Výsledky hledání

výrobce: Adobe× typ: zranitelnost× v celém archivu zrušit filtry

38 karet z 43 položek CZ · EN/orig

23

ZDI-26-658: Adobe Acrobat Pro DC JPEG Parsing Integer Overflow Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Pro DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81987.

EPSS 0.00 CVSS 7.8 CVE-2026-81987 Adobe US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-658: Adobe Acrobat Pro DC JPEG Parsing Integer Overflow Remote Code Execution Vulnerability

ZDI-26-659: Adobe Acrobat Reader DC JPEG2000 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-80160.

EPSS 0.00 CVSS 3.3 CVE-2026-80160 Adobe US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-659: Adobe Acrobat Reader DC JPEG2000 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

ZDI-26-660: Adobe Acrobat Reader DC Font Parsing Use-After-Free Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-80162.

EPSS 0.00 CVSS 3.3 CVE-2026-80162 Adobe US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-660: Adobe Acrobat Reader DC Font Parsing Use-After-Free Information Disclosure Vulnerability

ZDI-26-661: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81985.

EPSS 0.00 CVSS 7.8 CVE-2026-81985 Adobe US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-661: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability

ZDI-26-662: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81990.

EPSS 0.00 CVSS 7.8 CVE-2026-81990 Adobe US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-662: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability

ZDI-26-663: Adobe Acrobat Pro DC Annotation Use-After-Free Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Pro DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81989.

EPSS 0.00 CVSS 7.8 CVE-2026-81989 Adobe US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-663: Adobe Acrobat Pro DC Annotation Use-After-Free Remote Code Execution Vulnerability

ZDI-26-664: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81986.

EPSS 0.00 CVSS 7.8 CVE-2026-81986 Adobe US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-664: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability

ZDI-26-665: Adobe Acrobat Reader DC Annots Report Use-After-Free Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-79909.

EPSS 0.00 CVSS 7.8 CVE-2026-79909 Adobe US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-665: Adobe Acrobat Reader DC Annots Report Use-After-Free Remote Code Execution Vulnerability

ZDI-26-666: Adobe Acrobat Reader DC JPEG2000 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-79910.

EPSS 0.00 CVSS 3.3 CVE-2026-79910 Adobe US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-666: Adobe Acrobat Reader DC JPEG2000 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

ZDI-26-667: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81975.

EPSS 0.00 CVSS 7.8 CVE-2026-81975 Adobe US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-667: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability

ZDI-26-668: Adobe Acrobat Reader DC Annotation Use-After-Free Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-81984.

EPSS 0.00 CVSS 3.3 CVE-2026-81984 Adobe US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-668: Adobe Acrobat Reader DC Annotation Use-After-Free Information Disclosure Vulnerability

ZDI-26-669: Adobe Acrobat Reader DC JBIG2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-81978.

EPSS 0.00 CVSS 3.3 CVE-2026-81978 Adobe US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-669: Adobe Acrobat Reader DC JBIG2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

ZDI-26-670: Adobe Acrobat Pro DC Doc Object Out-Of-Bounds Read Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Pro DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-81991.

EPSS 0.00 CVSS 3.3 CVE-2026-81991 Adobe US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-670: Adobe Acrobat Pro DC Doc Object Out-Of-Bounds Read Information Disclosure Vulnerability

ZDI-26-671: Adobe Acrobat Reader DC Dialog Object Type Confusion Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-80161.

EPSS 0.00 CVSS 7.8 CVE-2026-80161 Adobe US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-671: Adobe Acrobat Reader DC Dialog Object Type Confusion Remote Code Execution Vulnerability

ZDI-26-672: Adobe Acrobat Reader DC PDF File Parsing Integer Underflow Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-81977.

EPSS 0.00 CVSS 3.3 CVE-2026-81977 Adobe US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-672: Adobe Acrobat Reader DC PDF File Parsing Integer Underflow Information Disclosure Vulnerability

ZDI-26-673: Adobe Acrobat Pro DC Doc Object Use-After-Free Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Pro DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81988.

EPSS 0.00 CVSS 7.8 CVE-2026-81988 Adobe US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-673: Adobe Acrobat Pro DC Doc Object Use-After-Free Remote Code Execution Vulnerability

ZDI-26-674: Adobe Acrobat Reader DC Annotation Out-Of-Bounds Write Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81981.

EPSS 0.00 CVSS 7.8 CVE-2026-81981 Adobe US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-674: Adobe Acrobat Reader DC Annotation Out-Of-Bounds Write Remote Code Execution Vulnerability

ZDI-26-675: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81976.

EPSS 0.00 CVSS 7.8 CVE-2026-81976 Adobe US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-675: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability

ZDI-26-676: Adobe Acrobat Reader DC DigSig Use-After-Free Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81973.

EPSS 0.00 CVSS 7.8 CVE-2026-81973 Adobe US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-676: Adobe Acrobat Reader DC DigSig Use-After-Free Remote Code Execution Vulnerability

ZDI-26-677: Adobe Photoshop DCM JPEG-LS Image Parsing Integer Overflow Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Photoshop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-75771.

EPSS 0.00 CVSS 7.8 CVE-2026-75771 Adobe US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-677: Adobe Photoshop DCM JPEG-LS Image Parsing Integer Overflow Remote Code Execution Vulnerability

ZDI-26-678: Adobe Photoshop DCM File Parsing Integer Overflow Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Photoshop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-75863.

EPSS 0.00 CVSS 7.8 CVE-2026-75863 Adobe US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-678: Adobe Photoshop DCM File Parsing Integer Overflow Remote Code Execution Vulnerability

ZDI-26-679: Adobe Photoshop DCM JPEG Image Parsing Integer Overflow Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Photoshop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-75862.

EPSS 0.00 CVSS 7.8 CVE-2026-75862 Adobe US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-679: Adobe Photoshop DCM JPEG Image Parsing Integer Overflow Remote Code Execution Vulnerability

Security update available for Adobe Acrobat and Reader (APSB26-141)

Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 8.8, CVEs: CVE-2026-81996, CVE-2026-81994, CVE-2026-81983, CVE-2026-79907, CVE-2026-79908, CVE-2026-79909, CVE-2026-80161, CVE-2026-81973, CVE-2026-81975, CVE-2026-81976, CVE-2026-81992, CVE-2026-81979, CVE-2026-81980, CVE-2026-81981, CVE-2026-81985, CVE-2026-81986, CVE-2026-81987, CVE-2026-81988, CVE-2026-81989, CVE-2026-81990 (+12 other associated CVEs), Summary: Adobe has released a security update for…

CVSS 8.8 Adobe FI

tg: zranitelnost tg: novinka v produktu

· NCSC-FI · Security update available for Adobe Acrobat and Reader (APSB26-141)

9

NCSC-2026-0364 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Illustrator

Adobe heeft meerdere kwetsbaarheden verholpen in Adobe Illustrator. De kwetsbaarheden bevinden zich in de wijze waarop Adobe Illustrator bestanden verwerkt. Eén kwetsbaarheid betreft een onjuiste autorisatie die het mogelijk maakt dat een aanvaller willekeurige code uitvoert wanneer een gebruiker een kwaadaardig bestand opent. Een andere kwetsbaarheid betreft onjuiste inputvalidatie, waardoor eveneens code-uitvoering mogelijk is bij het openen van speciaal vervaardigde bestanden. Daarnaast is…

Adobe NL

tg: zranitelnost

· NCSC-NL · NCSC-2026-0364 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Illustrator

NCSC-2026-0363 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Experience Manager

Adobe heeft meerdere kwetsbaarheden verholpen in Adobe Experience Manager. Adobe Experience Manager bevat meerdere Cross-Site Scripting (XSS) kwetsbaarheden, waaronder DOM-based en stored XSS. Deze kwetsbaarheden stellen een aanvaller in staat om kwaadaardige JavaScript-code te injecteren en uit te voeren binnen de browsers van gebruikers die een speciaal vervaardigde webpagina bezoeken of met deze pagina's interacteren. De stored XSS kwetsbaarheden ontstaan door onvoldoende input sanitatie en…

Adobe NL

tg: zranitelnost

· NCSC-NL · NCSC-2026-0363 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Experience Manager

NCSC-2026-0362 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe ColdFusion

Adobe heeft meerdere kwetsbaarheden verholpen in Adobe ColdFusion. De kwetsbaarheden in Adobe ColdFusion omvatten onder andere een stored Cross-Site Scripting (XSS) waarbij een aanvaller met lage privileges kwaadaardige scripts kan injecteren in formulier velden die vervolgens uitgevoerd worden in de browser van een gebruiker. Daarnaast is er een kwetsbaarheid in de dynamische code-evaluatie die het mogelijk maakt voor een aanvaller met lage privileges om zonder gebruikersinteractie…

Adobe NL

tg: zranitelnost

· NCSC-NL · NCSC-2026-0362 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe ColdFusion

NCSC-2026-0361 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Commerce

Adobe heeft meerdere kwetsbaarheden verholpen in Adobe Commerce. De kwetsbaarheden betreffen onder andere stored Cross-Site Scripting (XSS) waarbij aanvallers kwaadaardige JavaScript-code kunnen injecteren in formulier velden binnen de applicatie. Deze code wordt uitgevoerd in de context van de browser van het slachtoffer en kan ongeautoriseerde acties uitvoeren, zoals het kapen van sessies of het escaleren van privileges. Daarnaast zijn er meerdere incorrecte autorisatieproblemen…

Adobe NL

tg: zranitelnost

· NCSC-NL · NCSC-2026-0361 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Commerce

NCSC-2026-0360 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Photoshop Desktop

Adobe heeft meerdere kwetsbaarheden verholpen in Adobe Photoshop Desktop. De kwetsbaarheden bevinden zich in de verwerking van speciaal vervaardigde bestanden binnen Adobe Photoshop Desktop. Deze omvatten out-of-bounds write, integer overflow of wraparound, uncontrolled search path element en heap-based buffer overflow. Door het openen van kwaadaardig opgemaakte bestanden kan een aanvaller code uitvoeren met de privileges van de gebruiker die de applicatie draait. De kwetsbaarheden kunnen…

Adobe NL

tg: zranitelnost

· NCSC-NL · NCSC-2026-0360 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Photoshop Desktop

SPOJENO PŘES CVE Security update available for Adobe Commerce | APSB26-146

Classification: Critical, Solution: Official Fix, Exploit Maturity: High, CVSSv3.1: 10.0, CVEs: CVE-2026-75650, Summary: Adobe has released a security update for Adobe Commerce and Magento Open Source. This update resolves a critical vulnerability that could result in arbitrary code execution. Adobe is aware of CVE-2026-75650 being exploited in the wild. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H CVSS:3.1 10.0

KEV ✓ EPSS 0.02 CVSS 10.0 CVE-2026-75650 Adobe Magento obchod FI US IT FR

tg: zneužíváno tg: zranitelnost tg: rozbor tp: malware

· NCSC-FI · Security update available for Adobe Commerce | APSB26-146 · Tenable Research · StyleSmuggler (CVE-2026-75650): Frequently asked questions about Adobe Commerce and Magento zero-day · BleepingComputer · Adobe fixes critical Magento zero-day exploited to backdoor servers · CSIRT Itálie (ACN) · Adobe: rilevato sfruttamento in rete della CVE-2026-75650 · CISA KEV · Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability (CVE-2026-75650) · CERT-FR – avis · Vulnérabilité dans les produits Adobe (08 septembre 2026)

5

Microsoft and Adobe Patch Tuesday, September 2026 Security Update Review

Microsoft kicks off September with its monthly Patch Tuesday release, delivering fixes for security vulnerabilities affecting its products. The security updates are packed with security fixes, providing organizations with important updates to help protect their environments from emerging threats. This Patch Tuesday is Microsoft’s largest security update ever, marking a significant increase over other recent massive releases, including the 570 security flaws fixed in July and 400 fixed in August…

Microsoft Adobe US

tg: zneužíváno tg: zranitelnost tg: přehled

· Qualys · Microsoft and Adobe Patch Tuesday, September 2026 Security Update Review

The September 2026 Security Update Review

Whelp, here we are. Deep into the new normal. With nearly 1,000 CVEs coming out from Microsoft and a healthy release from Adobe as well, there’s a phrase from my military days that comes to mind: embrace the suck. Take an extend break from your regularly scheduled activities as we take a look at the latest security patches from Adobe and Microsoft. If you’d rather watch the full video recap covering the entire release, you can check out the Patch Report webcast on our YouTube channel. It should…

KEV ✓ EPSS 0.02 CVSS 10.0 CVE-2026-55007 CVE-2026-65669 CVE-2026-69465 CVE-2026-69525 CVE-2026-75650 CVE-2026-80097 CVE-2026-81963 CVE-2026-85880 Adobe Microsoft US

tg: zneužíváno tg: zranitelnost tg: přehled

· ZDI Blog · The September 2026 Security Update Review

Adobe security advisory (AV26-888)

Serial Number: AV26-888Date: September 8, 2026 As of September 7, 2026, Adobe is affected by a vulnerability in the following products: Adobe Commerce All except Hotfix for CVE-2026-7565 Prior to or equal to 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug Adobe Commerce B2B All except Hotfix for CVE-2026-7565 Prior to or equal to 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug Magento Open Source All except Hotfix for…

KEV ✓ EPSS 0.02 CVE-2026-7565 CVE-2026-75650 Adobe CA

tg: zneužíváno tg: zranitelnost

· Cyber Centre Kanada · Adobe security advisory (AV26-888)

CISA Adds Four Known Exploited Vulnerabilities to Catalog

CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-75650 Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability CVE-2026-81963 Microsoft Windows Link Following Vulnerability CVE-2026-85880 Microsoft Windows Heap-Based Buffer Overflow Vulnerability CVE-2026-86218 N-able N-central Static Code Injection Vulnerability These types of vulnerabilities…

KEV ✓ EPSS 0.02 CVE-2026-75650 CVE-2026-81963 CVE-2026-85880 CVE-2026-86218 Adobe Magento Microsoft N-able veřejná správa US

tg: zneužíváno tg: zranitelnost tg: regulace

· CISA Advisories · CISA Adds Four Known Exploited Vulnerabilities to Catalog

NCSC-2026-0344 [1.00] [H/H] Kwetsbaarheid verholpen in Adobe Commerce en Magento

Adobe heeft een kwetsbaarheid verholpen in Adobe Commerce en Magento. De kwetsbaarheid bevindt zich in de template engine van Adobe Commerce, waarbij speciale elementen niet correct worden geneutraliseerd. Een aanvaller kan hierdoor op afstand willekeurige code uitvoeren zonder dat er gebruikersinteractie nodig is. Dit gebeurt door misbruik te maken van een gewijzigde scope om privileges te escaleren of de uitvoeringcontext aan te passen. Adobe geeft aan dat deze kwetsbaarheid reeds actief…

Adobe NL

tg: zneužíváno tg: zranitelnost

· NCSC-NL · NCSC-2026-0344 [1.00] [H/H] Kwetsbaarheid verholpen in Adobe Commerce en Magento

1