CVE-2026-76195 -- CVSS 10.0 Vulnerability Briefing
CVE-2026-76195 | CVSS 10.0 (Critical) | Exploit: PoC available
What Is It
CVE-2026-76195 is an OS command injection vulnerability in Adobe Campaign Classic that can allow an attacker to execute arbitrary code without user interaction.
Technical Detail
The flaw is caused by improper neutralization of special elements used in OS commands. An attacker able to reach the vulnerable processing path may inject operating-system commands and achieve remote code execution in the security context of the current Adobe Campaign Classic user. The vulnerability has a CVSS score of 10.0 and changed scope, indicating that compromise may affect resources beyond the initially vulnerable component's security authority.
Exploitation Status
A proof of concept is available. Active exploitation in the wild has not been confirmed, and CVE-2026-76195 is not listed in CISA's Known Exploited Vulnerabilities catalog as of August 27, 2026.
Who Is Targeting This
No specific threat actor attribution at this time.
What To Do
Treat this as a critical patching priority and apply Adobe's security update for Adobe Campaign Classic as soon as it is available and validated. Identify all Adobe Campaign Classic instances, particularly internet-accessible deployments, and restrict access to administrative and application interfaces to trusted networks and authenticated users. No vendor workaround is confirmed in the available information. Monitor Adobe Campaign Classic hosts for unexpected child processes, shell or command-interpreter execution, suspicious commands launched under Campaign service accounts, and anomalous outbound network connections from affected servers.