CVE-2026-48331Patch(adobe / campaign)

LOWCVSS 10.0 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch adobe campaign systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed.

2.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • campaign
  • linux_kernel
  • windows

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 9 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 4 mentions (2026-08-04); latest day: 2
  • 9 total mentions across 4 days

Affected systems

Products
campaignlinux_kernelwindows

2 versions affected across 3 products

Deep dive

Activity timeline9 mentions / 4d
01234Mentions · 2026-08-03: 1Mentions · 2026-08-04: 4Mentions · 2026-08-05: 2Mentions · 2026-08-06: 2PoC Mentioned / Linked · 2026-08-04: 1Patch / Workaround · 2026-08-04: 2Patch / Workaround · 2026-08-05: 2Patch / Workaround · 2026-08-06: 2Technical Details · 2026-08-03: 1Technical Details · 2026-08-04: 2Technical Details · 2026-08-05: 1Technical Details · 2026-08-06: 208-0308-0408-0508-06
Signal classification4 categories
Patch
444.4%
Disclosure
333.3%
General
111.1%
PoC
111.1%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-08-031
Disclosure1
2026-08-044
Disclosure1General1Patch1PoC1
2026-08-052
Patch2
2026-08-062
Disclosure1Patch1
Full discourse9 posts
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    Adobe patched critical Adobe Campaign Classic flaws. CVE-2026-48331 scores CVSS 10.0 and enables arbitrary code execution. #Adobe #AdobeCampaignClassic #CVE202648331 #ArbitraryCodeExecution #Vulnerability #SSRF #SQLInjection #InfoSec #CyberSecurity https://securityonline.info/adobe-campaign-classic-cve-2026-48331/ https://t.co/VnvxKPm7KO

    Post summary

    Adobe has released a patch for the critical CVE-2026-48331 vulnerability in Adobe Campaign Classic, which scores CVSS 10.0 and enables arbitrary code execution.

    01070513
    12.9K followersView on X
  • Jamie Parfet@JamieParfet
    Disclosure

    Another day, another Adobe security bulletin 🔥 All unauthenticated, exploitable on a stock install: CVE-2026-48323 (RCE) CVE-2026-48331 (SSRF) CVE-2026-48330 (SQLi) CVE-2026-48326 (SQLi) CVE-2026-48333 (Auth bypass > RCE) https://helpx.adobe.com/security/products/campaign/apsb26-120.html

    Post summary

    Adobe disclosed several unauthenticated vulnerabilities in its Campaign product, including RCE, SSRF, and SQL injection, and provided a link to its security bulletin for patch details.

    00020212
    389 followersView on X
  • kawn@kawn2020
    Patch

    #securityupdate #adobeupdate #adobe #CampaignClassic Adobe から,Campaign Classic で更新をリリース. 適用優先度「1」,緊急度には「Critical」 7 件(うち CVSS 10.0 3 件)が含まれる. ・CVE-2026-48323 ・CVE-2026-48330 ・CVE-2026-48331 https://x.com/kawn2020/status/2084857607664419093

    Post summary

    Adobe released critical updates for Campaign Classic addressing CVE-2026-48323, CVE-2026-48330, and CVE-2026-48331, all rated CVSS 10.0.

    1000087
    92 followersView on X
  • ExploitGrid@exploitgrid
    PoC

    [CVE] CVE-2026-48331 [HIGH PRIORITY] #Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918) 🔗 https://exploitgrid.net/cve/CVE-2026-48331

    Post summary

    The post announces a high‑priority SSRF vulnerability (CVE‑2026‑48331) in Adobe Campaign Classic and provides a link to an ExploitGrid page, implying a PoC is available but no active exploitation or patching information.

    1000033
    29 followersView on X
  • ExploitGrid@exploitgrid
    General

    🛡️# ExploitGrid Daily #Threat Digest Top Vulnerabilities (CVEs) of the day CVE-2026-33591 CVE-2026-48323 CVE-2026-48330 CVE-2026-48331 CVE-2026-48326 ..🧵👇

    Post summary

    The post merely enumerates CVEs for the day with no additional context or actionable details, making it a general update rather than a focused threat analysis.

    1000039
    29 followersView on X
  • SecAlerts@SecAlertsCo
    Patch

    📡 Adobe Campaign Classic hit with a CVSS 10 SSRF — no auth, no user interaction needed, and it can escalate privileges. CVE-2026-48331 is as bad as it gets. Patch now. #cybersecurity #ciso #cto #vulnerabilities #mssp https://secalerts.co/vulnerability/CVE-2026-48331?utm_campaign=x https://t.co/ct4O1x3lno

    Post summary

    Adobe Campaign Classic is affected by a CVSS 10 SSRF that allows privilege escalation without authentication; users are urged to apply the available patch immediately.

    00000239
    876 followersView on X
  • kawn@kawn2020
    Patch

    #securityupdate #adobeupdate #adobe #CampaignClassic Adobe Campaign Classic ACC v7 7.4.3 build 9399 ・CVE-2026-48323(CVSS 10.0) ・CVE-2026-48330(〃 10.0) ・CVE-2026-48331(〃 10.0) ・CVE-2026-48317 ・CVE-2026-48326(〃 9.9) ・CVE-2026-48333(〃 9.8) ・CVE-2026-48399

    Post summary

    The post announces a security update (build 7.4.3 build 9399) for Adobe Campaign Classic, listing multiple high‑severity CVEs with CVSS scores, implying the update addresses these vulnerabilities.

    0000068
    92 followersView on X
  • MalwareObserver@MalwareObserver
    Disclosure

    🐛 VULNERABILITIES CVE Notify: 🚨 [CVE-2026-48331](https://helpx.adobe.com/security/products/campaign/apsb26-120.html) Adobe Campai... https://helpx.adobe.com/security/products/campaign/apsb26-120.html #CVE #ZeroDay #PatchManagement

    Post summary

    The post is a brief announcement of CVE-2026-48331 with a link to the Adobe security advisory, indicating the vulnerability is disclosed and patched, but no evidence of PoC, exploit, or active exploitation is presented.

    0000040
    17 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-48331 Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue d… https://www.cve.org/CVERecord?id=CVE-2026-48331

    Post summary

    The text reports CVE-2026‑48331 as a Server‑Side Request Forgery vulnerability in Adobe Campaign Classic that could enable privilege escalation, and directs readers to the official CVE record for details.

    000001.5K
    57.9K followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
Appadobecampaign---
Appadobecampaign7.4.3--
Appadobecampaign7.4.3--
Appadobecampaign7.4.3--
Appadobecampaign7.4.3--
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more