Adobe has launched safety updates to handle a maximum-severity safety flaw in Marketing campaign Traditional (ACC), its enterprise-focused advertising and marketing automation platform, that might end in arbitrary code execution.
The vulnerability, tracked as CVE-2026-48449, carries a severity rating of 10.0 on the CVSS scoring system.
It has been described as a case of incorrect authorization that might end in arbitrary code execution within the context of the present person with out requiring any person interplay.
The replace additionally resolves one other high-severity flaw (CVE-2026-48448, CVSS rating: 8.6) stemming from SQL injection that might pave the best way for arbitrary file reads.
“This replace addresses important vulnerabilities that might end in arbitrary code execution and arbitrary file system learn,” Adobe stated in an advisory. The corporate famous that it isn’t conscious of any of the issues being exploited within the wild.
Each shortcomings have been addressed in ACC v7: 7.4.3 construct 9398 for Home windows and Linux.
Individually, Adobe has additionally shipped updates to remediate eight critical-rated flaws in Adobe Bridge that might result in privilege escalation and arbitrary code execution –
- CVE-2026-48395 (CVSS rating: 8.6) – An untrusted search path vulnerability that results in arbitrary code execution
- CVE-2026-48396 (CVSS rating: 8.6) – An incorrect authorization vulnerability that results in arbitrary code execution
- CVE-2026-48390 (CVSS rating: 8.6) – An incorrect authorization vulnerability that results in privilege escalation
- CVE-2026-48391 (CVSS rating: 8.2) – An untrusted search path vulnerability that results in arbitrary code execution
- CVE-2026-48374 (CVSS rating: 7.8) – A path traversal vulnerability that results in arbitrary code execution
- CVE-2026-48392 (CVSS rating: 7.8) – An out-of-bounds write vulnerability that results in arbitrary code execution
- CVE-2026-48393 (CVSS rating: 7.8) – An out-of-bounds write vulnerability that results in arbitrary code execution
- CVE-2026-48394 (CVSS rating: 7.8) – An out-of-bounds write vulnerability that results in arbitrary code execution
Adobe credited safety researcher Kieran (“kaiksi”) with discovering and reporting CVE-2026-48390, CVE-2026-48391, CVE-2026-48395, CVE-2026-48396, and CVE-2026-48374, and “yjdfy” for CVE-2026-48392, CVE-2026-48393, and CVE-2026-48394.
Customers are suggested to use the newest updates for optimum safety.







