View Ridge Security
Back to Cyber HoseVulnerabilities & CVEs

Adobe Campaign Classic RCE Flaw CVE-2026-48449 Scores CVSS 10.0

๐Ÿšจ ACTIVE EXPLOITATION

  • Hijacked Hotel Wi-Fi Delivers CornFlake RAT via Fake Browser Updates
    Hijacked hotel Wi-Fi networks deliver CornFlake RAT through fake browser updates.
    • Targets hotel Wi-Fi users across multiple countries via captive portal gateways
    • Attackers hijack DNS and redirect automatic connectivity checks to fake update pages
    • CornFlake RAT captures webcam, microphone, keystrokes, screenshots, and steals credentials
    • Payload delivered after user interaction; includes persistence and watchdog mechanisms
    • Operation tracked as CaptiveCrunch, attributed to Storm-2945, linked to Russian SVR
      ๐Ÿ“Ž Coverage: thehackernews.com ยท ๐Ÿ‘ via The Hacker News

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • Adobe Campaign Classic RCE Flaw CVE-2026-48449 Scores CVSS 10.0, No User Interaction Needed CVE-2026-48449
    Adobe patched a critical CVE-2026-48449 vulnerability in Campaign Classic allowing code execution without user interaction.
    • Applies to Adobe Campaign Classic (ACC) enterprise marketing automation platform
    • Vulnerability CVE-2026-48449 allows arbitrary code execution without user interaction due to incorrect authorization
    • Also fixes CVE-2026-48448, a high-severity SQL injection flaw enabling arbitrary file reads
    • Affected versions fixed in ACC v7: 7.4.3 build 9398 for Windows and Linux
    • No known exploitation of these flaws in the wild as of the advisory
      ๐Ÿ“Ž Coverage: thehackernews.com ยท ๐Ÿ‘ via The Hacker News

๐Ÿ”“ CVEs & KEV

  • Other: 20 CVEs (worst 8.8)

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check