Security NEXTJuly 31, 2026🇯🇵Translated from Japanese

Critical Vulnerabilities Disclosed in Adobe Campaign Classic Require Immediate Patching

Adobe has disclosed two serious vulnerabilities in Adobe Campaign Classic (ACC) that require urgent remediation. The company published its security advisory on 29 July 2026, highlighting risks to on-premises installations running on Windows and Linux.

The first issue, tracked as CVE-2026-48449, stems from improper authorization handling. It allows remote attackers to execute arbitrary code without requiring authentication and received the maximum CVSSv3.1 base score of 10.0.

The second vulnerability, CVE-2026-48448, is a SQL injection flaw. Unauthenticated attackers can leverage it to read arbitrary files stored on the file system, earning a CVSSv3.1 score of 8.6.

Adobe Campaign Classic is a campaign management product used by organizations to support marketing initiatives. Security researchers assess both flaws as carrying a high risk of future exploitation.

Administrators are strongly advised to apply the patches released by Adobe immediately to protect affected on-premises environments.

Related articles

Security NEXTVulnerabilities & Exploits

Oracle Releases August 2026 Monthly Security Patches Fixing 943 Vulnerabilities

Oracle has published its monthly Critical Security Patch Update on August 18, 2026, addressing a total of 943 vulnerabilities across a wide range of products. This release supplements the company's quarterly Critical Patch Update and includes fixes for third-party software issues, resulting in 925 unique CVEs after removing duplicates. Of these, 710 vulnerabilities received CVSSv3 base scores of 7.0 or higher, with 154 scoring 9.0 or above, including three at the maximum 10.0. A total of 467 flaws can be exploited remotely without authentication. Major products affected include Oracle Fusion Middleware with 262 patches, Oracle E-Business Suite with 120 fixes, and Oracle Database Server with six updates. The next monthly update is scheduled for September 15, 2026, followed by the quarterly release on October 20.

AntiMalwareVulnerabilities & Exploits

PoC Exploit Released for Android CVE-2026-0075 Allowing Contact Theft Without READ_CONTACTS Permission

A researcher has published a proof-of-concept exploit for CVE-2026-0075 affecting Android 14, 15, 16 and 16 QPR2. The flaw resided in the ContactsProvider2 component and enabled local applications to extract contact database entries through SQL injection and verbose SQLite error responses, bypassing the need for any user-granted permissions. Google rated the issue high severity and addressed it in the June 2026 security bulletin by stripping detailed JSON error information from responses to unprivileged apps. The publicly available PoC on GitHub deliberately avoids requesting READ_CONTACTS or WRITE_CONTACTS and is intended strictly for lab comparison of patched versus vulnerable builds. No confirmed in-the-wild exploitation has been observed yet, but the release of working code increases risk for devices running older firmware. Users are advised to verify that their devices have received the security patch dated 5 June 2026 or later.

Security NEXTVulnerabilities & Exploits

Critical Authentication Bypass and Buffer Overflow Flaws Patched in NetScaler ADC and Gateway

Cloud Software Group disclosed two critical vulnerabilities affecting NetScaler ADC and NetScaler Gateway products. CVE-2026-19490 permits authentication bypass via an alternate path when the appliances operate as SSL VPN, ICA proxy, CVPN, or RDP proxy gateways, or when configured as authentication, authorization, and auditing virtual servers. CVE-2026-19489 is a buffer overflow in LSN groups with SIP ALG enabled that can lead to unexpected behavior or denial of service. Both issues received CVSS v4.0 base scores of 9.3 and 8.8 respectively. Fixed builds 14.1-73.32 and 13.1-63.21 are now available along with corresponding FIPS and NDcPP updates.

AntiMalwareVulnerabilities & Exploits

Microsoft Releases Fix for Windows Defender Crashes During Quick and Full Scans

Microsoft has issued a security intelligence update to resolve a crash in Windows Defender that occurred during quick or full system scans on affected Windows 10 and Windows 11 devices. The bug, introduced after a recent set of patches, caused the antivirus service to terminate unexpectedly with the message "Threat service has stopped. Restart it" and access violation error 0xc0000005. Some users misinterpreted the repeated failures as malware infection or severe system damage, leading them to reinstall Windows entirely. Administrators were able to reproduce the issue consistently across multiple machines simply by initiating a quick scan, confirming the root cause lay in Defender itself rather than individual endpoints. The fix is included in security intelligence version 1.457.236.0 and all subsequent releases, with Microsoft advising users to ensure automatic updates are applied via Windows Update or manually through the Windows Security interface.