CERT-In Vulnerability Note
CIVN-2026-0458
Multiple Vulnerabilities in Adobe Products
Original Issue Date:September 16, 2026
Severity Rating: CRITICAL
Software Affected
- Adobe Experience Manager (AEM) Cloud Service (CS) Release 2026.7.0 and earlier versions.
- Adobe Experience Manager (AEM) 6.5 LTS Service Pack 2 and earlier versions.
- Adobe Experience Manager (AEM) 6.5 Service Pack 24 and earlier versions.
- Adobe ColdFusion 2025 version 2025.0.12 and earlier versions.
- Adobe ColdFusion 2023 version 2023.0.23 and earlier versions.
- Adobe Photoshop 2026 version 27.6 and earlier versions for Windows and macOS.
- Adobe Photoshop 2025 version 26.11.6 and earlier versions for Windows and macOS.
- Adobe Illustrator 2025 version 29.8.10 and earlier versions for Windows.
- Adobe Illustrator 2026 version 30.7 and earlier versions for Windows.
- Adobe Animate 2023 version 23.0.16 and earlier versions for Windows and macOS.
- Adobe Animate 2024 version 24.0.14 and earlier versions for Windows and macOS.
- Adobe Photoshop Mobile version 1.6.0.2299 and earlier versions for Android.
- Adobe Commerce 2.4.9-2026-aug and earlier versions, 2.4.8-2026-aug and earlier versions, 2.4.7-2026-aug and earlier versions, 2.4.6-2026-aug and earlier versions, 2.4.5-2026-aug and earlier versions, and 2.4.4-2026-aug and earlier versions.
- Adobe Commerce B2B 1.5.3-2026-aug and earlier versions, 1.5.2-2026-aug and earlier versions, 1.4.2-2026-aug and earlier versions, 1.3.4-2026-aug and earlier versions, and 1.3.3-2026-aug and earlier versions.
- Magento Open Source 2.4.9-2026-aug and earlier versions, 2.4.8-2026-aug and earlier versions, 2.4.7-2026-aug and earlier versions, and 2.4.6-2026-aug and earlier versions.
- Adobe Acrobat Continuous 26.002.21900 and earlier versions for Windows and macOS.
- Acrobat Reader Continuous 26.002.21900 and earlier versions for Windows and macOS.
- Acrobat 2024 Classic 2024 version 24.001.30383 and earlier versions for Windows and macOS.
- Adobe Campaign Classic ACC v7 version 7.4.4 build 9401 and earlier versions for Windows and Linux.
Overview
Multiple vulnerabilities have been reported in various Adobe products which could allow attackers to execute arbitrary code, escalate privileges, bypass security restrictions, disclose sensitive information, access or modify files, or cause denial-of-service (DoS) conditions on affected systems.
Target Audience: All end-user organizations and individuals using affected Adobe products.
Risk Assessment: Critical risk of arbitrary code execution, privilege escalation, security feature bypass, sensitive information disclosure and compromise of affected systems.
Impact Assessment: Potential for arbitrary code execution, privilege escalation, unauthorized access to or modification of sensitive information and files, security feature bypass and denial-of-service (DoS) conditions.
Description
Adobe Experience Manager, ColdFusion, Photoshop, Illustrator, Animate, Photoshop Mobile, Adobe Commerce, Magento Open Source, Acrobat, Acrobat Reader and Campaign Classic are software products used for content management, application development, digital content creation, image editing, document processing, e-commerce and marketing operations.
Multiple vulnerabilities have been identified in the affected Adobe products, including improper authorization, cross-site scripting (XSS), improper input validation, code injection, SQL injection, path traversal, out-of-bounds memory access, use-after-free, prototype pollution, integer overflow, heap-based buffer overflow, improper access control, uncontrolled resource consumption and OS command injection vulnerabilities. These vulnerabilities could be exploited through specially crafted requests, files, inputs or application interactions, depending on the affected product and vulnerability.
Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary code, escalate privileges, bypass security restrictions, access or modify files, disclose sensitive information or cause denial-of-service (DoS) conditions. Notably, CVE-2026-75650 affecting Adobe Commerce, Adobe Commerce B2B and Magento Open Source is a critical remote code execution vulnerability that can be exploited by an unauthenticated remote attacker to execute arbitrary code on a vulnerable server.
NOTE: Adobe has confirmed that CVE-2026-75650 is being exploited in the wild.
Solution
Apply appropriate updates as mentioned as mentioned by the Vendor:
https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html
https://helpx.adobe.com/security/products/coldfusion/apsb26-119.html
https://helpx.adobe.com/security/products/photoshop/apsb26-130.html
https://helpx.adobe.com/security/products/illustrator/apsb26-131.html
https://helpx.adobe.com/security/products/animate/apsb26-132.html
https://helpx.adobe.com/security/products/photoshop-mobile/apsb26-136.html
https://helpx.adobe.com/security/products/magento/apsb26-138.html
https://helpx.adobe.com/security/products/acrobat/apsb26-141.html
https://helpx.adobe.com/security/products/campaign/apsb26-142.html
https://helpx.adobe.com/security/products/magento/apsb26-146.html
Vendor Information
Adobe
https://helpx.adobe.com/security.html
References
https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html
https://helpx.adobe.com/security/products/coldfusion/apsb26-119.html
https://helpx.adobe.com/security/products/photoshop/apsb26-130.html
https://helpx.adobe.com/security/products/illustrator/apsb26-131.html
https://helpx.adobe.com/security/products/animate/apsb26-132.html
https://helpx.adobe.com/security/products/photoshop-mobile/apsb26-136.html
https://helpx.adobe.com/security/products/magento/apsb26-138.html
https://helpx.adobe.com/security/products/acrobat/apsb26-141.html
https://helpx.adobe.com/security/products/campaign/apsb26-142.html
https://helpx.adobe.com/security/products/magento/apsb26-146.html
CVE Name
CVE-2025-64542
CVE-2025-64584
CVE-2025-64588
CVE-2025-64589
CVE-2025-64610
CVE-2025-64618
CVE-2025-64830
CVE-2025-64838
CVE-2025-64854
CVE-2025-64866
CVE-2025-64868
CVE-2026-19232
CVE-2026-19479
CVE-2026-19612
CVE-2026-19644
CVE-2026-19713
CVE-2026-21269
CVE-2026-27222
CVE-2026-27227
CVE-2026-27238
CVE-2026-27258
CVE-2026-48273
CVE-2026-71356
CVE-2026-71357
CVE-2026-71388
CVE-2026-71440
CVE-2026-71565
CVE-2026-72626
CVE-2026-72627
CVE-2026-75629
CVE-2026-75631
CVE-2026-75635
CVE-2026-75636
CVE-2026-75637
CVE-2026-75639
CVE-2026-75640
CVE-2026-75642
CVE-2026-75643
CVE-2026-75644
CVE-2026-75646
CVE-2026-75647
CVE-2026-75650
CVE-2026-75651
CVE-2026-75652
CVE-2026-75657
CVE-2026-75659
CVE-2026-75660
CVE-2026-75661
CVE-2026-75666
CVE-2026-75667
CVE-2026-75668
CVE-2026-75669
CVE-2026-75670
CVE-2026-75671
CVE-2026-75672
CVE-2026-75674
CVE-2026-75675
CVE-2026-75677
CVE-2026-75678
CVE-2026-75679
CVE-2026-75680
CVE-2026-75681
CVE-2026-75683
CVE-2026-75685
CVE-2026-75687
CVE-2026-75690
CVE-2026-75691
CVE-2026-75692
CVE-2026-75693
CVE-2026-75694
CVE-2026-75695
CVE-2026-75696
CVE-2026-75700
CVE-2026-75701
CVE-2026-75706
CVE-2026-75708
CVE-2026-75709
CVE-2026-75710
CVE-2026-75711
CVE-2026-75713
CVE-2026-75715
CVE-2026-75717
CVE-2026-75719
CVE-2026-75720
CVE-2026-75722
CVE-2026-75724
CVE-2026-75726
CVE-2026-75729
CVE-2026-75731
CVE-2026-75734
CVE-2026-75736
CVE-2026-75738
CVE-2026-75740
CVE-2026-75742
CVE-2026-75746
CVE-2026-75771
CVE-2026-75862
CVE-2026-75990
CVE-2026-75992
CVE-2026-75998
CVE-2026-76000
CVE-2026-81985
CVE-2026-81987
CVE-2026-81989
CVE-2026-81991
CVE-2026-81993
CVE-2026-81994
CVE-2026-81996
CVE-2026-81997
CVE-2026-82001
CVE-2026-82004
CVE-2026-82004
CVE-2026-82005
CVE-2026-82006
CVE-2026-82007
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-22902657
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|