OFFLINE
Awaiting data
Security intelligence
CriticalCritical vulnerability

CVE-2026-89275 (CVSS 10.0)

NVD · officialPublished Sep 22, 2026Risk 50/100EPSS 1.2%

Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

CVSS
10.0
AV:NetworkAC:LowPR:NoneUI:NoneC:HighI:HighA:High

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source