criticalZero-Day

Adobe Campaign Classic OS Command Injection (CVE-2026-76195)

First seen Aug 27, 2026 · Updated Aug 27, 2026 · CVSS 10

adobeos-command-injectionrcecampaign-classicunauthenticatedcritical-vulnerability

A critical OS Command Injection vulnerability in Adobe Campaign Classic (ACC) allows an attacker to achieve arbitrary code execution in the context of the current user without requiring any user interaction. With a maximum CVSS score of 10.0 and a changed scope, successful exploitation could allow attackers to pivot beyond the vulnerable component into connected infrastructure.

Technical Analysis

CVE-2026-76195 stems from improper neutralization of special elements used in OS commands within Adobe Campaign Classic, enabling an attacker to inject and execute arbitrary system commands. The vulnerability requires no user interaction and has a 'Scope Changed' designation, indicating the attacker can affect resources beyond the vulnerable component's security scope, likely underlying host or connected database/mail infrastructure. Given ACC's role as a marketing automation platform often integrated with CRM, email delivery services, and customer data stores, a compromised instance could expose API keys, database credentials, and personal data used across integrated systems. Organizations that have connected AI agents or RAG pipelines to Campaign Classic for customer data enrichment, personalization, or automated campaign orchestration risk credential theft or lateral movement into agent tooling if the injected commands harvest stored API keys or service account tokens. This is especially concerning for hybrid marketing/AI stacks where ACC serves as a data source for LLM-driven customer segmentation or content generation workflows.

Affected Systems

Adobe Campaign Classic (ACC) - all deployments prior to the vendor-issued patch; specific affected version ranges should be confirmed via Adobe's official security bulletin (APSB) for this CVE.

Indicators of Compromise

  • No public IOCs available at this time; monitor Adobe security bulletins and threat intelligence feeds for updates.

Remediation Steps

  1. 1

    Apply Vendor Patch

    Immediately apply the official Adobe security update addressing CVE-2026-76195 as soon as it is released; consult Adobe's security bulletin (APSB) for exact patched versions.

  2. 2

    Restrict Network Access

    Limit exposure of Adobe Campaign Classic management and API interfaces to trusted internal networks and VPNs, and disable unnecessary external access.

  3. 3

    Audit and Rotate Credentials

    Rotate any API keys, service account credentials, or database passwords accessible from or stored on the ACC host, particularly those used by connected AI agents, automation tools, or third-party integrations.

  4. 4

    Monitor for Exploitation

    Deploy host-based and network monitoring for anomalous process execution, unexpected outbound connections, and command-line activity on ACC servers.

  5. 5

    Segment Integrated Systems

    Ensure ACC is network-segmented from other critical systems, including AI agent infrastructure, RAG pipelines, and data warehouses, to limit blast radius in case of compromise.

CVE / Advisory IDs

CVE-2026-76195

Industries Most Exposed

marketingretaile-commercefinancial servicesmediatechnologyany industry using Adobe Campaign Classic for customer engagement

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.