August 2026 Patch TuesdayAPSB26-123Normal patch window

Adobe · APSB26-123

APSB26-123 official advisory and patch guidance

Adobe published APSB26-123 on Patch Tuesday for Adobe Campaign Classic. The bulletin links 3 CVEs and provides fixed release guidance.

Product
Adobe Campaign Classic
Release
ACC v7 7.4.4 build 9400
Published
2026-08-11
Updated
2026-08-11
Cycle
August 2026 Patch Tuesday
Normal patch windowBlackTree recommended timinghigh confidence
3Vendor-linked CVEsComplete For Advisory
1Preserved revisionsCanonical history remains visible
0Known issuesVendor-documented context only

Archived official source

APSB26-123 official vendor article

BlackTree retains a versioned copy of the official Adobe article for evidence. These facts do not prove that this update fixes every linked product or CVE.

Official article
Security update available for Adobe Campaign Classic | APSB26-123 ↗
CVEs named in article
CVE-2026-71398, CVE-2026-27302, CVE-2026-48381
Snapshot
Captured 26 Sept 2026, 20:28 UTC.

Action and evidence

Operational decision

Action type
Upgrade Release
Platform
Windows, Linux
Restart
unknown
Vendor signal
Critical; CVSS 10.0; Adobe priority 1

Why this urgency

  • Fix Available
  • Routine Review

Evidence signals kept separate

CISA KEV
Unknown
Confirmed exploitation
Not Stated
Vendor exploitability
Not stated in the reviewed source
Maximum CVSS
10.0 (CVSS 3.1, CVE-2026-71398)
Maximum EPSS
Not loaded for this patch record
Normal patch window

BlackTree recommends the normal approved patch window. No accepted exploitation or emergency signal currently justifies an out-of-band change by itself.

BlackTree urgency is an operational review window. It does not replace vendor severity or CVSS.

Environment override questions

  • Is Adobe Campaign Classic exposed to untrusted networks or content?
  • Does this update affect an identity, management, backup or other control-plane system?
  • Are compensating controls tested and monitored until the selected patch window?

Deployment context

Effects and caveats

  • Use the vendor update path and test the fixed release against managed plug-ins, workflows and file formats before broad deployment.

Known data gaps

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.

Deployment plan

Guidance basis: Blacktree Generic

Prerequisites

  • Confirm the affected product, edition, architecture and current build before deployment.

Sequencing

  • Test the update in a representative ring before broad deployment.

Downtime

Downtime and restart impact are not fully stated in the reviewed public source.

Rollback and recovery

  • Capture the current version and a recoverable backup or snapshot before the change.
  • Use the vendor-supported uninstall or recovery path when one is available.

Workarounds

  • No vendor workaround is asserted unless it appears in the official advisory.

Vulnerability relationships

Vendor-linked CVEs

The list matches the public CVE identifiers in the reviewed advisory.

Linked CVEs
3
Confirmed exploited
0
PoC or lab evidence
0
Maximum CVSS
10.0
Open linked CVE review

Provenance

Field verification

  • Advisory_identity_and_releaseadobe-bulletin/solutionVerified Automatic · Retrieved 25 Aug 2026, 19:50 UTC
  • Cve_relationshipsadobe-bulletin/vulnerability-detailsVerified Automatic · Retrieved 25 Aug 2026, 19:50 UTC
Open official vendor source

Revision history

Canonical record changes

  1. Revision 12026-08-11

    Initial APSB26-123 publication.

Publication review

The bulletin identity, release date, fixed versions, platforms, vendor signals and complete public CVE list were generated from the official Adobe bulletin and passed structural validation. The project owner approved automatic Patch Tuesday publication. Each published record passed its own official-source completeness gate. Pending sources expose readiness only and prior approved records are retained on refresh failure.