Adobe Campaign Classic Critical OS Command Injection (CVE-2026-82004, APSB26-142, CVSS 10.0) — Threadlinqs Intelligence
As of 2026-09-08, Adobe Campaign Classic Critical OS Command Injection (CVE-2026-82004, APSB26-142, CVSS 10.0) is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 5 indicators of compromise.
Threat ID: TL-2026-2408 · Severity: CRITICAL · CVSS: 10 · Status: ACTIVE · Category: VULNERABILITY
Adobe's September 2026 Patch Tuesday release (APSB26-142, 2026-09-08) fixes CVE-2026-82004, an unauthenticated OS command injection (CWE-78) in Adobe Campaign Classic v7 rated CRITICAL CVSS 10.0. The
On September 8, 2026, Adobe released security bulletin APSB26-142 for Adobe Campaign Classic (ACC) v7 as part of its September 2026 security update cycle (over 170 vulnerabilities patched across Adobe products that day). The bulletin addresses CVE-2026-82004, an OS command injection vulnerability (CWE-78: Improper Neutralization of Special Elements used in an OS Command) rated CRITICAL with a CVSS 3.1 base score of 10.0 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). The vulnerability could result in arbitrary code execution in the context of the current user: it is remotely exploitable over the network at low complexity, requires no privileges and no user interaction, and carries a changed scope, meaning the impact can extend to the underlying operating system, database connections, and connected CRM/integration endpoints beyond the ACC component itself. Affected builds are Adobe Campaign Classic v7 through 7.4.4 build 9401 on both Windows and Linux; the fix ships in 7.4.4 build 9402. Adobe-hosted (fully managed) instances are remediated by Adobe; on-premise and hybrid deployments with on-premise components must upgrade and restart the nlserver service for the fix to take effect.
The central attack surface for Campaign Classic is its SOAP web interface. All ACC functionality is exposed to the Rich Client (console), Thin Client (browser), and API integrations through POST /nl/jsp/soaprouter.jsp, the single SOAP routing endpoint served by the embedded Apache Tomcat JSP server inside the nlserver web process. SOAP envelopes dispatched through this endpoint (namespaces such as xtk:session, xtk:queryDef, nms:delivery) process user-controlled XML parameters, and the OS command injection sink in this processing path is the code-execution primitive behind CVE-2026-82004. This is not an isolated event: 2026 has seen a recurring series of CVSS 10.0 vulnerabilities in this same interface, including incorrect-authorization/Java-deserialization RCE (CVE-2026-48449, APSB26-114), SQL injection (CVE-2026-48448, APSB26-114), additional OS command injection and SSRF flaws (CVE-2026-76197, CVE-2026-76195, CVE-2026-76193, APSB26-134), and further incorrect-authorization arbitrary code execution issues (CVE-2026-48286, CVE-2026-48303, CVE-2026-27302, CVE-2026-71398), with Adobe itself attributing the increased discovery cadence in part to AI-assisted vulnerability discovery. This pattern makes ACC one of Adobe's most persistently targeted server products during 2026, alongside Commerce/Magento and ColdFusion, all of which received Adobe Deployment Priority 1 ratings in the September 2026 release.
At the time of disclosure no public proof-of-concept and no exploitation in the wild had been reported for CVE-2026-82004, and no Adobe Campaign Classic CVE is listed in the CISA Known Exploited Vulnerabilities catalog as of 2026-09-08. NVD lists the record as undergoing analysis. AusCERT redistributed the Adobe bulletin to its Australian constituency as ESB-2026.10699 (published 2026-09-09 10:28 UTC+1000) with member-only technical detail; the AusCERT bulletin metadata confirms Product: Adobe Campaign Classic, Publisher: Adobe, OS: Windows and Linux, referencing the APSB26-142 advisory. Defenders should treat this as a should-patch-within-72-hours unauthenticated remote code execution class exposure on a product that handles large volumes of customer PII and campaign data, and should monitor for post-RCE activity consistent with web shell deployment, discovery, credential access, and data exfiltration if an ACC server is compromised.
Target sectors: marketing, finance, retail, health, telecoms
Target regions: Global
Timeline
- Adobe releases APSB26-66 for Campaign Classic fixing two critical incorrect-authorization CVEs (CVE-2026-48303, CVE-2026-47938, CVSS 10.0) in build 7.4.3 build 9395 - first in the 2026 series of CVSS 10.0 Campaign flaws.
- Adobe releases APSB26-69 fixing CVE-2026-48286, a critical (CVSS 10.0) incorrect-authorization vulnerability in Campaign Classic, addressed in build 7.4.3 build 9397.
- Adobe releases APSB26-114 for Campaign Classic addressing CVE-2026-48449 (incorrect authorization/Java deserialization RCE via the SOAP API, CVSS 10.0) and CVE-2026-48448 (SQL injection, CVSS 8.6), fixed in build 7.4.3 build 9398; NVD publishes CVE-2026-48449 on 2026-07-30.
- Adobe releases APSB26-120 covering 7 additional Adobe Campaign Classic vulnerabilities (6 rated critical).
- Adobe releases APSB26-123 with three critical Campaign Classic CVEs (CVE-2026-27302, CVE-2026-71398, CVE-2026-48381), fixed in build 7.4.4 build 9400.
- Adobe releases APSB26-134 addressing three CVSS 10.0 Campaign Classic flaws: OS command injection (CVE-2026-76197, CVE-2026-76195) and SSRF (CVE-2026-76193), fixed in build 7.4.4 build 9401; NVD status Analyzed by 2026-09-01.
- Adobe releases APSB26-142 for Campaign Classic fixing CVE-2026-82004, a CVSS 10.0 OS command injection (CWE-78) affecting builds up to 7.4.4 build 9401 on Windows and Linux; fixed in build 9402. Rated Deployment Priority 1 (patch within 72 hours).
- NVD publishes CVE-2026-82004 (status: undergoing analysis) with CVSS 3.1 base score 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H); no public PoC and no in-the-wild exploitation reported; not present in the CISA KEV catalog as of this date.
- AusCERT redistributes the Adobe bulletin to its constituency as External Security Bulletin ESB-2026.10699 (10:28 UTC+1000), confirming Product: Adobe Campaign Classic, Publisher: Adobe, OS: Windows and Linux; full technical detail is member-only. Australian date rolls to 2026-09-09 due to UTC+1000.
Detections & IOCs
As of 2026-09-10, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 5 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-82004, T1190, T1059.003, T1059.004, T1505.002, T1543.003, T1082, T1005, T1071.001, T1021.001, T1021.004