ELEVATED 5 min read 2 Aug 2026

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction Leads Today's Security Review

Executive assessment Today's brief leads with Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction. All 7 selected findings retain their own technical scope, action, observed status, and evidence limits.

Key findings
01
Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
CRITICAL
Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution.
02
CVE-2026-53609: Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch…
CRITICAL
Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass CVE coverage: CVE-2026-53609. Sources: - https://github.com/advisories/GHSA-6h5j-32cf-4253
03
Still active: Multiple vulnerabilities in Phoenix Contact CHARX
CRITICAL
First reported 2026-07-31; ongoing coverage. CVE coverage: CVE-2026-44095, CVE-2026-44101, CVE-2026-41032, CVE-2026-44094, CVE-2026-44097, CVE-2026-44093, CVE-2026-44096, CVE-2026-44105, CVE-2026-44106, CVE-2026-44090, CVE-2026-44100, CVE-2026-44107, CVE-2026-44092, CVE-2026-44108.
04
Still active: Multiple vulnerabilities in Phoenix Contact CHARX SEC-3150
CRITICAL
First reported 2026-08-01; ongoing coverage. CVE coverage: CVE-2026-44103, CVE-2026-44099, CVE-2026-44091, CVE-2026-44098, CVE-2026-44104, CVE-2026-7849.
05
Still active: CVE-2026-65835: Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Gen…
MEDIUM
First reported 2026-08-01; ongoing coverage. Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation) CVE coverage: CVE-2026-65835, CVE-2026-22872.
06
Still active: Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation
INFO
First reported 2026-07-31; ongoing coverage. The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another vulnerability, this time in Microsoft Outlook Web Access (OWA), to target U.S.
07
Still active: Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents
INFO
First reported 2026-07-31; ongoing coverage. Hidden instructions in a Word document can make Microsoft 365 Copilot rewrite figures in a report, then copy the same instructions into the finished file. Håkon Måløy disclosed the technique on July 28, 144 days after reporting it to Microsoft.

Executive assessment

Today's brief leads with Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction. All 7 selected findings retain their own technical scope, action, observed status, and evidence limits.

Finding 01 — Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

What changed: Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system.

Technical evidence: CVE-2026-48449; CVSS v3.1 10; weakness ['CWE-863']; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-48449 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: thehackernews.com](<https://thehackernews.com/2026/08/adobe-campaign-classic-cvss-100-flaw.html>)

Finding 02 — CVE-2026-53609: Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch…

What changed: Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass CVE coverage: CVE-2026-53609. Sources: - https://github.com/advisories/GHSA-6h5j-32cf-4253

Technical evidence: CVE-2026-53609; CVSS v3.1 9.1; weakness ['CWE-1321']; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-53609 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: github.com](<https://github.com/advisories/GHSA-6h5j-32cf-4253>)

Finding 03 — Still active: Multiple vulnerabilities in Phoenix Contact CHARX

Coverage status: First reported 2026-07-31; ongoing coverage.

What changed: CVE coverage: CVE-2026-44095, CVE-2026-44101, CVE-2026-41032, CVE-2026-44094, CVE-2026-44097, CVE-2026-44093, CVE-2026-44096, CVE-2026-44105, CVE-2026-44106, CVE-2026-44090, CVE-2026-44100, CVE-2026-44107, CVE-2026-44092, CVE-2026-44108. The cited advisories disclose: SEC-3000 Command Injection Remote Code Execution Vulnerability; SEC-3150 OCPP Missing Authentication for Critical Function Authentication Bypass Vulnerability; SEC-3000 Insertion of Sensitive Information into Log File Information Disclosure Vulnerability; SEC-3150 Failing Open Authentication Bypass Vulnerability; SEC-3150 update2-upload Arbitrary File Upload Vulnerability; SEC-3150 user-applications Symlink Following Local Privilege Escalation Vulnerability; SEC-3150 Privilege Defined With Unsafe Actions Local Privilege Escalation Vulnerability; SEC-3150 Insertion of Sensitive Information into Log File Authentication Bypass Vulnerability; SEC-3150 user-applications Link Following Local Privilege Escalation Vulnerability; SEC-3150 ModBus Server Exposed Dangerous Function Denial-of-Service Vulnerability; SEC-3150 charx-jupicore Missing Authentication Configuration Modification Vulnerability; SEC-3150 ModBus Server Exposed Dangerous Function Denial-of-Service Vulnerability; SEC-3150 charx-system-config-manager Service CRLF Injection Firewall Bypass Vulnerability; SEC-3150 Race Condition Firewall Bypass Vulnerability.

Technical evidence: CVE-2026-44101; CVSS v4.0 9.3; weakness ['CWE-306']; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-44101 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: www.zerodayinitiative.com](<http://www.zerodayinitiative.com/advisories/ZDI-26-521/>)

Finding 04 — Still active: Multiple vulnerabilities in Phoenix Contact CHARX SEC-3150

Coverage status: First reported 2026-08-01; ongoing coverage.

What changed: CVE coverage: CVE-2026-44103, CVE-2026-44099, CVE-2026-44091, CVE-2026-44098, CVE-2026-44104, CVE-2026-7849. The cited advisories disclose: Jupicore External Control of Path Remote Code Execution Vulnerability; CharxSystemConfigManager Configuration Injection Remote Code Execution Vulnerability; MQTT Service Server-Side Request Forgery Remote Code Execution Vulnerability; BackendURL WebSocket Command Injection Remote Code Execution Vulnerability; Missing Cryptographic Signature Remote Code Execution Vulnerability; CharxSystemConfigManager Configuration Injection Remote Code Execution Vulnerability.

Technical evidence: CVE-2026-44104; CVSS v4.0 9.3; weakness ['CWE-347']; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-44104 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: www.zerodayinitiative.com](<http://www.zerodayinitiative.com/advisories/ZDI-26-520/>)

Finding 05 — Still active: CVE-2026-65835: Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Gen…

Coverage status: First reported 2026-08-01; ongoing coverage.

What changed: Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation) CVE coverage: CVE-2026-65835, CVE-2026-22872. Sources: - https://github.com/advisories/GHSA-jr6p-8pjj-mfx6

Technical evidence: CVE-2026-65835; CVSS v3.1 6.6; weakness ['CWE-269', 'CWE-863']; technical confidence High.

Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-65835 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: github.com](<https://github.com/advisories/GHSA-jr6p-8pjj-mfx6>)

Finding 06 — Still active: Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation

Coverage status: First reported 2026-07-31; ongoing coverage.

What changed: The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another vulnerability, this time in Microsoft Outlook Web Access (OWA), to target U.S. and European government entities, as well as the telecommunications, financial, hospitality, and aerospace sectors.

Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.

Observed status: The cited source reports active in-the-wild exploitation; independent corroboration (CISA KEV or grounded vendor data) is not yet available.

Action: Review the cited source, validate exposure of the affected technology in owned environments, apply available vendor guidance, and retain evidence of the exposure decision.

Evidence limits: grounded severity unavailable

exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: thehackernews.com](<https://thehackernews.com/2026/07/russian-hackers-exploit-microsoft-owa.html>)

Finding 07 — Still active: Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents

Coverage status: First reported 2026-07-31; ongoing coverage.

What changed: Hidden instructions in a Word document can make Microsoft 365 Copilot rewrite figures in a report, then copy the same instructions into the finished file. Håkon Måløy disclosed the technique on July 28, 144 days after reporting it to Microsoft.

Why it matters: Public exploit code is available, so weaponisation is low-effort; prioritise exposure validation and patching ahead of routine cycles.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Review the cited source, validate exposure of the affected technology in owned environments, apply available vendor guidance, and retain evidence of the exposure decision.

Evidence limits: grounded severity unavailable

exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: thehackernews.com](<https://thehackernews.com/2026/07/microsoft-copilot-for-word-can-copy.html>)

cve-2026-44095cve-2026-44103cve-2026-48449cve-2026-53609cve-2026-65835

Act on this brief

Map detection coverage gaps for the techniques above, or generate Sigma rules from the named CVEs.