
[CIVN-2026-0432] Multiple vulnerabilities in Adobe products
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple vulnerabilities in Adobe products
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: CRITICAL
Software Affected
Adobe Content Credentials Rust SDK versions c2pa-v0.89.0 and earlier
Adobe C2PA Tool versions c2patool-v0.26.70 and earlier
Adobe Substance 3D Designer versions 16.0.4 and earlier
Adobe Substance 3D Sampler versions 6.0.1 and earlier
Adobe Substance 3D Painter versions 12.1.2 and earlier
Adobe Illustrator 2025 versions 29.8.9 and earlier for Windows
Adobe Illustrator 2026 versions 30.6 and earlier for Windows
Adobe XD versions 60 and earlier for Windows and macOS
Adobe Campaign Classic ACC v7 versions 7.4.4 build 9400 and earlier for Windows and Linux
Overview
Multiple vulnerabilities have been reported in Adobe products, which could allow an attacker to execute arbitrary code, trigger denial of service conditions, disclose sensitive information, expose memory contents, or read arbitrary files from the targeted system.
Target Audience:
All end-user organisations and individuals using affected Adobe products.
Impact Assessment:
Potential for arbitrary code execution, denial of service, arbitrary file-system read, memory exposure, and compromise of the affected system.
Risk Assessment:
Critical risk of arbitrary code execution, unauthorized access, information disclosure, service disruption, and system compromise.
Description
Adobe provides a range of software products for digital content creation, 3D design and content creation, graphic design, user experience design, content authenticity, and marketing campaign management.
Multiple vulnerabilities exist in Adobe products due to uncontrolled resource consumption, improper input validation, heap-based buffer overflow, stack-based buffer overflow, out-of-bounds read, out-of-bounds write, NULL pointer dereference, improper neutralization of special elements used in OS commands, and server-side request forgery.
Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary code, trigger denial of service conditions, disclose sensitive information, expose memory contents, or read arbitrary files from the targeted system.
Solution
Apply appropriate updates as mentioned by the vendor given below:
https://helpx.adobe.com/security/products/content-authenticity-sdk/apsb26-110.html
https://helpx.adobe.com/security/products/substance3d_designer/apsb26-115.html
https://helpx.adobe.com/security/products/substance3d-sampler/apsb26-121.html
https://helpx.adobe.com/security/products/illustrator/apsb26-124.html
https://helpx.adobe.com/security/products/xd/apsb26-125.html
https://helpx.adobe.com/security/products/substance3d_painter/apsb26-129.html
https://helpx.adobe.com/security/products/campaign/apsb26-134.html
Vendor Information
Adobe
https://www.adobe.com
References
Adobe
https://helpx.adobe.com/security/products/content-authenticity-sdk/apsb26-110.html
https://helpx.adobe.com/security/products/substance3d_designer/apsb26-115.html
https://helpx.adobe.com/security/products/substance3d-sampler/apsb26-121.html
https://helpx.adobe.com/security/products/illustrator/apsb26-124.html
https://helpx.adobe.com/security/products/xd/apsb26-125.html
https://helpx.adobe.com/security/products/substance3d_painter/apsb26-129.html
https://helpx.adobe.com/security/products/campaign/apsb26-134.html
CVE Name
CVE-2026-71360
CVE-2026-71443
CVE-2026-71442
CVE-2026-71444
CVE-2026-76189
CVE-2026-76198
CVE-2026-48433
CVE-2026-48432
CVE-2026-48431
CVE-2026-48430
CVE-2026-48428
CVE-2026-48427
CVE-2026-71564
CVE-2026-48426
CVE-2026-48429
CVE-2026-48424
CVE-2026-48425
CVE-2026-48423
CVE-2026-48422
CVE-2026-48421
CVE-2026-48420
CVE-2026-48420
CVE-2026-48419
CVE-2026-48418
CVE-2026-48417
CVE-2026-71382
CVE-2026-71441
CVE-2026-71399
CVE-2026-75770
CVE-2026-75769
CVE-2026-75768
CVE-2026-75767
CVE-2026-75766
CVE-2026-75750
CVE-2026-75749
CVE-2026-75752
CVE-2026-76197
CVE-2026-76195
CVE-2026-76193
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqYKbYACgkQ3jCgcSdc
ys8t9g//UyNJcuIamoZxlaKJtzELPH6WkXdxXqytlpa2iOziULbDlI8Gbij3rr31
bsMLPSkboHhXMow0A/1tFez+KJso5tTL097g9MqiDUpZ2m5Nr+GgEJHc1HGDfIAs
VgLuJVem0rJgqzfsMq3qDxYtzkyH2Z2lT6vSuKgD235VCanU5Sfg+xjGEi6/vIJv
VNqrlY2VfFNm2txhEvP35oLvZxvXs61/McLxKYLbplK0M/17ENgO5EPpVelrEVgo
oAzoW5NIfm1NfEIiJ0+t89SLCVafaQ3fd0bcuIUv2yE4E64fhAQTYt6XMfH+05oS
tbIpFHBy5gGSV67iy4RNuaKtXH1e5WA8wzRyipwhUz3bifnqxTSjJzntMTj7xxU8
vMjThjIRlgvueDgKdtAqcfQVEnMLQDc6KegkFoF8rrltMWde7/wPMJJ5+ZtmRp0A
zD05vIQKVbA+oGx5OZKc1V7khMsWRKL2+ehkL/H2+tkuBUlPIhDyUIbTlV+sN7g1
ky1SVVKWsM8RSyRVDza1Fa97tGB+s7JW80ck31s0oNNyi+LKmmkAafhTnERMTgVG
LqzC5qTJoROVW18Ye/uAfObqSXgp4J10HgRp2Ru0but/oRUmcacqiUrozRfYpL9r
kaT9e5fFxHcM20RWpXFJ+4m65qmeVVj9FS1YLRoyvsg0f5Ia70Y=
=rs/Q
—–END PGP SIGNATURE—–


