Adobe Campaign Classic v7 Gets Critical CVSS 10.0 Patch for CVE-2026-82004
Adobe published a security bulletin on September 8, 2026, for Adobe Campaign Classic v7 after identifying CVE-2026-82004, a critical OS command injection vulnerability rated CVSS 10.0 that could allow arbitrary code execution. The fix is Campaign Classic v7.4.4 build 9402, while build 9401 and earlier remain affected. The Zero Day Initiative’s September 2026 security review and the September 9 CVE Brief archive independently list the same Campaign Classic vulnerability as a Priority 1, no-interaction security issue.
Adobe Campaign Classic v7 build 9401 and earlier are affected
Adobe’s APSB26-142 security bulletin identifies the affected range as Adobe Campaign Classic v7.4.4 build 9401 and earlier on Windows and Linux. The flaw is classified as an improper neutralization of special elements used in an operating system command, commonly known as OS command injection.
The bulletin assigns the issue a CVSS base score of 10.0 and describes the impact as arbitrary code execution. Adobe also says it was not aware of active exploitation for the vulnerabilities addressed in the update when the bulletin was issued.
CVE-2026-82004 creates a remote code execution risk
The technical severity comes from the vulnerability’s attack profile. Adobe’s CVSS vector indicates that the flaw can be reached over a network, requires low attack complexity, does not require existing privileges, and does not require user interaction. That combination makes the issue materially different from a local administrator-only defect because an exposed Campaign Classic environment may be targeted without first compromising an authenticated user.
The Zero Day Initiative classified APSB26-142 as a critical Adobe Campaign Classic bulletin with a CVSS score of 10.0 and deployment priority 1. The September 9 CVE Brief listing also records CVE-2026-82004 as a network vulnerability requiring no privileges and no interaction, providing an independent confirmation of the risk profile.
Campaign Classic build 9402 is the required fix
Adobe lists v7.4.4 build 9402 as the updated version for Windows and Linux deployments. The security bulletin applies to fully self-hosted installations and the self-hosted components of hybrid deployments. Adobe-hosted instances have already been remediated and do not require customer action for this bulletin.
For teams running Campaign Classic on their own infrastructure, the immediate implication is straightforward: build 9401 or an earlier build should be treated as vulnerable until the environment is upgraded to build 9402. The update is marked Priority 1, so the issue belongs ahead of routine Campaign maintenance and feature planning.









