Vulnerabilities
Adobe Campaign Classic Hit by a Second CVSS 10.0 RCE (CVE-2026-48449) — and Last Month's Patch Is the Vulnerable Build
Adobe patched CVE-2026-48449, a CVSS 10.0 incorrect-authorization flaw in on-premise Campaign Classic that can run code with no authentication and no user interaction. The catch: build 9397, which fixed July's max-severity bug, is the version this one breaks. Patch to 9398.