Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

A Critical Flaw in Adobe Campaign Classic Exposes Organizations to Serious Risks

A high-severity vulnerability has been discovered in Adobe Campaign Classic, a popular marketing automation platform used by many organizations. The flaw, assigned a CVSS (Common Vulnerability Scoring System) score of 10.0, allows attackers to execute arbitrary code on affected systems without requiring user interaction. This means that even if an organization’s security defenses are robust, an attacker could still breach their system and gain unauthorized access.

The vulnerability affects Adobe Campaign Classic versions prior to 12.4.1. It works by exploiting a weakness in the platform’s handling of XML data, allowing attackers to inject malicious code into the system. This can occur when an organization’s employees or partners interact with the platform, either intentionally or unintentionally, via email campaigns, web applications, or other interfaces.

Organizations that use Adobe Campaign Classic should be aware that the vulnerability is not only a risk for their own systems but also potentially for their customers and partners who may have been exposed through integrations. This is particularly concerning given the nature of the flaw, which can be exploited remotely without requiring any interaction from the victim.

The discovery of this vulnerability highlights the ongoing struggle to secure complex software systems used in modern business operations. These platforms often involve multiple interconnected components and interfaces, making it challenging for developers and security teams to identify and mitigate vulnerabilities. Furthermore, the use of third-party libraries and dependencies can introduce new risks that are difficult to manage.

While Adobe has released a patch for the vulnerability (version 12.4.1), many organizations may not have applied the update or may be unaware of the risk. This emphasizes the importance of proactive security measures, including regular software updates, penetration testing, and monitoring for suspicious activity.

To minimize the risks associated with this vulnerability, we recommend that Adobe Campaign Classic users prioritize updating their platform to the latest version as soon as possible. Additionally, organizations should review their incident response plans to ensure they are prepared in case an attacker attempts to exploit this flaw. Regular security audits and penetration testing can also help identify and address potential weaknesses before they are exploited by attackers.


Source: The Hacker News — 2026-08-01