CVE-2026-48323Disclosure(adobe / campaign)

LOWCVSS 10.0 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch adobe campaign systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

2.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1336

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • campaign
  • linux_kernel
  • windows

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 10 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 8 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 3 mentions (2026-08-04); latest day: 1
  • 10 total mentions across 5 days

Affected systems

Products
campaignlinux_kernelwindows

2 versions affected across 3 products

Deep dive

Activity timeline10 mentions / 5d
01223Mentions · 2026-08-03: 1Mentions · 2026-08-04: 3Mentions · 2026-08-05: 2Mentions · 2026-08-06: 3Mentions · 2026-08-14: 1PoC Mentioned / Linked · 2026-08-04: 1Patch / Workaround · 2026-08-04: 1Patch / Workaround · 2026-08-05: 1Patch / Workaround · 2026-08-06: 3Technical Details · 2026-08-03: 1Technical Details · 2026-08-04: 2Technical Details · 2026-08-05: 2Technical Details · 2026-08-06: 2Technical Details · 2026-08-14: 108-0308-0408-0508-0608-14
Signal classification4 categories
Disclosure
550.0%
Patch
330.0%
General
110.0%
PoC
110.0%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-08-031
Disclosure1
2026-08-043
General1Patch1PoC1
2026-08-052
Disclosure1Patch1
2026-08-063
Disclosure2Patch1
2026-08-141
Disclosure1
Full discourse10 posts
  • Sami Laiho@samilaiho
    Patch

    Critical vulnerabilities in Adobe products URL: https://nvd.nist.gov/vuln/detail/CVE-2026-48323 Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 10.0

    Post summary

    The statement reports a critical CVE in Adobe products and notes that an official fix is available, but provides no technical details, PoC, or evidence of exploitation.

    020201.0K
    30.6K followersView on X
  • Jamie Parfet@JamieParfet
    Disclosure

    Another day, another Adobe security bulletin 🔥 All unauthenticated, exploitable on a stock install: CVE-2026-48323 (RCE) CVE-2026-48331 (SSRF) CVE-2026-48330 (SQLi) CVE-2026-48326 (SQLi) CVE-2026-48333 (Auth bypass > RCE) https://helpx.adobe.com/security/products/campaign/apsb26-120.html

    Post summary

    Adobe announces a set of unauthenticated vulnerabilities affecting stock installations, specifying the CVEs and their types, and references a bulletin that includes patch information.

    00020212
    389 followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    🧨 Adobe Campaign Classic Hit With Multiple CVSS 10.0 Flaws Adobe Campaign Classic (ACC) accounts for three critical vulnerabilities this week, and none of them have patches. CVE-2026-48330 is a SQL injection flaw, CVE-2026-48323 involves…

    Post summary

    Adobe Campaign Classic has three newly disclosed CVSS 10.0 vulnerabilities, including a SQL injection flaw (CVE-2026-48330), and currently no patches are available for them.

    1000036
    88 followersView on X
  • kawn@kawn2020
    Patch

    #securityupdate #adobeupdate #adobe #CampaignClassic Adobe から,Campaign Classic で更新をリリース. 適用優先度「1」,緊急度には「Critical」 7 件(うち CVSS 10.0 3 件)が含まれる. ・CVE-2026-48323 ・CVE-2026-48330 ・CVE-2026-48331 https://x.com/kawn2020/status/2084857607664419093

    Post summary

    Adobe released critical updates for Campaign Classic addressing CVE‑2026‑48323, CVE‑2026‑48330, and CVE‑2026‑48331, with priority 1 and CVSS 10.0 for three vulnerabilities.

    1000087
    92 followersView on X
  • ExploitGrid@exploitgrid
    PoC

    [CVE] CVE-2026-48323 [HIGH PRIORITY] #Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements Us... 🔗 https://exploitgrid.net/cve/CVE-2026-48323

    Post summary

    The post announces CVE-2026-48323 as a high-priority flaw in Adobe Campaign Classic, noting an "Improper Neutralization of Special Elements" vulnerability and linking to an ExploitGrid page that likely hosts PoC code. There is no evidence of active exploitation, available patches, or false-positive status.

    1000033
    29 followersView on X
  • ExploitGrid@exploitgrid
    General

    🛡️# ExploitGrid Daily #Threat Digest Top Vulnerabilities (CVEs) of the day CVE-2026-33591 CVE-2026-48323 CVE-2026-48330 CVE-2026-48331 CVE-2026-48326 ..🧵👇

    Post summary

    A daily threat digest lists five newly disclosed CVEs without providing any further context, technical details, or actionable information.

    1000039
    29 followersView on X
  • SecAlerts@SecAlertsCo
    Disclosure

    📧 Adobe Campaign Classic hit with CVSS 10 template injection (CVE-2026-48323) — unauthenticated RCE, network-accessible, no interaction needed. If ACC is in your stack, patch now via APSB26-120. #cybersecurity #ciso #cto #vulnerabilities #msp https://secalerts.co/vulnerability/CVE-2026-48323?utm_campaign=x https://t.co/B9woxhEaDy

    Post summary

    Adobe Campaign Classic is affected by CVE‑2026‑48323, a CVSS 10 unauthenticated RCE via template injection; a patch (APSB26‑120) is available.

    00000135
    876 followersView on X
  • kawn@kawn2020
    Disclosure

    #securityupdate #adobeupdate #adobe #CampaignClassic Adobe Campaign Classic ACC v7 7.4.3 build 9399 ・CVE-2026-48323(CVSS 10.0) ・CVE-2026-48330(〃 10.0) ・CVE-2026-48331(〃 10.0) ・CVE-2026-48317 ・CVE-2026-48326(〃 9.9) ・CVE-2026-48333(〃 9.8) ・CVE-2026-48399

    Post summary

    The tweet announces new CVEs for Adobe Campaign Classic with CVSS scores, indicating a disclosure, but lacks exploit, patch, or mitigation details.

    0000068
    92 followersView on X
  • ThreatAft@ThreatAft
    Patch

    🚨 Adobe Campaign Classic 7-CVE Bundle — CVSS 10.0 CVE-2026-48323: Unauthenticated RCE via template engine injection. Update to 7.0.1 or 7.4.4 NOW. → http://threataft.com/articles/adobe-campaign-classic-7-cve-bundle #cybersecurity #infosec #Adobe #CampaignClassic #CVSS10 #ThreatIntel

    Post summary

    The post alerts users to a critical Adobe Campaign Classic CVE causing unauthenticated RCE, and urges updating to the latest patches (7.0.1 or 7.4.4) as the primary mitigation.

    0000083
    36 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-48323 Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code… https://www.cve.org/CVERecord?id=CVE-2026-48323

    Post summary

    The text announces a new CVE (CVE‑2026‑48323) for Adobe Campaign Classic, describing an improper neutralization vulnerability that could allow arbitrary code execution.

    00000955
    57.9K followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
Appadobecampaign---
Appadobecampaign7.4.3--
Appadobecampaign7.4.3--
Appadobecampaign7.4.3--
Appadobecampaign7.4.3--
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more