CVE-2026-48326Disclosure(adobe / campaign)

LOWCVSS 9.9 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch adobe campaign systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

2.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • campaign
  • linux_kernel
  • windows

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 3 mentions (2026-08-04); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Products
campaignlinux_kernelwindows

2 versions affected across 3 products

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-08-03: 1Mentions · 2026-08-04: 3Mentions · 2026-08-05: 1Mentions · 2026-08-06: 1PoC Mentioned / Linked · 2026-08-04: 1Patch / Workaround · 2026-08-04: 1Technical Details · 2026-08-03: 1Technical Details · 2026-08-04: 2Technical Details · 2026-08-05: 1Technical Details · 2026-08-06: 108-0308-0408-0508-06
Signal classification4 categories
Disclosure
233.3%
General
233.3%
Patch
116.7%
PoC
116.7%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-08-031
Disclosure1
2026-08-043
General1Patch1PoC1
2026-08-051
Disclosure1
2026-08-061
General1
Full discourse6 posts
  • Jamie Parfet@JamieParfet
    General

    Another day, another Adobe security bulletin 🔥 All unauthenticated, exploitable on a stock install: CVE-2026-48323 (RCE) CVE-2026-48331 (SSRF) CVE-2026-48330 (SQLi) CVE-2026-48326 (SQLi) CVE-2026-48333 (Auth bypass > RCE) https://helpx.adobe.com/security/products/campaign/apsb26-120.html

    Post summary

    Adobe announced a security bulletin listing five unauthenticated vulnerabilities (RCE, SSRF, SQLi, Auth bypass) that are exploitable on stock installations; the post does not provide a PoC, exploit code, or patch details.

    00020212
    389 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-48326 Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in… https://www.cve.org/CVERecord?id=CVE-2026-48326

    Post summary

    The text announces a newly disclosed SQL injection flaw in Adobe Campaign Classic (ACC), identified as CVE-2026-48326, with no additional exploitation or patch details.

    10010939
    57.9K followersView on X
  • ExploitGrid@exploitgrid
    PoC

    [CVE] CVE-2026-48326 [HIGH PRIORITY] #Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements us... 🔗 https://exploitgrid.net/cve/CVE-2026-48326

    Post summary

    The post references an exploit grid page for CVE‑2026‑48326, implying a PoC exists, but lacks detailed exploitation or patch information.

    1000027
    29 followersView on X
  • ExploitGrid@exploitgrid
    General

    🛡️# ExploitGrid Daily #Threat Digest Top Vulnerabilities (CVEs) of the day CVE-2026-33591 CVE-2026-48323 CVE-2026-48330 CVE-2026-48331 CVE-2026-48326 ..🧵👇

    Post summary

    The post merely lists five CVEs without offering any details on exploitation, patches, or technical specifics.

    1000039
    29 followersView on X
  • kawn@kawn2020
    Disclosure

    #securityupdate #adobeupdate #adobe #CampaignClassic Adobe Campaign Classic ACC v7 7.4.3 build 9399 ・CVE-2026-48323(CVSS 10.0) ・CVE-2026-48330(〃 10.0) ・CVE-2026-48331(〃 10.0) ・CVE-2026-48317 ・CVE-2026-48326(〃 9.9) ・CVE-2026-48333(〃 9.8) ・CVE-2026-48399

    Post summary

    The tweet announces several critical CVEs affecting Adobe Campaign Classic v7.4.3, listing their identifiers and CVSS scores.

    0000068
    92 followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    CVE-2026-48326 - Critical SQLi in Adobe Campaign Classic. Low-privilege attacker can achieve RCE. CVSS 9.9, unpatched. Mitigate immediately. https://www.valtersit.com/cve/cve-2026-48326 #CVE #Adobe #infosec #CVE #Linux #infosec #infosec #devsecops #devops #developer #sysadmin #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #ethicalhacking #cybersecurityawareness #cybersecurity #cybersecuritynews #cybersecuritytips #python #hacker #linux #kali #ubuntu

    Post summary

    The tweet signals a critical SQL injection in Adobe Campaign Classic that could lead to remote code execution and urges immediate mitigation, but does not provide proof-of-concept or exploitation details.

    0000061
    1.0K followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
Appadobecampaign---
Appadobecampaign7.4.3--
Appadobecampaign7.4.3--
Appadobecampaign7.4.3--
Appadobecampaign7.4.3--
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more