of incorrect authorization that could result in

Analysis

Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system. It has been described as a case of incorrect authorization that could result in

Indicators of Compromise (1)

CVE (1)
CVE-2026-48449
Source Attribution

Originally published by The Hacker News on Aug 1, 2026.

Related Threats

HIGHVulnerability

NVD HIGH: CVE-2026-16635 — The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in a...

The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.1.0 This is due to the `maybe_update_user_role()` function passing an attacker-controlled Gravity Forms field value (`$lead[$feed->user_role_field_id]`) directly into `WP_User::set_role()` without any allowlist validation, capability comparison, or permission check to constrain whic

CVE-2026-16635
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-16144 — The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vu...

The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.20 via the _save_data function. This is due to insufficient validation of the 'thisPermalink' field value before it overwrites a trusted callable placeholder, allowing attacker-controlled strings to reach call_user_func() in _save_data(). This

CVE-2026-16144
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-15964 — The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication ...

The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password reset in all versions up to, and including, 2.0.0. This is due to the `ssoprocess_ajax()` function — registered on `wp_ajax_nopriv_ssoprocess_ajax` and therefore reachable without authentication — accepting an attacker-supplied `email` parameter with the `setnewpassword` operation an

CVE-2026-15964
NIST NVD