September 2026 Patch TuesdayAPSB26-142Accelerated, within 72 hours
Adobe · APSB26-142
APSB26-142 official advisory and patch guidance
Adobe published APSB26-142 on Patch Tuesday for Adobe Campaign Classic. The bulletin links 1 CVE and provides fixed release guidance.
- Product
- Adobe Campaign Classic
- Release
- ACC v7 7.4.4 build 9402
- Published
- 2026-09-08
- Updated
- 2026-09-08
Accelerated, within 72 hoursBlackTree recommended timinghigh confidence
1Vendor-linked CVEsComplete For Advisory
2Preserved revisionsCanonical history remains visible
0Known issuesVendor-documented context only
- CVEs named in article
- CVE-2026-82004, CVE-2026-73369, CVE-2026-84412, CVE-2026-89275, CVE-2026-75723, CVE-2026-75699, CVE-2026-75703, CVE-2026-75721, CVE-2026-89276, CVE-2026-82008, CVE-2026-82003, CVE-2026-83660, CVE-2026-82010, CVE-2026-82013, CVE-2026-82443, CVE-2026-75728, CVE-2026-82011, CVE-2026-82009
- Snapshot
- Captured 27 Sept 2026, 20:00 UTC.
Action and evidence
Operational decision
- Action type
- Upgrade Release
- Platform
- Windows, Linux
- Restart
- unknown
- Vendor signal
- Critical; CVSS 10.0; Adobe priority 1
Why this urgency
- Fix Available
- Vendor Accelerated Guidance
Evidence signals kept separate
- CISA KEV
- Unknown
- Confirmed exploitation
- Not Stated
- Vendor exploitability
- Not stated in the reviewed source
- Maximum CVSS
- 10.0 (CVSS 3.1, CVE-2026-82004)
- Maximum EPSS
- Not loaded for this patch record
Accelerated, within 72 hoursBlackTree recommends an accelerated change within 72 hours when this update applies. Use an earlier controlled window than the routine schedule.
BlackTree urgency is an operational review window. It does not replace vendor severity or CVSS.
Environment override questions
- Is Adobe Campaign Classic exposed to untrusted networks or content?
- Does this update affect an identity, management, backup or other control-plane system?
- Are compensating controls tested and monitored until the selected patch window?
Deployment context
Effects and caveats
- Adobe Priority 1 recommends installation as soon as possible, with 72 hours as an example.
- Use the vendor update path and test the fixed release against managed plug-ins, workflows and file formats before broad deployment.
Known data gaps
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
- Adobe Priority 1 applies to the bulletin; it does not confirm exploitation of every linked CVE.
Deployment plan
Guidance basis: Blacktree Generic
Prerequisites
- Confirm the affected product, edition, architecture and current build before deployment.
Sequencing
- Test the update in a representative deployment ring before broad release.
Downtime
Downtime and restart impact are not fully stated in the reviewed public source.
Rollback and recovery
- Capture the current version and a recoverable backup or snapshot before the change.
- Use the vendor-supported uninstall or recovery path when one is available.
Workarounds
- No vendor workaround is asserted unless it appears in the official advisory.
Provenance
Field verification
- Advisory_identity_and_releaseadobe-bulletin/solutionVerified Automatic · Retrieved 14 Sept 2026, 22:19 UTC
- Cve_relationshipsadobe-bulletin/vulnerability-detailsVerified Automatic · Retrieved 14 Sept 2026, 22:19 UTC
Open official vendor sourceRevision history
Canonical record changes
- Revision 12026-09-08
Initial publication of APSB26-142.
- Revision 22026-09-08
Material official-source change detected in: data_gaps, deployment_effects, urgency.
RevisedThis record has a material revision or correction state. Review the timeline and official source before deployment.
Publication review
The bulletin identity, release date, fixed versions, platforms, vendor signals and complete public CVE list were generated from the official Adobe bulletin and passed structural validation. The project owner approved automatic Patch Tuesday publication. Each published record passed its own official-source completeness gate. Pending sources expose readiness only and prior approved records are retained on refresh failure.