CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Adobe Campaign Classic v7, unauthenticated code injection (CVSS 10.0), fixed in build 9402, no exploitation known

cve · CVE-2026-75703 single-source

Coverage
1
first 2026-10-02 → last 2026-10-02
Latest activity
2026-10-02
Adobe's 22 September revision grew one Campaign Classic CVE into eighteen, ten unauthenticated; build 9402…
Peak priority
notable
1 notable
Targets
technology
sectors: technology
Sources cited
3
3 hosts

Action items (1)

Do-now tasks recorded on the entries about CVE-2026-75703, newest first. Check the date before acting on an older one.

  • Update every on-premise Adobe Campaign Classic v7 server, and the on-premise components of any hybrid deployment, to build 9402; build 9401 fixes only APSB26-134's three flaws, and an Adobe-hosted instance that still reports 9401 is not evidence of exposure.
    2026-10-02CVE-2026-82004 +12

Defender insights

What each entry about CVE-2026-75703 tells a defender to do, newest first.

2026-10-02NOTABLEAdobe's 22 September revision grew one Campaign Classic CVE into eighteen, ten unauthenticated; build 9402 closes them

Detection

Story timeline

  1. 2026-10-02Adobe Campaign Classic: eight unauthenticated CVSS 10.0 flaws in APSB26-142 and three more in APSB26-134, with build 9402 as the fix
    trending-vulnerabilitiesAdobe's 22 September revision grew one Campaign Classic CVE into eighteen, ten unauthenticated; build 9402 closes them
ATT&CK techniques (1 across 1 tactic)

1 technique observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Initial AccessExploit Public-Facing Application

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-10-02/adobe-campaign-classic-apsb26-142-134-unauth-cvss10 · ATT&CK page ↗

Entries about Adobe Campaign Classic v7, unauthenticated code injection (CVSS 10.0), fixed in build 9402, no exploitation known (1)

2026-10-02 · view entry permalink →

NOTABLECVE-2026-82004 +12NATOA2

Adobe Campaign Classic: eight unauthenticated CVSS 10.0 flaws in APSB26-142 and three more in APSB26-134, with build 9402 as the fix

Adobe's Priority 1 bulletin APSB26-142 covers Adobe Campaign Classic v7 7.4.4 build 9401 and earlier on Windows and Linux and names build 9402 as the fix; it was published on 2026-09-08 with one CVE and revised on 2026-09-22 to add seventeen more, for eighteen, all rated Critical (Adobe PSIRT, 2026-09-22). Ten of the eighteen need no privileges: eight are CVSS 10.0 with the vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H (CVE-2026-82004, an OS command injection; six code-injection flaws, CVE-2026-73369, -84412, -89275, -75699, -75703 and -75721; and CVE-2026-75723, an incorrect-authorization flaw), plus CVE-2026-83660 (SSRF, 9.9) and CVE-2026-75728 (incorrect authorization, 9.1) (Adobe PSIRT, 2026-09-22). The remaining eight require low or high privileges. The earlier bulletin APSB26-134 (Priority 1, 2026-08-25) fixed three more unauthenticated CVSS 10.0 flaws in build 9401, CVE-2026-76197 and CVE-2026-76195 (OS command injection) and CVE-2026-76193 (SSRF) (Adobe PSIRT, 2026-08-25).

Adobe states it is not aware of exploitation of any issue in APSB26-142, and none of these CVEs is in CISA's KEV catalog as of the 2026-10-01 version (Adobe PSIRT, 2026-09-22; CISA KEV, 2026-10-01). The bulletin applies to fully on-premise deployments and the on-premise components of hybrid deployments; Adobe-hosted instances are already remediated, and because the hosted fixes did not increment the customer-visible build number, some hosted instances still report build 9401 (Adobe PSIRT, 2026-09-22). Adobe's table names build 9402 for all eighteen, so estates that moved to it for the single CVE visible on 2026-09-08 already hold every fix; estates that stopped at build 9401 or earlier carry the ten unauthenticated flaws.

Exposure: on-premise Campaign Classic v7 servers, and the on-premise tier of hybrid deployments, running build 9401 or earlier; the flaw classes (OS command injection, code injection, incorrect authorization and SSRF) are all network-reachable, so reachability of the Campaign endpoints from outside decides how urgent the update is.

Adobe is not aware of any exploits in the wild for any of the issues addressed in this update.

Adobe-hosted instances have already been remediated and require no customer action.

some Adobe-hosted instances may continue to report build 9401 even though the applicable security fixes have already been deployed

Adobe PSIRT (APSB26-142) 2026-09-22

Builds on: Adobe ships a priority-1 fix for a CVSS 10.0 unauthenticated code-execution flaw in Campaign… · Adobe ships a second Campaign Classic emergency fix in five days; build 9398 was the patch, and… · Adobe's August bulletins carry three separate unauthenticated, maximum-severity code-execution…

vulnerability02 Oct 05:00Zsingle-sourceOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Vulns1

Source distribution

  • adobe.com1 (33%)
  • cisa.gov1 (33%)
  • helpx.adobe.com1 (33%)