CVE-2026-76197Patch(adobe / campaign)

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch adobe campaign systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • campaign
  • linux_kernel
  • windows

Threat summary

  • Patch or workaround signal is available
  • 12 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 9 signals
  • Technical details provided in 10 signals
  • Disclosure: 4 classified signals
  • Peaked 5d ago at 5 mentions (2026-08-26); latest day: 1
  • 12 total mentions across 7 days

Affected systems

Products
campaignlinux_kernelwindows

5 versions affected across 3 products

Deep dive

Activity timeline12 mentions / 7d
01345Mentions · 2026-08-25: 1Mentions · 2026-08-26: 5Mentions · 2026-08-27: 2Mentions · 2026-08-28: 1Mentions · 2026-09-01: 1Mentions · 2026-09-03: 1Mentions · 2026-09-04: 1Patch / Workaround · 2026-08-25: 1Patch / Workaround · 2026-08-26: 4Patch / Workaround · 2026-08-27: 1Patch / Workaround · 2026-08-28: 1Patch / Workaround · 2026-09-01: 1Patch / Workaround · 2026-09-03: 1Technical Details · 2026-08-25: 1Technical Details · 2026-08-26: 4Technical Details · 2026-08-27: 2Technical Details · 2026-09-01: 1Technical Details · 2026-09-03: 1Technical Details · 2026-09-04: 108-2508-2608-2708-2809-0109-0309-04
Signal classification2 categories
Patch
866.7%
Disclosure
433.3%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-08-251
Disclosure1
2026-08-265
Disclosure1Patch4
2026-08-272
Disclosure1Patch1
2026-08-281
Patch1
2026-09-011
Patch1
2026-09-031
Patch1
2026-09-041
Disclosure1
Full discourse12 posts
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    Three critical Adobe Campaign Classic flaws (CVE-2026-76197, CVSS 10.0) allow arbitrary code execution. Update to build 9401 now. #Adobe #CyberSecurity #CVE202676197 #RCE #Infosec https://securityonline.info/adobe-campaign-classic-vulnerability/

    Post summary

    Adobe Campaign Classic faces three critical CVEs (notably CVE‑2026‑76197) enabling arbitrary code execution; users are advised to update to build 9401 to apply the fix.

    01071711
    13.0K followersView on X
  • stelin41@stelin41
    Disclosure

    @VXXDXX4XLL and I found our first CVE ! CVE-2026-76197: RCE in Adobe Campaign Classic (CVSS 10.0) https://helpx.adobe.com/security/products/campaign/apsb26-134.html https://t.co/0uj3cFaFCB

    Post summary

    The tweet announces CVE-2026-76197, an RCE in Adobe Campaign Classic with CVSS 10.0, and links to Adobe’s security advisory.

    21030251
    58 followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    🎯 Adobe Campaign Classic: Triple CVSS 10 Exposure Adobe Campaign Classic (ACC) dominates the critical list with at least three perfect-score vulnerabilities disclosed this week. CVE-2026-76195 and CVE-2026-76197 are both OS…

    Post summary

    Three newly disclosed CVEs (CVE‑2026‑76195, CVE‑2026‑76197, and another) in Adobe Campaign Classic are reported with perfect CVSS 10 scores, highlighting critical vulnerabilities discovered this week.

    1000023
    85 followersView on X
  • SecAlerts@SecAlertsCo
    Patch

    📧 Adobe Campaign Classic hit with CVSS 10 OS command injection — CVE-2026-76197 allows unauthenticated RCE, no privileges needed. If ACC is in your stack, patch now via APSB26-134. #cybersecurity #ciso #cto #vulnerabilities #msp https://secalerts.co/vulnerability/CVE-2026-76197?utm_campaign=x https://t.co/9ZCdKAwnSj

    Post summary

    The tweet announces a critical OS command injection vulnerability in Adobe Campaign Classic, providing exploitation details and urging immediate patching via APSB26-134.

    00010111
    885 followersView on X
  • キタきつね@foxbook
    Disclosure

    Adobe Campaign Classic CVE-2026-76197 (CVSS 10.0): 重大な脆弱性により任意のコード実行が可能 Adobe Campaign Classic CVE-2026-76197 (CVSS 10.0): Critical Flaws Allow Arbitrary Code Execution #DailyCyberSecurity (Aug 26) https://securityonline.info/adobe-campaign-classic-vulnerability/

    Post summary

    Adobe Campaign Classic vulnerability (CVE-2026-76197) with CVSS 10.0 allowing arbitrary code execution has been publicly disclosed.

    00010281
    4.9K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Critical RCE flaws in #Adobe #CampaignClassic. #CVE-2026-76193 #CVE-2026-76195 #CVE-2026-76197 CVSS: 10.0. SSRF and OS command injection can lead to arbitrary code execution! Update ACC v7 to build 9401. #Patch #Patch #Patch

    Post summary

    Adobe Campaign Classic faces critical RCE flaws (CVSS 10) via SSRF and OS command injection; users are urged to update to build 9401.

    01000284
    7.2K followersView on X
  • iototsecnews@iototsecnews
    Patch

    Adobe Campaign Classic の Critical 脆弱性 CVE-2026-76197/76195/76193 が FIX:RCE の恐れ https://iototsecnews.jp/2026/08/27/adobe-campaign-classic-vulnerabilities-enable-arbitrary-code-execution/ Adobe Campaign Classic に深刻な脆弱性が発生し、更新プログラムが適用されました。Adobe Campaign Classic 7.4.4 build 9400 以下には、外部からの入力に対する確認処理が不足しています。これにより認証なしでの遠隔操作/重要データの漏洩/システム制御権の奪取といった甚大な影響が生じます。影響を受ける CVE-2026-76197/CVE-2026-76195/CVE-2026-76193 に対しては、修正版 build 9401 への速やかな改修や通信制限などの防御措置が求められます。 #Adobe #CampaignClassic #CVE202676193 #CVE202676195 #CVE202676197 #Vulnerability

    Post summary

    Adobe released a patch (build 9401) and recommends communication restrictions for critical RCE vulnerabilities (CVE‑2026‑76197/76195/76193) affecting Campaign Classic build 9400 or earlier.

    00000102
    510 followersView on X
  • NCIIPC India@NCIIPC
    Patch

    #Adobe has released security update for Adobe Campaign Classic which addresses multiple #Critical vulnerabilities. #CVE-2026-76197 #CVE-2026-76195 #CVE-2026-76193 https://helpx.adobe.com/ua/security/products/campaign/apsb26-134.html

    Post summary

    Adobe issued a patch for three critical CVEs affecting Campaign Classic; the post announces the update without details of exploitation or technical specifics.

    00000334
    8.5K followersView on X
  • ThreatAft@ThreatAft
    Patch

    🚨 CVE-2026-76195/76197 (CVSS 10.0): Critical Adobe Campaign Classic RCE flaws enable unauthenticated code execution. ✅ Patch to 7.4.4 build 9401 NOW 🔒 Restrict access if delayed 🔗 https://threataft.com/articles/adobe-campaign-classic-rce-command-injection-cve-2026-76195-cve-2026-76197?utm_source=twitter&utm_medium=social&utm_campaign=share #Adobe #CampaignClassic #CVE202676195 #CVE202676197 #infosec #RCE https://t.co/mtUBc66tZS

    Post summary

    Critical Adobe Campaign Classic RCE vulnerabilities (CVE-2026-76195/76197) announced with a patch available for version 7.4.4 build 9401.

    0000060
    37 followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos Adobe ❗ CVE-2026-76197 ❗ CVE-2026-76195 ❗ CVE-2026-76193 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-adobe-7/ https://t.co/yOgb31sYbM

    Post summary

    The post announces three Adobe product CVEs and provides links to a CERT page for further information, but does not include any PoC, exploit, patch, or technical details.

    00000271
    6.7K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - Adobe Campaign Classic OS Command Injection RCE (CVE-2026-76197) Adobe Campaign Classic (ACC) improperly neutralizes special characters when building OS command strings, enabling remote OS command injection. A network attacker can send crafted input to execute arbitrary commands as the ACC service user without user interaction. 👉Affected: Adobe Campaign Classic (ACC) 7: 7.4.4 build 9400 and earlier | Update to ACC v7 7.4.4 build 9401 or later.

    Post summary

    Adobe Campaign Classic is affected by CVE‑2026‑76197, an OS command injection RCE that allows remote attackers to run arbitrary commands; a patch is available in build 9401 or later.

    0000084
    294 followersView on X
  • kawn@kawn2020
    Patch

    #securityupdate #adobeupdate #adobe #CampaignClassic Adobe から,Campaign Classic で更新をリリース. 適用優先度「1」,緊急度には「Critical」 3 件(すべて CVSS 10.0). ・CVE-2026-76193 ・CVE-2026-76195 ・CVE-2026-76197 https://x.com/kawn2020/status/2092448139030769742

    Post summary

    Adobe released a critical‑level update for Campaign Classic fixing CVE‑2026‑76193, ‑76195, and ‑76197, each rated CVSS 10.0, indicating a patch has been issued.

    0000063
    88 followersView on X
CPE platform detail12 entries

12 of 12 entries

PartVendorProductVersionTarget SWTarget HW
Appadobecampaign---
Appadobecampaign7.4.1--
Appadobecampaign7.4.2--
Appadobecampaign7.4.2--
Appadobecampaign7.4.3--
Appadobecampaign7.4.3--
Appadobecampaign7.4.3--
Appadobecampaign7.4.3--
Appadobecampaign7.4.3--
Appadobecampaign7.4.4--
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more