PatchSiren cyber security CVE debrief
CVE-2026-83660 Adobe CVE debrief
CVE-2026-83660 is a Server-Side Request Forgery (SSRF) vulnerability affecting Adobe Campaign Classic (ACC), potentially leading to privilege escalation. The vulnerability has a CVSS score of 9.9 and is considered CRITICAL. According to the NVD, exploitation does not require user interaction and the scope has been changed. Defenders should assess exposure of ACC systems, especially those with internet-facing interfaces, and evaluate potential impact on user privileges. This involves verifying if systems are vulnerable and applying necessary patches or updates. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L, and affected versions include those prior to 7.4.4 (build
- Vendor
- Adobe
- Product
- Adobe Campaign Classic
- CVSS
- CRITICAL 9.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-22
- Original CVE updated
- 2026-09-26
- Advisory published
- 2026-09-22
- Advisory updated
- 2026-09-26
Who should care
Defenders responsible for Adobe Campaign Classic systems, especially those with internet-facing interfaces, should assess exposure and potential impact on user privileges. Security teams and system administrators need to verify if their systems are vulnerable and apply necessary patches or updates.
Why it matters
CVE-2026-83660 is a critical SSRF vulnerability in Adobe Campaign Classic that could lead to privilege escalation. Defenders should prioritize verifying exposure, assessing impact on user privileges, and applying patches or updates. Security teams and system administrators are advised to monitor ACC systems for suspicious activity and restrict access where necessary.
- Potential privilege escalation on ACC systems.
- Possible unauthorized access to sensitive data or system configurations.
- Risk of lateral movement within the network if exploited.
- Need for verification of system exposure and user privilege restrictions.
Technical summary
The vulnerability (CVE-2026-83660) is a Server-Side Request Forgery (SSRF) issue in Adobe Campaign Classic (ACC) that could result in privilege escalation. It has a CVSS score of 9.9 and is considered CRITICAL. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L. Affected versions include those prior to 7.4.4 (build 9400 and 9401).
Defensive priority
Defenders should prioritize verifying exposure of ACC systems, especially those with internet-facing interfaces, and assess potential impact on user privileges.
Recommended defensive actions
- Verify exposure of Adobe Campaign Classic systems, especially those with internet-facing interfaces.
- Assess potential impact on user privileges and restrict access where necessary.
- Apply patches or updates provided by Adobe to address this vulnerability.
- Monitor ACC systems for suspicious activity indicative of SSRF exploitation.
Evidence notes
The NVD entry provides details on the vulnerability, including its CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L) and affected versions. Adobe has released a vendor advisory (APSB26-142) addressing this issue.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-83660 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-83660
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-83660 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-83660
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://helpx.adobe.com/security/products/campaign/apsb26-142.html
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.