VDB
CVE-2026-27302
CVE-2026-27302
PUBLISHED
CVSS 10 CRITICAL
Adobe has released a security update for Adobe Campaign Classic. This update addresses critical vulnerabilities that could result in arbitrary code execution. Adobe is not aware of any exploits in the wild for any of the issues addressed in this update. Vulnerability: Incorrect Authorization (CWE-863) Impact: Arbitrary code execution Severity: Critical CVSS: 10.0 CWE: CWE-863
EPSS 0.71% · 50.9th percentile
Risk Scores
CVSS 3.1
10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS Score
0.71%
50.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Adobe | Adobe Campaign Classic | 7.4.3, 7.4.3, 7.4.3 |
Timeline
- Apr 14, 2026 CVE Published
- Aug 24, 2026 EPSS Score
- Aug 26, 2026 EPSS Score
- Aug 28, 2026 EPSS Score
- Aug 30, 2026 EPSS Score
- Sep 3, 2026 EPSS Score
- Sep 5, 2026 EPSS Score
References
- https://helpx.adobe.com/security/products/campaign/apsb26-123.html advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27302 advisory
- https://helpx.adobe.com/security/products/connect/apsb26-37.html advisory
- https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fhelpx.adobe.com%2Fadobe-connect%2Frelease-note%2Fadobe-connect-12-11-release-notes.html&data=05%7C02%7Crkang%40adobe.com%7Ce406f039e3b64e22714f08de8ef6f5a7%7Cfa7b1b5a7b34438794aed2c178decee1%7C0%7C0%7C639105388506870728%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=yFyO3AVXd%2BzEfNBlghfnZP8LYVfTKPls5BJYZwTlCh8%3D&reserved=0 patch