Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

CVE-2026-76193 -- CVSS 10.0 Vulnerability Briefing

CVE-2026-76193 | CVSS 10.0 (Critical) | Exploit: PoC available

What Is It

CVE-2026-76193 is a critical server-side request forgery vulnerability in Adobe Campaign Classic that can lead to arbitrary code execution in the context of the current user.

Technical Detail

The flaw allows an attacker to induce Adobe Campaign Classic to make attacker-controlled server-side requests, creating a path to arbitrary code execution. Successful exploitation does not require user interaction and could allow an attacker to execute code with the privileges of the affected Campaign Classic process or current user context. The vulnerability has changed scope, meaning exploitation may affect resources beyond the initially vulnerable component's security authority.

Exploitation Status

A proof of concept is available. CISA has not listed this vulnerability in its Known Exploited Vulnerabilities catalog, and active exploitation in the wild has not been confirmed in the available data.

Who Is Targeting This

No specific threat actor attribution at this time.

What To Do

Prioritize applying Adobe security updates or vendor-provided mitigations for affected Adobe Campaign Classic deployments as soon as they are available. Restrict the application server's outbound network access to only required destinations and services, particularly cloud metadata endpoints, internal administrative interfaces, and management networks, to reduce SSRF impact. Review Campaign Classic and surrounding proxy, web-server, and network logs for unexpected outbound requests initiated by application servers, especially requests to internal addresses, link-local IP ranges, metadata services, or unusual ports. No specific workaround, affected version list, or vendor detection guidance is confirmed in the available data.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →