[CIVN-2026-0458] Multiple Vulnerabilities in Adobe Products

By Published On: September 17, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Multiple Vulnerabilities in Adobe Products


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: CRITICAL


Software Affected


Adobe Experience Manager (AEM) Cloud Service (CS) Release 2026.7.0 and earlier versions.

Adobe Experience Manager (AEM) 6.5 LTS Service Pack 2 and earlier versions.

Adobe Experience Manager (AEM) 6.5 Service Pack 24 and earlier versions.

Adobe ColdFusion 2025 version 2025.0.12 and earlier versions.

Adobe ColdFusion 2023 version 2023.0.23 and earlier versions.

Adobe Photoshop 2026 version 27.6 and earlier versions for Windows and macOS.

Adobe Photoshop 2025 version 26.11.6 and earlier versions for Windows and macOS.

Adobe Illustrator 2025 version 29.8.10 and earlier versions for Windows.

Adobe Illustrator 2026 version 30.7 and earlier versions for Windows.

Adobe Animate 2023 version 23.0.16 and earlier versions for Windows and macOS.

Adobe Animate 2024 version 24.0.14 and earlier versions for Windows and macOS.

Adobe Photoshop Mobile version 1.6.0.2299 and earlier versions for Android.

Adobe Commerce 2.4.9-2026-aug and earlier versions, 2.4.8-2026-aug and earlier versions, 2.4.7-2026-aug and earlier versions, 2.4.6-2026-aug and earlier versions, 2.4.5-2026-aug and earlier versions, and 2.4.4-2026-aug and earlier versions.

Adobe Commerce B2B 1.5.3-2026-aug and earlier versions, 1.5.2-2026-aug and earlier versions, 1.4.2-2026-aug and earlier versions, 1.3.4-2026-aug and earlier versions, and 1.3.3-2026-aug and earlier versions.

Magento Open Source 2.4.9-2026-aug and earlier versions, 2.4.8-2026-aug and earlier versions, 2.4.7-2026-aug and earlier versions, and 2.4.6-2026-aug and earlier versions.

Adobe Acrobat Continuous 26.002.21900 and earlier versions for Windows and macOS.

Acrobat Reader Continuous 26.002.21900 and earlier versions for Windows and macOS.

Acrobat 2024 Classic 2024 version 24.001.30383 and earlier versions for Windows and macOS.

Adobe Campaign Classic ACC v7 version 7.4.4 build 9401 and earlier versions for Windows and Linux.

Overview


Multiple vulnerabilities have been reported in various Adobe products which could allow attackers to execute arbitrary code, escalate privileges, bypass security restrictions, disclose sensitive information, access or modify files, or cause denial-of-service (DoS) conditions on affected systems.


Target Audience:

All end-user organizations and individuals using affected Adobe products.


Risk Assessment:

Critical risk of arbitrary code execution, privilege escalation, security feature bypass, sensitive information disclosure and compromise of affected systems.


Impact Assessment:

Potential for arbitrary code execution, privilege escalation, unauthorized access to or modification of sensitive information and files, security feature bypass and denial-of-service (DoS) conditions.


Description


Adobe Experience Manager, ColdFusion, Photoshop, Illustrator, Animate, Photoshop Mobile, Adobe Commerce, Magento Open Source, Acrobat, Acrobat Reader and Campaign Classic are software products used for content management, application development, digital content creation, image editing, document processing, e-commerce and marketing operations.


Multiple vulnerabilities have been identified in the affected Adobe products, including improper authorization, cross-site scripting (XSS), improper input validation, code injection, SQL injection, path traversal, out-of-bounds memory access, use-after-free, prototype pollution, integer overflow, heap-based buffer overflow, improper access control, uncontrolled resource consumption and OS command injection vulnerabilities. These vulnerabilities could be exploited through specially crafted requests, files, inputs or application interactions, depending on the affected product and vulnerability.


Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary code, escalate privileges, bypass security restrictions, access or modify files, disclose sensitive information or cause denial-of-service (DoS) conditions. Notably, CVE-2026-75650 affecting Adobe Commerce, Adobe Commerce B2B and Magento Open Source is a critical remote code execution vulnerability that can be exploited by an unauthenticated remote attacker to execute arbitrary code on a vulnerable server.


NOTE: Adobe has confirmed that CVE-2026-75650 is being exploited in the wild.


Solution


Apply appropriate updates as mentioned as mentioned by the Vendor:

https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html


https://helpx.adobe.com/security/products/coldfusion/apsb26-119.html


https://helpx.adobe.com/security/products/photoshop/apsb26-130.html


https://helpx.adobe.com/security/products/illustrator/apsb26-131.html


https://helpx.adobe.com/security/products/animate/apsb26-132.html


https://helpx.adobe.com/security/products/photoshop-mobile/apsb26-136.html


https://helpx.adobe.com/security/products/magento/apsb26-138.html


https://helpx.adobe.com/security/products/acrobat/apsb26-141.html


https://helpx.adobe.com/security/products/campaign/apsb26-142.html


https://helpx.adobe.com/security/products/magento/apsb26-146.html



Vendor Information


Adobe

https://helpx.adobe.com/security.html


References


 

https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html

https://helpx.adobe.com/security/products/coldfusion/apsb26-119.html

https://helpx.adobe.com/security/products/photoshop/apsb26-130.html

https://helpx.adobe.com/security/products/illustrator/apsb26-131.html

https://helpx.adobe.com/security/products/animate/apsb26-132.html

https://helpx.adobe.com/security/products/photoshop-mobile/apsb26-136.html

https://helpx.adobe.com/security/products/magento/apsb26-138.html

https://helpx.adobe.com/security/products/acrobat/apsb26-141.html

https://helpx.adobe.com/security/products/campaign/apsb26-142.html

https://helpx.adobe.com/security/products/magento/apsb26-146.html


CVE Name

CVE-2025-64542

CVE-2025-64584

CVE-2025-64588

CVE-2025-64589

CVE-2025-64610

CVE-2025-64618

CVE-2025-64830

CVE-2025-64838

CVE-2025-64854

CVE-2025-64866

CVE-2025-64868

CVE-2026-19232

CVE-2026-19479

CVE-2026-19612

CVE-2026-19644

CVE-2026-19713

CVE-2026-21269

CVE-2026-27222

CVE-2026-27227

CVE-2026-27238

CVE-2026-27258

CVE-2026-48273

CVE-2026-71356

CVE-2026-71357

CVE-2026-71388

CVE-2026-71440

CVE-2026-71565

CVE-2026-72626

CVE-2026-72627

CVE-2026-75629

CVE-2026-75631

CVE-2026-75635

CVE-2026-75636

CVE-2026-75637

CVE-2026-75639

CVE-2026-75640

CVE-2026-75642

CVE-2026-75643

CVE-2026-75644

CVE-2026-75646

CVE-2026-75647

CVE-2026-75650

CVE-2026-75651

CVE-2026-75652

CVE-2026-75657

CVE-2026-75659

CVE-2026-75660

CVE-2026-75661

CVE-2026-75666

CVE-2026-75667

CVE-2026-75668

CVE-2026-75669

CVE-2026-75670

CVE-2026-75671

CVE-2026-75672

CVE-2026-75674

CVE-2026-75675

CVE-2026-75677

CVE-2026-75678

CVE-2026-75679

CVE-2026-75680

CVE-2026-75681

CVE-2026-75683

CVE-2026-75685

CVE-2026-75687

CVE-2026-75690

CVE-2026-75691

CVE-2026-75692

CVE-2026-75693

CVE-2026-75694

CVE-2026-75695

CVE-2026-75696

CVE-2026-75700

CVE-2026-75701

CVE-2026-75706

CVE-2026-75708

CVE-2026-75709

CVE-2026-75710

CVE-2026-75711

CVE-2026-75713

CVE-2026-75715

CVE-2026-75717

CVE-2026-75719

CVE-2026-75720

CVE-2026-75722

CVE-2026-75724

CVE-2026-75726

CVE-2026-75729

CVE-2026-75731

CVE-2026-75734

CVE-2026-75736

CVE-2026-75738

CVE-2026-75740

CVE-2026-75742

CVE-2026-75746

CVE-2026-75771

CVE-2026-75862

CVE-2026-75990

CVE-2026-75992

CVE-2026-75998

CVE-2026-76000

CVE-2026-81985

CVE-2026-81987

CVE-2026-81989

CVE-2026-81991

CVE-2026-81993

CVE-2026-81994

CVE-2026-81996

CVE-2026-81997

CVE-2026-82001

CVE-2026-82004

CVE-2026-82004

CVE-2026-82005

CVE-2026-82006

CVE-2026-82007




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqr6VAACgkQ3jCgcSdc

ys9IwhAAoJnuMsFGqLXkG7/QKdb3+3KJXEIzzsqWCNRaV/A9gZhJCKrdk8IaF4af

wm7wHgIjDqD4IuFuPC2OULKxWyuys/vda1rt7rUxrdrjzNJkqwvmRsSP3jtSX1Ww

iOf8tx0u0P9FWlBztzOBSu5IA9aHnKNVLJ4+WUb3n4wC5+2Vjp6RAv82AAeewdQN

EV6QwaWb1+CIEhJAHiT2SX/VFzKhnOt1vOrDzbctyBhXEEt97LMetxHgRxbpwr7g

e9I2P/00lb8t0Dn51zNldX/+1ROkDfwQxtzdeJZfnn8/nm3e0bTllEs4swcWrbqu

hU6AjnkV+4bH+4PZJodvqbgW9IBecX307vXp/mwnjjTpbdKhYOuVyFaQzF38h9WY

UmKoHy7hA8IXVTful2MvY8R5ZXpudkyBy0fksKmu34rB6MnUlv1N+4S+tQB0nDte

DDVORUrQDN6Yj82CLgmgZaCJ2GMpnJjNa1uiXOBgSW9OMb0jPPbzLPQ5qKgiyyJ9

Er/82pnHTcVLHuGYpyviohI8l9ZpTHEZEJmdu0SFDB21gYn63VZtEdckCd3COTo6

xOTBSbBA3U1lNypHMIC1cBauvBjnLvJl8l0D7wDGEEPahZVg/PWi2yMFYT0t3d6P

3tJHD4lJjFTiqBcCT8lwTUpx33HOLJkZwHGGCdXv/DpmJfoUFwY=

=02RQ

—–END PGP SIGNATURE—–

Share this article