Feed›Vulnerability›Multiple Vulnerabilities in Adobe Products Could Allow for A...
VulnerabilityCIS Advisories
9.9 — CRITICAL

Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution

📅 8 September 2026 at 19:24 UTC📰 CIS AdvisoriesView original source ↗

Multiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution.Adobe Experience Manager (AEM) is an enterprise-grade digital experience platform that combines content management, digital asset management, and digital enrollment into a single cloud-native solution.Adobe ColdFusion is a commercial rapid web application development platform used to build, deploy, and scale dynamic enterprise web and mobile applications.Adobe Photoshop is a professional raster graphics editor used to create, edit, and manipulate digital images.Adobe Illustrator is an industry-standard vector graphics editor and design software used to create infinitely scalable artwork, logos, icons, typography, and complex illustrations.Adobe Animate is computer animation and multimedia authoring software.Adobe Commerce is a flexible, enterprise-level e-commerce platform built on top of Magento technology that helps businesses create and manage online stores.Adobe Acrobat Reader is a free software application used to view, print, sign, share, and annotate PDF (Portable Document Format) files.Adobe Campaign Classic is an enterprise marketing automation and cross-channel campaign management platform used to design, execute, and orchestrate customer journeys across online and offline channels.Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

Multiple vulnerabilities have been discovered in Adobe products, allowing for arbitrary code execution with potentially elevated access or control over the victim's account or session. The most severe vulnerability has a CVSS score of 9.9, indicating critical severity.

⚙️Technical Details
💥Impact Assessment
Severity: Critical
Who Is at Risk
Users with administrative user rights or those whose accounts are configured to have fewer user rights on the system may be impacted.
🛡️Recommended Actions
1Implement a patch management process to apply security updates as soon as possible
2Restrict privileges of users and ensure they do not have elevated access to sensitive data or systems
3Monitor for suspicious activity and implement additional security controls such as intrusion detection systems
📦Affected Products
Adobe IndesignApple MacosMicrosoft WindowsAdobe Experience ManagerAdobe ColdFusionAdobe PhotoshopAdobe IllustratorAdobe AnimateAdobe CommerceAdobe Acrobat Reader
🔐NVD Verified DataVERIFIED
CVE-2026-19232 ↗CVSS 9.9 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Weaknesses
CWE-863
CVE-2025-64830 ↗CVSS 5.4 — MEDIUM
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weaknesses
CWE-79
CVE-2026-75735 ↗CVSS 5.4 — MEDIUM
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weaknesses
CWE-79
CVE-2026-27238 ↗CVSS 5.4 — MEDIUM
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weaknesses
CWE-79
Affected Products (CPE)
Adobe IndesignApple MacosMicrosoft Windows
CVE-2026-75736 ↗CVSS 5.4 — MEDIUM
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weaknesses
CWE-79

Read the full article

This is a curated summary. The complete article is available at CIS Advisories.

Read on CIS Advisories ↗
← Back to feed