
[CIAD-2026-0031] Multiple Vulnerabilities in Adobe Products
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in Adobe Products
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: High
Software Affected
Adobe Experience Manager (AEM) Cloud Service (CS) prior to release 2026.05, 6.5 LTS SP1 and earlier, SP24 and earlier
Adobe Experience Manager Forms AEM 6.5.24.0 and earlier
Adobe InDesign ID21.3 and earlier versions, ID20.5.3 and earlier versions
Adobe InCopy 21.3 and earlier versions, 20.5.3 and earlier versions
Adobe Substance 3D Sampler 6.0.0 and earlier versions
Adobe Content Credentials SDK @contentauth/c2pa-web@0.7.1 and earlier, c2pa-v0.80.1 and earlier
Adobe Dreamweaver 21.7 and earlier versions
Adobe Acrobat Reader in Adobe Acrobat and Acrobat Reader 26.001.21651 and earlier, and in Acrobat 2024 Classic 2024 24.001.30365 and earlier
Adobe ColdFusion Update 8 and earlier versions, Update 19 and earlier versions
Adobe Format Plugins 1.1.2 and earlier versions
Adobe Campaign Classic ACC v7: 7.4.3 build 9394 and earlier
Overview
Multiple vulnerabilities have been reported in Adobe products, which could be exploited by an attacker to execute arbitrary code, gain elevated privileges, bypass security restrictions, gain access to sensitive information, manipulate application functionality, or cause denial of service (DoS) conditions on the targeted system.
Target Audience:
Individuals, organizations, IT administrators, developers, end users, and security teams responsible for maintaining and securing Adobe products.
Risk Assessment:
High risk of complete system compromise, unauthorized access to sensitive information, privilege escalation, and disruption of services.
Impact Assessment:
Potential for complete system compromise.
Description
Multiple vulnerabilities have been reported in various Adobe products. These vulnerabilities exist due to improper input validation, cross-site scripting (DOM-based, reflected and stored XSS) issues, memory corruption issues, incorrect authorization, and supply chain related issues.
An attacker could exploit these vulnerabilities by convincing a user to open a specially crafted file. Successful exploitation could allow and attacker to execute arbitrary code, gain elevated privileges, bypass security restrictions, gain access to sensitive information, manipulate application functionality, or cause denial of service (DoS) conditions on the targeted system.
For complete list of affected products, CVEs, workarounds and solutions, refer to the Adobe security updates:
https://helpx.adobe.com/security/products/experience-manager/apsb26-56.html
https://helpx.adobe.com/security/products/aem-forms/apsb26-57.html
https://helpx.adobe.com/security/products/indesign/apsb26-58.html
https://helpx.adobe.com/security/products/incopy/apsb26-59.html
https://helpx.adobe.com/security/products/substance3d-sampler/apsb26-60.html
https://helpx.adobe.com/security/products/content-authenticity-sdk/apsb26-61.html
https://helpx.adobe.com/security/products/dreamweaver/apsb26-62.html
https://helpx.adobe.com/security/products/acrobat/apsb26-63.html
https://helpx.adobe.com/security/products/coldfusion/apsb26-64.html
https://helpx.adobe.com/security/products/formatplugins/apsb26-65.html
https://helpx.adobe.com/security/products/campaign/apsb26-66.html
Solution
Apply appropriate security updates as mentioned in Adobe Security Bulletin:
https://helpx.adobe.com/security/products/experience-manager/apsb26-56.html
https://helpx.adobe.com/security/products/aem-forms/apsb26-57.html
https://helpx.adobe.com/security/products/indesign/apsb26-58.html
https://helpx.adobe.com/security/products/incopy/apsb26-59.html
https://helpx.adobe.com/security/products/substance3d-sampler/apsb26-60.html
https://helpx.adobe.com/security/products/content-authenticity-sdk/apsb26-61.html
https://helpx.adobe.com/security/products/dreamweaver/apsb26-62.html
https://helpx.adobe.com/security/products/acrobat/apsb26-63.html
https://helpx.adobe.com/security/products/coldfusion/apsb26-64.html
https://helpx.adobe.com/security/products/formatplugins/apsb26-65.html
https://helpx.adobe.com/security/products/campaign/apsb26-66.html
Vendor Information
Adobe
https://helpx.adobe.com/security.html
References
https://helpx.adobe.com/security/products/experience-manager/apsb26-56.html
https://helpx.adobe.com/security/products/aem-forms/apsb26-57.html
https://helpx.adobe.com/security/products/indesign/apsb26-58.html
https://helpx.adobe.com/security/products/incopy/apsb26-59.html
https://helpx.adobe.com/security/products/substance3d-sampler/apsb26-60.html
https://helpx.adobe.com/security/products/content-authenticity-sdk/apsb26-61.html
https://helpx.adobe.com/security/products/dreamweaver/apsb26-62.html
https://helpx.adobe.com/security/products/acrobat/apsb26-63.html
https://helpx.adobe.com/security/products/coldfusion/apsb26-64.html
https://helpx.adobe.com/security/products/formatplugins/apsb26-65.html
https://helpx.adobe.com/security/products/campaign/apsb26-66.html
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmoru4UACgkQ3jCgcSdc
ys8hwA//QHGLbxjGYeWAtIhTSJ1xFdNlIinas8bwhrNUQlKwS+l8xSf4gf745RDb
kAZz4QZ40dk0X/1SHp1q3cgH5UgSkwXXGITvCg0zuBRyUVDHtGlERKWkWrT80cKI
bzGoBMVTxqeLUVCKpwXsJRBYT3rWR6x3m8txKxWCAPYl1FFwfMJPzy/S6rOfJ24s
p7HhIhdwYUxllQWdr2jUDWIADgmdIsoFle8x1UiwmLj8hS88AA7w1pZMQS47STif
59u1VGFBgP0rI4Kc2lk6Ok00rktfP0pp8Gvn4I3BUW0hIv7oAmMbZ+BXYGlV32Ar
s5CTib8bQthXa743meGYoC6zcv3pljB2+YzuBue9WVSejtcPk+IYMeFdSUsGdYd7
IQWxsFuDkr+oOZcJi1k07CVSGwRI77m7Sn7/WmTRyaaw8p8S2UgKJE9xO1dIhM8p
zUJ5jwZcNxD3Km5rb9FLAW97xLSEFZSVyjaJaf5pmcpkuSD1uI9iFZfWMfFNXk75
x41Zs8UDDdpXCbu0t+Qb91Q9sQl/TpUnv+pg6GBzcgMDJndSdxsmuGloiwoVNenp
PktzW9ESQkJdr4R8hQkEH62zriUGSzCjku08SZ3zYloc42YWrW8ranDk+c2JUwYl
2YAtgxWiZabHjszL5TvfD+NKBQ1/+QApkv/HQRpbNqkKZnnObV4=
=cDtR
—–END PGP SIGNATURE—–


