Adobe Patches Maximum-Severity Campaign Classic Code Execution Flaw

Adobe has fixed CVE-2026-48449, a CVSS 10.0 vulnerability in Adobe Campaign Classic that could enable arbitrary code execution without user interaction. The ACC v7 7.4.3 build 9398 update also addresses CVE-2026-48448, a high-severity SQL injection flaw that could allow arbitrary file reads. Separate updates resolve eight critical Adobe Bridge vulnerabilities capable of enabling code execution or privilege escalation. Adobe has found no evidence of active exploitation, but users should install the latest security updates promptly.

Reference: thehackernews.com