CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →
← Back to the live brief
NOTABLECVE-2026-82004 +12NATOA2vulnerability

Adobe Campaign Classic: eight unauthenticated CVSS 10.0 flaws in APSB26-142 and three more in APSB26-134, with build 9402 as the fix

Adobe's 22 September revision grew one Campaign Classic CVE into eighteen, ten unauthenticated; build 9402 closes them

Defender actions

  • Update every on-premise Adobe Campaign Classic v7 server, and the on-premise components of any hybrid deployment, to build 9402; build 9401 fixes only APSB26-134's three flaws, and an Adobe-hosted instance that still reports 9401 is not evidence of exposure.

Analysis

Adobe's Priority 1 bulletin APSB26-142 covers Adobe Campaign Classic v7 7.4.4 build 9401 and earlier on Windows and Linux and names build 9402 as the fix; it was published on 2026-09-08 with one CVE and revised on 2026-09-22 to add seventeen more, for eighteen, all rated Critical (Adobe PSIRT, 2026-09-22). Ten of the eighteen need no privileges: eight are CVSS 10.0 with the vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H (CVE-2026-82004, an OS command injection; six code-injection flaws, CVE-2026-73369, -84412, -89275, -75699, -75703 and -75721; and CVE-2026-75723, an incorrect-authorization flaw), plus CVE-2026-83660 (SSRF, 9.9) and CVE-2026-75728 (incorrect authorization, 9.1) (Adobe PSIRT, 2026-09-22). The remaining eight require low or high privileges. The earlier bulletin APSB26-134 (Priority 1, 2026-08-25) fixed three more unauthenticated CVSS 10.0 flaws in build 9401, CVE-2026-76197 and CVE-2026-76195 (OS command injection) and CVE-2026-76193 (SSRF) (Adobe PSIRT, 2026-08-25).

Adobe states it is not aware of exploitation of any issue in APSB26-142, and none of these CVEs is in CISA's KEV catalog as of the 2026-10-01 version (Adobe PSIRT, 2026-09-22; CISA KEV, 2026-10-01). The bulletin applies to fully on-premise deployments and the on-premise components of hybrid deployments; Adobe-hosted instances are already remediated, and because the hosted fixes did not increment the customer-visible build number, some hosted instances still report build 9401 (Adobe PSIRT, 2026-09-22). Adobe's table names build 9402 for all eighteen, so estates that moved to it for the single CVE visible on 2026-09-08 already hold every fix; estates that stopped at build 9401 or earlier carry the ten unauthenticated flaws.

Exposure: on-premise Campaign Classic v7 servers, and the on-premise tier of hybrid deployments, running build 9401 or earlier; the flaw classes (OS command injection, code injection, incorrect authorization and SSRF) are all network-reachable, so reachability of the Campaign endpoints from outside decides how urgent the update is.

Cited evidence

Adobe is not aware of any exploits in the wild for any of the issues addressed in this update.

Adobe-hosted instances have already been remediated and require no customer action.

some Adobe-hosted instances may continue to report build 9401 even though the applicable security fixes have already been deployed

Adobe PSIRT (APSB26-142) 2026-09-22

Sources3

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.