PatchSiren cyber security CVE debrief
CVE-2026-82013 Adobe CVE debrief
A Server-Side Request Forgery (SSRF) vulnerability in Adobe Campaign Classic (ACC) could allow a low-privileged attacker to gain elevated access to internal resources. The vulnerability, tracked as CVE-2026-82013, has a CVSS score of 9.9 and is considered critical. Exploitation does not require user interaction. This vulnerability affects Adobe Campaign Classic versions prior to 7.4.4. Defenders and security teams should assess exposure and apply patches to prevent exploitation. The CVE record and NVD vulnerability detail provide information on the vulnerability, its impact, and affected versions.
- Vendor
- Adobe
- Product
- Adobe Campaign Classic
- CVSS
- CRITICAL 9.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-22
- Original CVE updated
- 2026-09-26
- Advisory published
- 2026-09-22
- Advisory updated
- 2026-09-26
Who should care
Defenders and security teams responsible for Adobe Campaign Classic systems should assess exposure and apply patches. IT administrators and incident response teams should review and update their plans to address potential exploitation.
Why it matters
CVE-2026-82013 is a critical SSRF vulnerability in Adobe Campaign Classic that allows low-privileged attackers to gain elevated access to internal resources. Defenders should assess exposure, apply patches, and verify system security to prevent exploitation.
- Potential privilege escalation requires immediate attention to prevent exploitation.
- Verification of system security and monitoring for suspicious activity is necessary.
- Applying patches or mitigations provided by Adobe is crucial to prevent exploitation.
Technical summary
The CVE-2026-82013 vulnerability in Adobe Campaign Classic allows a low-privileged attacker to gain elevated access to internal resources via SSRF. The vulnerability has a CVSS score of 9.9 and is considered critical. Affected versions include those prior to 7.4.4. The vulnerability can be exploited without user interaction, and defenders should prioritize verifying the vulnerability's impact on their systems and applying the necessary fixes. The CVE record and NVD vulnerability detail provide information on the vulnerability, its impact, and affected versions.
Defensive priority
Immediate attention is required to assess exposure and apply patches. Defenders should prioritize verifying the vulnerability's impact on their systems and applying the necessary fixes.
Recommended defensive actions
- Assess exposure of Adobe Campaign Classic systems to CVE-2026-82013
- Apply patches or mitigations provided by Adobe
- Verify system security and monitor for suspicious activity
- Review and update incident response plans
- Perform vulnerability scanning to identify potentially affected systems
- Implement compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD vulnerability detail provide information on the vulnerability, its impact, and affected versions. However, the scope of affected versions and systems requires further verification.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-82013 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-82013
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-82013 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-82013
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://helpx.adobe.com/security/products/campaign/apsb26-142.html
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.