EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Technical advisory

NCSC-2026-0393 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Campaign Classic

Official source
EudorIA operational summary

What it means

Priority 85/100

Adobe ha rimosso 18 vulnerabilità critiche in Adobe Campaign Classic, tra cui code- e OS-command injection, SQL injection, insufficient authorization e SSRF. Otto vulnerabilità hanno un CVSS 10,0 e possono essere sfruttate remotamente senza autenticazione o interazione utente. L'attacco potrebbe portare a esecuzione di codice, escalation di privilegi, bypass di sicurezza e DoS. Nessun sfruttamento attivo confermato.

Why it matters

Le vulnerabilità critiche in Adobe Campaign Classic rappresentano un rischio elevato per le PMI italiane, che potrebbero subire accessi non autorizzati, furto di dati e interruzione dei servizi. La mancanza di patch potrebbe compromettere la continuità operativa e la conformità normativa.

Potential operational benefits

  • Riduzione della superficie esposta a attacchi remoti
  • Miglioramento della protezione contro SQL injection e SSRF
  • Aumento della capacità di rilevamento e risposta agli attacchi
  • Minimizzazione del rischio di interruzione dei servizi
Indications to confirm against the customer's technical and organisational perimeter.
Relevant controlsPatch managementFirewall NGFW / IPSWAFMonitoraggio / SIEMBackup & DR
AudienceITSOCCISO
Information centre

Translation in progress

NCSC Nederland

The official content is available in the original language. The Italian version will be published once automated checks are complete.

Text acquired from the source

Adobe heeft 18 kritieke kwetsbaarheden verholpen in Adobe Campaign Classic. De kwetsbaarheden betreffen onder meer code- en OS-command-injectie, SQL-injectie, onvoldoende autorisatie, onvoldoende invoervalidatie en Server-Side Request Forgery (SSRF). Alle 18 kwetsbaarheden zijn als kritiek aangemerkt en tien kunnen zonder authenticatie op afstand worden misbruikt. Succesvol misbruik kan onder meer leiden tot het uitvoeren van willekeurige code, privilege-escalatie, het omzeilen van beveiligingsmaatregelen, het uitlezen van bestanden en Denial-of-Service. De kwetsbaarheden met kenmerk CVE-2026-82004, CVE-2026-73369, CVE-2026-84412, CVE-2026-89275, CVE-2026-75723, CVE-2026-75699, CVE-2026-75703 en CVE-2026-75721 hebben een CVSS-score van 10,0 en kunnen zonder authenticatie en gebruikersinteractie op afstand worden misbruikt. Voor zeven hiervan noemt Adobe willekeurige code-uitvoering als mogelijke impact. Voor CVE-2026-75703 noemt Adobe Denial-of-Service als impact.

Source
NCSC Nederland (Paesi Bassi)
Publishing entity
NCSC Nederland
Entity type
National CSIRT
Area
Europe · NL
Original language
nl · translation in preparation
Publication
24/09/2026 08:43
MITRE ATT&CK
T1059, T1059.001, T1059.003, T1059.004
CVE
CVE-2026-82004, CVE-2026-73369, CVE-2026-84412, CVE-2026-89275, CVE-2026-75723, CVE-2026-75699, CVE-2026-75703, CVE-2026-75721
Stated country
NL
Technical scope

Affected products and versions

Verification in progress
Information not yet acquired.

The collector will check NVD and the available official vendor advisories.

Open the original source