Vulnerabilities are always being discovered and the issue seems to be with a third-party library called Tidy. Apparently this library randomly doesn't patch URLs correctly which might lead to the security vulnerability (open redirect hijack / phishing).
Hard to tell if this is a new issue with no patch or its an legacy issue that was just discovered or just that Campaign uses a legacy version with the vulnerability that was eventually patched. Either way, the recommendation is not to encode hostnames in your personalised URLs.
I would say the fact that we all got an important email was this was just discovered or just exploited in the wild, but that's just speculation. The email was worded carefully "...Adobe is currently not aware of any threat actor having used this attack method in connection with your Campaign Classic instance..."
Adobe security bulletins and CVE database listings don't show anything new