Adobe Security Bulletin
Last updated on Aug 25, 2026
Security update available for Adobe Campaign Classic | APSB26-134
Summary
Adobe has released a security update for Adobe Campaign Classic. This update addresses critical vulnerabilities that could result in arbitrary code execution.
Adobe is not aware of any exploits in the wild for any of the issues addressed in this update.
Affected versions
Solution
Adobe categorizes these updates with the following priority rating and recommends users update their installation to the newest version:
Note
This security bulletin applies only to fully on-premise deployments of Adobe Campaign Classic and to the on-premise components of hybrid deployments. Adobe-hosted instances have already been remediated and require no customer action.
Vulnerability Details
Note
Effective August 11, 2026, Adobe may assign a single CVE identifier to internally discovered vulnerabilities with the same severity rating and CWE category when a release includes systemic fixes.
NOTE: Adobe has a public bug bounty program with HackerOne. If you are interested in working with Adobe as an external security researcher, please check out https://app.intigriti.com/programs/adobe/adobepublic/detail.
For more information, visit https://www.adobe.com/trust/security/bug-bounty.html, or email PSIRT@adobe.com.