Security NEXTAugust 4, 2026🇯🇵Translated from Japanese

Adobe Releases Emergency Update for Campaign Classic Fixing Multiple Critical Vulnerabilities

Adobe has released an emergency security update for Adobe Campaign Classic to address seven critical vulnerabilities, several of which received the maximum CVSSv3.1 base score of 10.0.

The company disclosed the issues on August 3, 2026, through a security advisory and urged immediate application of the new patches. The vulnerabilities impact on-premises installations running on Windows and Linux as well as the on-premises components in hybrid deployments.

Just days earlier, on July 29, Adobe had already shipped an emergency update (version 7.4.3 build 9398). However, both that release and all prior versions remain affected by the newly disclosed flaws, necessitating another round of updates.

The most severe issues include:

  • CVE-2026-48331 – a server-side request forgery (SSRF) vulnerability
  • CVE-2026-48323 – an input processing flaw in the template engine
  • CVE-2026-48330 – an SQL injection vulnerability

All three received a CVSSv3.1 base score of 10.0. Adobe recommends that organizations running the affected versions apply the latest fixes without delay to prevent potential exploitation.

Related articles

Security NEXTVulnerabilities & Exploits

N-able Releases Hotfix for Exploited N-central Authentication Bypass Flaw CVE-2026-18577

N-able has published a hotfix addressing a high-severity authentication bypass vulnerability in its N-central IT operations management platform. The flaw, tracked as CVE-2026-18577, allows attackers to bypass authentication through alternative paths or channels and potentially take over user accounts. It affects N-central 2026.1 and earlier versions and stems from an incomplete fix for the earlier CVE-2026-18556 issue. The vulnerability carries a CVSS v4.0 base score of 8.2 and is rated High severity. Exploitation has already been observed in the wild, with Indicators of Compromise including related IP addresses now publicly available. N-able released N-central 2026.3 Hotfix 1 (build 2026.3.1.7) on August 2, 2026, and urges customers to apply the update while also recommending agent updates where possible.

SecuritylabVulnerabilities & Exploits

Dark Patterns in Vulnerability Management: How Metrics Undermine Real Security

Vulnerability management programs often fail not due to lack of scanners but because of poorly chosen metrics that prioritize reporting over actual risk reduction. Teams focus on closing easy vulnerabilities, meeting CVSS-based deadlines, and improving dashboard numbers while attackers exploit the shortest path to critical assets. The article examines five common traps including total vulnerability counts, context-free SLAs, closure rate targets, static dashboards, and claims of no critical findings. It argues that these metrics create a false sense of security and distort team behavior according to Goodhart's Law. Instead, organizations should adopt attack path metrics, exposure management approaches such as CTEM, and measurements that track real reduction in attacker reachability. The piece highlights MaxPatrol Carbon as an example of tools that model attacker paths rather than isolated CVEs.

Security NEXTVulnerabilities & Exploits

MongoDB Server Patches 24 Vulnerabilities Including Critical Flaw in mongod Compute Mode

MongoDB has released updates addressing 24 vulnerabilities in MongoDB Server, with one rated critical. The patches cover multiple branches and include fixes for CVE-2026-13072, which carries a CVSSv3.1 base score of 9.2. The critical issue affects standalone mongod instances with compute mode enabled and stems from insufficient validation of external input that can lead to memory corruption. Additional fixes resolve 16 high-severity issues, seven medium, and one low, including CVE-2026-13059 that could allow unauthorized read-write actions by low-privileged authenticated users. Updated versions MongoDB 8.3.7, 8.2.12, 8.0.28, and 7.0.39 are now available. The company published the updates on July 22, 2026, and urges immediate application to maintain system integrity.

Security NEXTVulnerabilities & Exploits

Weekly Roundup: Critical Vulnerabilities Hit VMware ESX, FortiOS, Chrome, fastjson, Cisco FMC and Ruby on Rails

Security NEXT published its list of the ten most-read articles for the week of July 26 to August 1, 2026. The ranking is dominated by high-severity vulnerabilities affecting widely deployed enterprise platforms. VMware released fixes for serious flaws in ESX and vCenter, while Fortinet confirmed active exploitation of vulnerabilities in FortiOS and VeloCloud Orchestrator. Google patched 370 security issues in Chrome, and a data-conversion library fastjson was found vulnerable with observed attacks. Apple shipped iOS 26.6 and iPadOS 26.6 containing fixes for 87 vulnerabilities, and Cisco warned that its Firewall Management Center is already being exploited. Additional patches addressed OpenAM, Node.js, and a critical flaw dubbed KindaRails2Shell in Ruby on Rails. The list also includes a breach at an ANA Group e-commerce site that may have exposed customer data.