Visualização de leitura

Critical Adobe Campaign Classic Vulnerabilities Enables Arbitrary Code Execution

Adobe has issued a critical security update for Adobe Campaign Classic, addressing multiple flaws that could enable arbitrary code execution on vulnerable systems. The update, tracked as APSB26-120 and published on August 3, 2026, carries Adobe’s highest priority rating of 1.

The security issues affect Adobe Campaign Classic ACC v7.4.3 build 9398 and earlier on Windows and Linux. Organizations should upgrade to ACC v7.4.3 build 9399 as soon as possible.

Organizations use Adobe Campaign Classic to manage cross-channel marketing campaigns, customer profiles, email workflows, and campaign automation. A successful compromise could give attackers access to sensitive marketing data, internal infrastructure, customer information, and connected systems.

Adobe Campaign Classic Vulnerabilities

The most serious flaws are three unauthenticated remote vulnerabilities (CVSS 10.0) that can lead to arbitrary code execution: CVE-2026-48331 – Server-side request forgery (SSRF), CVE-2026-48323 – Template engine injection, CVE-2026-48330 – SQL injection.

Their CVSS vectors show that an attacker could exploit them remotely over a network without requiring authentication or user interaction. This makes internet-facing and externally accessible Campaign Classic deployments especially important to patch quickly.

CVE-2026-48331 is an SSRF vulnerability. SSRF bugs can allow an attacker to make the vulnerable server send requests to internal services, cloud metadata endpoints, or systems that are normally inaccessible from the internet. In certain environments, this can help attackers access credentials, map internal networks, or reach administrative services.

Adobe also fixed another SQL injection vulnerability, CVE-2026-48326, rated 9.9 out of 10. Unlike the maximum-severity SQL injection flaw, exploiting this issue requires low-level privileges. However, a malicious authenticated user or an attacker with stolen credentials could potentially use it to execute code and compromise the underlying server.

CVE-2026-48333, rated 9.8, is an incorrect authorization vulnerability that could allow privilege escalation. Attackers may exploit such flaws to access functions or data beyond their intended permissions.

The remaining issues include CVE-2026-48317, an eval injection vulnerability with a CVSS score of 9.6, and CVE-2026-48399, a security feature bypass flaw with a CVSS score of 7.5.

Eval injection can occur when an application processes dynamic code unsafely, potentially allowing attackers to run attacker-controlled commands.

Adobe said it is not aware of any exploits targeting these vulnerabilities in the wild. However, the critical severity, remote attack paths, and lack of authentication requirements make rapid remediation essential.

The Adobe bulletin applies to on-premise and hybrid Adobe Campaign Classic deployments, while Adobe-hosted instances have already been remediated and require no customer action.

Security teams should identify exposed Campaign Classic servers, apply build 9399, review administrative accounts, restrict unnecessary network access, and monitor logs for unusual requests, unexpected database activity, or suspicious changes to privileges.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

The post Critical Adobe Campaign Classic Vulnerabilities Enables Arbitrary Code Execution appeared first on Cyber Security News.

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction.

Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute arbitrary code in the context of the current user without requiring any user interaction.

“Adobe has released a security update for Adobe Campaign Classic. This update addresses critical vulnerabilities  that could result in arbitrary code execution and arbitrary file system read.” reads the advisory. “Adobe is not aware of any exploits in the wild for any of the issues addressed in these updates.”

Organizations using Adobe Campaign Classic should apply the available security updates as soon as possible to reduce the risk of exploitation.

Adobe also fixed CVE-2026-48448 (CVSS score 8.6), a high-severity SQL injection flaw that could allow arbitrary file reads.

Both vulnerabilities are patched in Adobe Campaign Classic v7.4.3 build 9398 for Windows and Linux.

Adobe also released updates for Adobe Bridge, fixing eight critical vulnerabilities that could allow attackers to execute arbitrary code or escalate privileges. The flaws include incorrect authorization, untrusted search path, path traversal, and out-of-bounds write vulnerabilities, with CVSS scores ranging from 7.8 to 8.6.

Below is the list of the flaws:

Vulnerability CategoryVulnerability ImpactSeverityCVSS base scoreCVSS vectorCVE Number
Untrusted Search Path (CWE-426)Arbitrary code executionCritical8.6CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HCVE-2026-48395
Incorrect Authorization (CWE-863)Arbitrary code executionCritical8.6CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HCVE-2026-48396
Incorrect Authorization (CWE-863)Privilege escalationCritical8.2CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:NCVE-2026-48390
Untrusted Search Path (CWE-426)Arbitrary code executionCritical8.2CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:HCVE-2026-48391
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) (CWE-22)Arbitrary code executionCritical7.8CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HCVE-2026-48374
Out-of-bounds Write (CWE-787)Arbitrary code executionCritical7.8CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HCVE-2026-48392
Out-of-bounds Write (CWE-787)Arbitrary code executionCritical7.8CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HCVE-2026-48393
Out-of-bounds Write (CWE-787)Arbitrary code executionCritical7.8CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HCVE-2026-48394

Researcher Kieran (kaiksi) disclosed the flaws CVE-2026-48390, CVE-2026-48391, CVE-2026-48395, CVE-2026-48396, and CVE-2026-48374, while the researcher yjdfy reported the vulnerabilities CVE-2026-48392, CVE-2026-48393, and CVE-2026-48394.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Campaign Classic)

WhatsApp Web chats exposed by Adobe’s Acrobat extension flaw

HermeticReader is the name given to a recently disclosed vulnerability in the Adobe Acrobat PDF extension for Chrome, tracked as CVE-2026-48294.

Researchers discovered the issue in early June 2026 and reported it to Adobe, which patched the flaw over a single weekend. They found that a single visit to a malicious website could turn Adobe’s Acrobat Chrome browser extension into a silent spy on your WhatsApp Web conversations.

The exploit worked across platforms, meaning any Windows, macOS, Linux, or ChromeOS device was potentially vulnerable if it met three conditions:

  • It used Google Chrome or another Chromium-based browser compatible with Chrome extensions, which account for around 78% of the browser market.
  • It had the vulnerable Adobe Acrobat PDF extension installed and enabled. The extension has reportedly been installed on around 329 million browsers.
  • It had at least one WhatsApp Web tab open or the user was logged into WhatsApp Web when they visited a malicious website.

HermeticReader did not exploit a bug in WhatsApp itself. It also didn’t require malware on the device or stolen usernames and passwords.

There are plenty of potential victims. And if these conditions were met, a visit to a specially crafted website could give an attacker access to your WhatsApp chat list, contact names, profile name, messages, and the contents of whichever conversation was open at the time.

How the attack worked

HermeticReader effectively broke the browser’s same‑origin protections via the Adobe extension’s privileged context. Same‑origin protections are basically the browser’s rule that says websites aren’t allowed to snoop on each other’s private data unless they’re clearly part of the same site (same scheme, host, and port).

The problem was that the Adobe extension operated with much higher privileges than a normal website, effectively bypassing those restrictions. It was like giving a visitor a master key that opened every apartment in the building instead of just the one they were invited into.

How to stay safe

Adobe fixed the vulnerability in version 26.5.2.3 of the Acrobat PDF extension. The update is installed automatically, but it’s worth checking that you’re running the latest version. Versions 26.5.2.2 and earlier are affected by HermeticReader.

The affected extension ID is efaidnbmnnnibpcajpcglclefindmkaj.

You should also:

  • Review the devices linked to your WhatsApp account and sign out of any you don’t recognize or no longer use.
  • Remove browser extensions you don’t use, recognize, or trust.
  • Keep software and extensions updated so security fixes are installed as soon as they’re available.

HermeticReader is a reminder that browser extensions sit in a powerful position between users and the web, and that convenience integrations can become privacy liabilities if messaging and storage flows are not tightly constrained. Even well‑known brands can ship features that briefly put your privacy at risk.


Scammers don’t need to hack you. They just need you to click once. 

Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.

Security updates available for Adobe, Chrome, Firefox, VMWare, and Zoom

Security updates are not just for enterprises with a dedicated security team and a change-management calendar. For consumers and small businesses, they are one of the simplest ways to shut down known attack paths before criminals get a chance to use them.

That matters because attackers love these flaws. because browser bugs, code execution issues, authentication bypasses, and privilege-escalation problems can be turned into a foothold, a data theft opportunity, or a full system compromise if left unpatched.

If you only do one thing after reading a security advisory, make it this: update the affected software promptly, restart when required, and verify the version afterward.

Adobe

Adobe released a large batch of security updates covering ColdFusion, Commerce/Magento Open Source, and Experience Manager. The ColdFusion bulletin alone includes multiple critical flaws that could lead to arbitrary code execution.

The updates and instructions can be found on the pages we linked to.

Chrome

Google patched 15 security flaws in Chrome, including two critical use-after-free bugs in Ozone. The fixes are in Chrome 150.0.7871.124/.125, depending on platform.

You can find an explanation of the version numbering system and step-by-step instructions in our guide to how to update Chrome on every operating system.

Firefox

Mozilla fixed two critical Firefox flaws in Firefox 152.0.6, and it says public exploit code exists for both issues. One affects JavaScript/WebAssembly and the other involves DOM navigation and site isolation, which makes this more than routine housekeeping.

Users should update Firefox to version 152.0.6 as soon as possible. For most users this can simply be done by restarting the browser. If you see the “What’s new” tab, the update is complete.

VMWare

Broadcom released a fix for a critical authentication bypass in VMware Avi Load Balancer, tracked as CVE-2026-47865. The issue could allow a network-accessible attacker to reach the Avi Control Plane, which makes it especially important in environments that expose management services or rely on load balancers at the edge.

Updates and the instructions to apply them can be found in the Security Advisory.

Zoom

Zoom Security Bulletin ZSB-26014 covers a critical issue in Zoom Workplace for Windows, described as improper input validation. The public record identifies the issue as CVE-2026-53412.

For users, the action item is to update Zoom Workplace for Windows to the vendor-fixed release as soon as it is available in your environment. For small businesses, that means updating not just the app on employee laptops, but also any centralized deployment package so the old build doesn’t come right back on the next install cycle.


CNET Editors' Choice Award 2026

“One of the best cybersecurity suites on the planet.” 

According to CNET. Read their review


Adobe fixed multiple maximum-severity flaws in ColdFusion and Campaign Classic

Adobe fixed multiple critical flaws, including max severity bugs in ColdFusion and Campaign Classic that could lead to remote code execution


Adobe has released security updates for ColdFusion and Campaign Classic, fixing multiple critical vulnerabilities, including seven maximum-severity issues (CVSS score of 10.0). If exploited, the flaws could allow attackers to execute arbitrary code, escalate privileges, read sensitive files, or bypass security protections.

Adobe strongly recommends that customers apply the updates as soon as possible to reduce the risk of compromise.

The vulnerabilities include:

  • CVE-2026-48276, CVE-2026-48283 (CVSS score of 10.0) – Allow attackers to upload malicious files and execute arbitrary code.
  • CVE-2026-48277, CVE-2026-48281, CVE-2026-48316 (CVSS score of 10.0) – Input validation flaws that could let attackers execute arbitrary code.
  • CVE-2026-48282 (CVSS score of 10.0) – A path traversal flaw that could result in arbitrary code execution.
  • CVE-2026-48313 (CVSS score of 9.3) – A path traversal flaw that could let attackers read sensitive files.
  • CVE-2026-48315 (CVSS score of 9.3) – An input validation flaw that could allow privilege escalation.

Adobe addressed these vulnerabilities in ColdFusion 2023 Update 21 and ColdFusion 2025 Update 10. Security researchers Anirudh Anand, Matan Sandori, and 2Bsecure reported several of the vulnerabilities.

The firm thanked researchers for reporting the issues and helping improve security: Anirudh Anand reported CVE-2026-48283 and CVE-2026-48313, while Matan Sandori and 2Bsecure reported CVE-2026-48307.

The company also fixed a critical flaw, tracked as CVE-2026-48286 (CVSS score of 10.0) in Adobe Campaign Classic that could let attackers execute arbitrary code due to an authorization weakness.

The issue affects on-premises deployments running version 7.4.3 build 9396 and earlier and is fixed in build 9397. Adobe-hosted instances are not affected.

The software giant said it has seen no evidence of active exploitation.

“Adobe is not aware of any exploits in the wild for any of the issues addressed in these updates.” reads the advisory.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Coldfusion)

Microsoft Patch Tuesday, March 2026 Edition

Microsoft Corp. today pushed security updates to fix at least 77 vulnerabilities in its Windows operating systems and other software. There are no pressing “zero-day” flaws this month (compared to February’s five zero-day treat), but as usual some patches may deserve more rapid attention from organizations using Windows. Here are a few highlights from this month’s Patch Tuesday.

Image: Shutterstock, @nwz.

Two of the bugs Microsoft patched today were publicly disclosed previously. CVE-2026-21262 is a weakness that allows an attacker to elevate their privileges on SQL Server 2016 and later editions.

“This isn’t just any elevation of privilege vulnerability, either; the advisory notes that an authorized attacker can elevate privileges to sysadmin over a network,” Rapid7’s Adam Barnett said. “The CVSS v3 base score of 8.8 is just below the threshold for critical severity, since low-level privileges are required. It would be a courageous defender who shrugged and deferred the patches for this one.”

The other publicly disclosed flaw is CVE-2026-26127, a vulnerability in applications running on .NET. Barnett said the immediate impact of exploitation is likely limited to denial of service by triggering a crash, with the potential for other types of attacks during a service reboot.

It would hardly be a proper Patch Tuesday without at least one critical Microsoft Office exploit, and this month doesn’t disappoint. CVE-2026-26113 and CVE-2026-26110 are both remote code execution flaws that can be triggered just by viewing a booby-trapped message in the Preview Pane.

Satnam Narang at Tenable notes that just over half (55%) of all Patch Tuesday CVEs this month are privilege escalation bugs, and of those, a half dozen were rated “exploitation more likely” — across Windows Graphics Component, Windows Accessibility Infrastructure, Windows Kernel, Windows SMB Server and Winlogon. These include:

CVE-2026-24291: Incorrect permission assignments within the Windows Accessibility Infrastructure to reach SYSTEM (CVSS 7.8)
CVE-2026-24294: Improper authentication in the core SMB component (CVSS 7.8)
CVE-2026-24289: High-severity memory corruption and race condition flaw (CVSS 7.8)
CVE-2026-25187: Winlogon process weakness discovered by Google Project Zero (CVSS 7.8).

Ben McCarthy, lead cyber security engineer at Immersive, called attention to CVE-2026-21536, a critical remote code execution bug in a component called the Microsoft Devices Pricing Program. Microsoft has already resolved the issue on their end, and fixing it requires no action on the part of Windows users. But McCarthy says it’s notable as one of the first vulnerabilities identified by an AI agent and officially recognized with a CVE attributed to the Windows operating system. It was discovered by XBOW, a fully autonomous AI penetration testing agent.

XBOW has consistently ranked at or near the top of the Hacker One bug bounty leaderboard for the past year. McCarthy said CVE-2026-21536 demonstrates how AI agents can identify critical 9.8-rated vulnerabilities without access to source code.

“Although Microsoft has already patched and mitigated the vulnerability, it highlights a shift toward AI-driven discovery of complex vulnerabilities at increasing speed,” McCarthy said. “This development suggests AI-assisted vulnerability research will play a growing role in the security landscape.”

Microsoft earlier provided patches to address nine browser vulnerabilities, which are not included in the Patch Tuesday count above. In addition, Microsoft issued a crucial out-of-band (emergency) update on March 2 for Windows Server 2022 to address a certificate renewal issue with passwordless authentication technology Windows Hello for Business.

Separately, Adobe shipped updates to fix 80 vulnerabilities — some of them critical in severity — in a variety of products, including Acrobat and Adobe Commerce. Mozilla Firefox v. 148.0.2 resolves three high severity CVEs.

For a complete breakdown of all the patches Microsoft released today, check out the SANS Internet Storm Center’s Patch Tuesday post. Windows enterprise admins who wish to stay abreast of any news about problematic updates, AskWoody.com is always worth a visit. Please feel free to drop a comment below if you experience any issues apply this month’s patches.

FYSA – Adobe Cold Fusion Path Traversal Vulnerability

Summary

Adobe has released a security bulletin (APSB24-107) addressing an arbitrary file system read vulnerability in ColdFusion, a web application server. The vulnerability, identified as CVE-2024-53961, can be exploited to read arbitrary files on the system, potentially leading to unauthorized access and data exposure.

Threat Topography

  • Threat Type: Arbitrary File System Read
  • Industries Impacted: Technology, Software, and Web Development
  • Geolocation: Global
  • Environment Impact: Web servers running ColdFusion 2021 and 2023 are vulnerable

Overview

X-Force Incident Command is monitoring the disclosure of an arbitrary file system read vulnerability in ColdFusion, a web application server, that can be exploited by an attacker to read arbitrary files on the system. The vulnerability, identified as CVE-2024-53961, affects ColdFusion 2021 and 2023. Adobe has provided a patch to address the issue. Adobe has also disclosed that proof of concept exploit code has been published for this vulnerability, making it crucial for organizations to prioritize patching to mitigate the risk of unauthorized access and data exposure. Exploitation has not yet been detected in the wild.

X-Force Incident Command recommends that organizations using ColdFusion review the Adobe bulleting and prioritize patching if running vulnerable versions of the software. Additionally, they should also consider implementing access controls and authentication mechanisms to limit unauthorized access to sensitive data.

X-Force Incident Command will continue to monitor this situation and provide updates as available.

Key Findings

  • The vulnerability, CVE-2024-53961, affects ColdFusion 2021 and 2023.
  • The vulnerability can be exploited to read arbitrary files on the system.
  • Adobe has provided a patch to address the issue.
  • The vulnerability can potentially lead to unauthorized access and data exposure.

Mitigations/Recommendations

  • Apply the patch provided by Adobe as soon as possible.
  • Implement access controls and authentication mechanisms to limit unauthorized access to sensitive data.
  • Monitor systems for any signs of exploitation.
  • Prioritize patching and vulnerability remediation to mitigate the risk of exploitation.
  • Consider implementing file system monitoring and logging to detect and prevent unauthorized file access.

References

The post FYSA – Adobe Cold Fusion Path Traversal Vulnerability appeared first on Security Intelligence.

❌