NCSC-2026-0393 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Campaign Classic
What it means
Adobe ha rimosso 18 vulnerabilità critiche in Adobe Campaign Classic, tra cui code- e OS-command injection, SQL injection, insufficient authorization e SSRF. Otto vulnerabilità hanno un CVSS 10,0 e possono essere sfruttate remotamente senza autenticazione o interazione utente. L'attacco potrebbe portare a esecuzione di codice, escalation di privilegi, bypass di sicurezza e DoS. Nessun sfruttamento attivo confermato.
Why it matters
Le vulnerabilità critiche in Adobe Campaign Classic rappresentano un rischio elevato per le PMI italiane, che potrebbero subire accessi non autorizzati, furto di dati e interruzione dei servizi. La mancanza di patch potrebbe compromettere la continuità operativa e la conformità normativa.
Recommended actions
- Applicare immediatamente le patch disponibili per Adobe Campaign Classic
- Configurare regole di firewall per bloccare accessi non autorizzati al database
- Implementare un WAF per filtrare richieste SQL e SSRF
- Ridurre l'esposizione di Adobe Campaign Classic a Internet
- Monitorare i log di sistema e le richieste HTTP per segnali di attacco
- Eseguire backup regolari e testare la ripristino di emergenza
Potential operational benefits
- Riduzione della superficie esposta a attacchi remoti
- Miglioramento della protezione contro SQL injection e SSRF
- Aumento della capacità di rilevamento e risposta agli attacchi
- Minimizzazione del rischio di interruzione dei servizi
Translation in progress
The official content is available in the original language. The Italian version will be published once automated checks are complete.
Text acquired from the source
Adobe heeft 18 kritieke kwetsbaarheden verholpen in Adobe Campaign Classic. De kwetsbaarheden betreffen onder meer code- en OS-command-injectie, SQL-injectie, onvoldoende autorisatie, onvoldoende invoervalidatie en Server-Side Request Forgery (SSRF). Alle 18 kwetsbaarheden zijn als kritiek aangemerkt en tien kunnen zonder authenticatie op afstand worden misbruikt. Succesvol misbruik kan onder meer leiden tot het uitvoeren van willekeurige code, privilege-escalatie, het omzeilen van beveiligingsmaatregelen, het uitlezen van bestanden en Denial-of-Service. De kwetsbaarheden met kenmerk CVE-2026-82004, CVE-2026-73369, CVE-2026-84412, CVE-2026-89275, CVE-2026-75723, CVE-2026-75699, CVE-2026-75703 en CVE-2026-75721 hebben een CVSS-score van 10,0 en kunnen zonder authenticatie en gebruikersinteractie op afstand worden misbruikt. Voor zeven hiervan noemt Adobe willekeurige code-uitvoering als mogelijke impact. Voor CVE-2026-75703 noemt Adobe Denial-of-Service als impact.
- Source
- NCSC Nederland (Paesi Bassi)
- Publishing entity
- NCSC Nederland
- Entity type
- National CSIRT
- Area
- Europe · NL
- Original language
- nl · translation in preparation
- Publication
- 24/09/2026 08:43
- MITRE ATT&CK
- T1059, T1059.001, T1059.003, T1059.004
- CVE
- CVE-2026-82004, CVE-2026-73369, CVE-2026-84412, CVE-2026-89275, CVE-2026-75723, CVE-2026-75699, CVE-2026-75703, CVE-2026-75721
- Stated country
- NL
Affected products and versions
The collector will check NVD and the available official vendor advisories.