2026-10-02NOTABLEAdobe's 22 September revision grew one Campaign Classic CVE into eighteen, ten unauthenticated; build 9402 closes them
Adobe Campaign Classic v7, unauthenticated OS command injection (CVSS 10.0), fixed in build 9401, no exploitation known
cve · CVE-2026-76195 single-source
Coverage
1
first 2026-10-02 → last 2026-10-02
Latest activity
2026-10-02
Adobe's 22 September revision grew one Campaign Classic CVE into eighteen, ten unauthenticated; build 9402…
Peak priority
notable
1 notable
Targets
technology
sectors: technology
Sources cited
3
3 hosts
Action items (1)
Do-now tasks recorded on the entries about CVE-2026-76195, newest first. Check the date before acting on an older one.
- Update every on-premise Adobe Campaign Classic v7 server, and the on-premise components of any hybrid deployment, to build 9402; build 9401 fixes only APSB26-134's three flaws, and an Adobe-hosted instance that still reports 9401 is not evidence of exposure.2026-10-02CVE-2026-82004 +12
Defender insights
What each entry about CVE-2026-76195 tells a defender to do, newest first.
Detection
Story timeline
ATT&CK techniques (1 across 1 tactic)
1 technique observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-10-02/adobe-campaign-classic-apsb26-142-134-unauth-cvss10 · ATT&CK page ↗
Entries about Adobe Campaign Classic v7, unauthenticated OS command injection (CVSS 10.0), fixed in build 9401, no exploitation known (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Adobe Campaign Classic×1
- Adobe Campaign Classic v7, unauthenticated code injection (CVSS 10.0), fixed in build 9402, no exploitation known×1
- Adobe Campaign Classic v7, unauthenticated code injection (CVSS 10.0), fixed in build 9402, no exploitation known×1
- Adobe Campaign Classic v7, unauthenticated code injection (CVSS 10.0), fixed in build 9402, no exploitation known×1
- Adobe Campaign Classic v7, unauthenticated code injection (CVSS 10.0), fixed in build 9402, no exploitation known×1
- Adobe Campaign Classic v7, unauthenticated code injection (CVSS 10.0), fixed in build 9402, no exploitation known×1
- Adobe Campaign Classic v7, unauthenticated code injection (CVSS 10.0), fixed in build 9402, no exploitation known×1
- Adobe Campaign Classic v7, unauthenticated incorrect authorization (CVSS 10.0), fixed in build 9402, no exploitation known×1
Where this entity is cited
Source distribution
- adobe.com1 (33%)
- cisa.gov1 (33%)
- helpx.adobe.com1 (33%)
External references
All cited sources (3)
- helpx.adobe.comprimaryAdobe PSIRT (APSB26-134)https://helpx.adobe.com/security/products/campaign/apsb26-134.html
- adobe.comAdobe PSIRT (APSB26-142)https://www.adobe.com/trust/security/products/campaign/apsb26-142.html
- cisa.govCISA Known Exploited Vulnerabilities cataloghttps://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json