CVE-2026-71398Patch(adobe / campaign)

LOWCVSS 10.0 · CRITICAL

Signal is active with 7 mentions in latest observed window

Immediate actions

  • Patch adobe campaign systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • campaign

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 7 signals
  • Disclosure: 3 classified signals
  • 7 total mentions across 1 day

Affected systems

Vendors
Products
campaign

Deep dive

Activity timeline7 mentions / 1d
02457Mentions · 2026-08-12: 7Patch / Workaround · 2026-08-12: 4Technical Details · 2026-08-12: 708-12
Signal classification2 categories
Patch
457.1%
Disclosure
342.9%
Referenced assets4 URLs
Full discourse7 posts
  • Veriti Spottr@veritispottr
    Disclosure

    LOW Alert (CVE-2026-71398): Adobe — arbitrary code execution Read more: https://threat.veritispottr.com #CyberSecurity #ThreatIntel #InfoSec

    Post summary

    The alert announces a low‑severity Adobe vulnerability (CVE‑2026‑71398) that allows arbitrary code execution, but offers no additional technical details, PoC, or patch information.

    0001049
    223 followersView on X
  • TECHEPAGES@techepages
    Patch

    Adobe has released patches for 50+ vulnerabilities, including critical flaws in ColdFusion (CVE-2026-48362, CVE-2026-48273, CVE-2026-71384) and Campaign Classic (CVE-2026-71398, CVE-2026-27302, CVE-2026-48381). These issues could enable arbitrary code execution or DoS. Commerce updates also address privilege escalation (CVE-2026-71362). With Priority 1 ratings, immediate patching is strongly advised.

    Post summary

    Adobe has issued patches for over 50 critical vulnerabilities, including issues in ColdFusion and Campaign Classic that could lead to arbitrary code execution or DoS, and urges immediate remediation.

    0001060
    38 followersView on X
  • ThreatAft@ThreatAft
    Disclosure

    🚨 Adobe Campaign Classic — TWO CVSS 10.0 CVEs CVE-2026-27302 (Aug): Incorrect Auth → RCE CVE-2026-71398 (Jul): Incorrect Auth → RCE → http://threataft.com/articles/adobe-campaign-classic-two-cvss-10-cves #cybersecurity #infosec #Adobe #CampaignClassic #CVSS10 #ThreatIntel

    Post summary

    The post announces two CVSS 10 Adobe Campaign Classic vulnerabilities that allow remote code execution through incorrect authentication, but does not provide PoC, exploit, or patch information.

    0000042
    36 followersView on X
  • SecAlerts@SecAlertsCo
    Patch

    📨 Adobe Campaign Classic: CVE-2026-71398 is a CVSS 10 Incorrect Authorization flaw enabling remote arbitrary code execution. No privileges required. Patch via APSB26-123 now. #ciso #cto #cio #cybersecurity #Adobe #vulnerabilities #mssp https://secalerts.co/vulnerability/CVE-2026-71398?utm_campaign=x https://t.co/tmewoViw3T

    Post summary

    Adobe Campaign Classic CVE-2026-71398 is a CVSS‑10 Incorrect Authorization flaw allowing remote arbitrary code execution; patch APSB26‑123 is now available.

    00000227
    878 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨Critical - Adobe Campaign Classic Network RCE via Incorrect Authorization (CVE-2026-71398) Adobe Campaign Classic (ACC) contains an incorrect authorization flaw allowing remote attackers to reach code execution paths and run arbitrary code as the current user over the network with no user interaction. Scope changes; high impact to confidentiality, integrity, and availability. 👉Affected: Adobe Campaign Classic (ACC) (versions not specified)

    Post summary

    Adobe Campaign Classic exhibits a critical network RCE via incorrect authorization, allowing remote attackers to execute code as the current user without user interaction.

    0000065
    288 followersView on X
  • kawn@kawn2020
    Patch

    #securityupdate #adobeupdate #adobe #CampaignClassic Adobe から,Campaign Classic で更新をリリース. 適用優先度「1」,緊急度には「Critical」 3 件(うち CVSS 10.0 2 件)が含まれる. ・CVE-2026-27302(CVSS 10.0) ・CVE-2026-71398( 〃 ) ・CVE-2026-48381 https://x.com/kawn2020/status/2087451212627255511

    Post summary

    Adobe has released critical patches for Campaign Classic, addressing CVEs 2026-27302, 2026-71398, and 2026-48381.

    0000047
    90 followersView on X
  • CyberSignal | Cybersecurity News@XQOPTRX
    Patch

    🔥 Adobe patches multiple CVSS 10.0 vulnerabilities Adobe released fixes for 50+ vulnerabilities across its products. Among the most severe: 🔴 ColdFusion CVE-2026-48362 — CVSS 10.0 🔴 Campaign Classic CVE-2026-71398 — CVSS 10.0 🔴 Campaign Classic CVE-2026-27302 — CVSS 10.0 Potential impact includes arbitrary code execution and denial of service. 📅 August 11, 2026 🔎 Source: Adobe / SecurityWeek. #Adobe #ColdFusion #CVE #CyberSecurity #PatchNow

    Post summary

    Adobe issued patches for over 50 critical CVEs, including three CVSS 10.0 vulnerabilities in ColdFusion and Campaign Classic, which could lead to arbitrary code execution and denial of service.

    0000038
    42 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appadobecampaign---

Explore more