Výsledky hledání

výrobce: Adobe× v celém archivu zrušit filtry

60 karet z 65 položek CZ · EN/orig

23

ZDI-26-658: Adobe Acrobat Pro DC JPEG Parsing Integer Overflow Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Pro DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81987.

EPSS 0.00 CVSS 7.8 CVE-2026-81987 Adobe US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-658: Adobe Acrobat Pro DC JPEG Parsing Integer Overflow Remote Code Execution Vulnerability

ZDI-26-659: Adobe Acrobat Reader DC JPEG2000 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-80160.

EPSS 0.00 CVSS 3.3 CVE-2026-80160 Adobe US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-659: Adobe Acrobat Reader DC JPEG2000 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

ZDI-26-660: Adobe Acrobat Reader DC Font Parsing Use-After-Free Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-80162.

EPSS 0.00 CVSS 3.3 CVE-2026-80162 Adobe US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-660: Adobe Acrobat Reader DC Font Parsing Use-After-Free Information Disclosure Vulnerability

ZDI-26-661: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81985.

EPSS 0.00 CVSS 7.8 CVE-2026-81985 Adobe US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-661: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability

ZDI-26-662: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81990.

EPSS 0.00 CVSS 7.8 CVE-2026-81990 Adobe US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-662: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability

ZDI-26-663: Adobe Acrobat Pro DC Annotation Use-After-Free Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Pro DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81989.

EPSS 0.00 CVSS 7.8 CVE-2026-81989 Adobe US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-663: Adobe Acrobat Pro DC Annotation Use-After-Free Remote Code Execution Vulnerability

ZDI-26-664: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81986.

EPSS 0.00 CVSS 7.8 CVE-2026-81986 Adobe US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-664: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability

ZDI-26-665: Adobe Acrobat Reader DC Annots Report Use-After-Free Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-79909.

EPSS 0.00 CVSS 7.8 CVE-2026-79909 Adobe US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-665: Adobe Acrobat Reader DC Annots Report Use-After-Free Remote Code Execution Vulnerability

ZDI-26-666: Adobe Acrobat Reader DC JPEG2000 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-79910.

EPSS 0.00 CVSS 3.3 CVE-2026-79910 Adobe US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-666: Adobe Acrobat Reader DC JPEG2000 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

ZDI-26-667: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81975.

EPSS 0.00 CVSS 7.8 CVE-2026-81975 Adobe US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-667: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability

ZDI-26-668: Adobe Acrobat Reader DC Annotation Use-After-Free Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-81984.

EPSS 0.00 CVSS 3.3 CVE-2026-81984 Adobe US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-668: Adobe Acrobat Reader DC Annotation Use-After-Free Information Disclosure Vulnerability

ZDI-26-669: Adobe Acrobat Reader DC JBIG2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-81978.

EPSS 0.00 CVSS 3.3 CVE-2026-81978 Adobe US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-669: Adobe Acrobat Reader DC JBIG2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

ZDI-26-670: Adobe Acrobat Pro DC Doc Object Out-Of-Bounds Read Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Pro DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-81991.

EPSS 0.00 CVSS 3.3 CVE-2026-81991 Adobe US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-670: Adobe Acrobat Pro DC Doc Object Out-Of-Bounds Read Information Disclosure Vulnerability

ZDI-26-671: Adobe Acrobat Reader DC Dialog Object Type Confusion Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-80161.

EPSS 0.00 CVSS 7.8 CVE-2026-80161 Adobe US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-671: Adobe Acrobat Reader DC Dialog Object Type Confusion Remote Code Execution Vulnerability

ZDI-26-672: Adobe Acrobat Reader DC PDF File Parsing Integer Underflow Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-81977.

EPSS 0.00 CVSS 3.3 CVE-2026-81977 Adobe US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-672: Adobe Acrobat Reader DC PDF File Parsing Integer Underflow Information Disclosure Vulnerability

ZDI-26-673: Adobe Acrobat Pro DC Doc Object Use-After-Free Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Pro DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81988.

EPSS 0.00 CVSS 7.8 CVE-2026-81988 Adobe US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-673: Adobe Acrobat Pro DC Doc Object Use-After-Free Remote Code Execution Vulnerability

ZDI-26-674: Adobe Acrobat Reader DC Annotation Out-Of-Bounds Write Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81981.

EPSS 0.00 CVSS 7.8 CVE-2026-81981 Adobe US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-674: Adobe Acrobat Reader DC Annotation Out-Of-Bounds Write Remote Code Execution Vulnerability

ZDI-26-675: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81976.

EPSS 0.00 CVSS 7.8 CVE-2026-81976 Adobe US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-675: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability

ZDI-26-676: Adobe Acrobat Reader DC DigSig Use-After-Free Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81973.

EPSS 0.00 CVSS 7.8 CVE-2026-81973 Adobe US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-676: Adobe Acrobat Reader DC DigSig Use-After-Free Remote Code Execution Vulnerability

ZDI-26-677: Adobe Photoshop DCM JPEG-LS Image Parsing Integer Overflow Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Photoshop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-75771.

EPSS 0.00 CVSS 7.8 CVE-2026-75771 Adobe US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-677: Adobe Photoshop DCM JPEG-LS Image Parsing Integer Overflow Remote Code Execution Vulnerability

ZDI-26-678: Adobe Photoshop DCM File Parsing Integer Overflow Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Photoshop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-75863.

EPSS 0.00 CVSS 7.8 CVE-2026-75863 Adobe US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-678: Adobe Photoshop DCM File Parsing Integer Overflow Remote Code Execution Vulnerability

ZDI-26-679: Adobe Photoshop DCM JPEG Image Parsing Integer Overflow Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Photoshop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-75862.

EPSS 0.00 CVSS 7.8 CVE-2026-75862 Adobe US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-679: Adobe Photoshop DCM JPEG Image Parsing Integer Overflow Remote Code Execution Vulnerability

Security update available for Adobe Acrobat and Reader (APSB26-141)

Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 8.8, CVEs: CVE-2026-81996, CVE-2026-81994, CVE-2026-81983, CVE-2026-79907, CVE-2026-79908, CVE-2026-79909, CVE-2026-80161, CVE-2026-81973, CVE-2026-81975, CVE-2026-81976, CVE-2026-81992, CVE-2026-81979, CVE-2026-81980, CVE-2026-81981, CVE-2026-81985, CVE-2026-81986, CVE-2026-81987, CVE-2026-81988, CVE-2026-81989, CVE-2026-81990 (+12 other associated CVEs), Summary: Adobe has released a security update for…

CVSS 8.8 Adobe FI

tg: zranitelnost tg: novinka v produktu

· NCSC-FI · Security update available for Adobe Acrobat and Reader (APSB26-141)

9

NCSC-2026-0364 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Illustrator

Adobe heeft meerdere kwetsbaarheden verholpen in Adobe Illustrator. De kwetsbaarheden bevinden zich in de wijze waarop Adobe Illustrator bestanden verwerkt. Eén kwetsbaarheid betreft een onjuiste autorisatie die het mogelijk maakt dat een aanvaller willekeurige code uitvoert wanneer een gebruiker een kwaadaardig bestand opent. Een andere kwetsbaarheid betreft onjuiste inputvalidatie, waardoor eveneens code-uitvoering mogelijk is bij het openen van speciaal vervaardigde bestanden. Daarnaast is…

Adobe NL

tg: zranitelnost

· NCSC-NL · NCSC-2026-0364 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Illustrator

NCSC-2026-0363 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Experience Manager

Adobe heeft meerdere kwetsbaarheden verholpen in Adobe Experience Manager. Adobe Experience Manager bevat meerdere Cross-Site Scripting (XSS) kwetsbaarheden, waaronder DOM-based en stored XSS. Deze kwetsbaarheden stellen een aanvaller in staat om kwaadaardige JavaScript-code te injecteren en uit te voeren binnen de browsers van gebruikers die een speciaal vervaardigde webpagina bezoeken of met deze pagina's interacteren. De stored XSS kwetsbaarheden ontstaan door onvoldoende input sanitatie en…

Adobe NL

tg: zranitelnost

· NCSC-NL · NCSC-2026-0363 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Experience Manager

NCSC-2026-0362 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe ColdFusion

Adobe heeft meerdere kwetsbaarheden verholpen in Adobe ColdFusion. De kwetsbaarheden in Adobe ColdFusion omvatten onder andere een stored Cross-Site Scripting (XSS) waarbij een aanvaller met lage privileges kwaadaardige scripts kan injecteren in formulier velden die vervolgens uitgevoerd worden in de browser van een gebruiker. Daarnaast is er een kwetsbaarheid in de dynamische code-evaluatie die het mogelijk maakt voor een aanvaller met lage privileges om zonder gebruikersinteractie…

Adobe NL

tg: zranitelnost

· NCSC-NL · NCSC-2026-0362 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe ColdFusion

NCSC-2026-0361 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Commerce

Adobe heeft meerdere kwetsbaarheden verholpen in Adobe Commerce. De kwetsbaarheden betreffen onder andere stored Cross-Site Scripting (XSS) waarbij aanvallers kwaadaardige JavaScript-code kunnen injecteren in formulier velden binnen de applicatie. Deze code wordt uitgevoerd in de context van de browser van het slachtoffer en kan ongeautoriseerde acties uitvoeren, zoals het kapen van sessies of het escaleren van privileges. Daarnaast zijn er meerdere incorrecte autorisatieproblemen…

Adobe NL

tg: zranitelnost

· NCSC-NL · NCSC-2026-0361 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Commerce

NCSC-2026-0360 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Photoshop Desktop

Adobe heeft meerdere kwetsbaarheden verholpen in Adobe Photoshop Desktop. De kwetsbaarheden bevinden zich in de verwerking van speciaal vervaardigde bestanden binnen Adobe Photoshop Desktop. Deze omvatten out-of-bounds write, integer overflow of wraparound, uncontrolled search path element en heap-based buffer overflow. Door het openen van kwaadaardig opgemaakte bestanden kan een aanvaller code uitvoeren met de privileges van de gebruiker die de applicatie draait. De kwetsbaarheden kunnen…

Adobe NL

tg: zranitelnost

· NCSC-NL · NCSC-2026-0360 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Photoshop Desktop

SPOJENO PŘES CVE Security update available for Adobe Commerce | APSB26-146

Classification: Critical, Solution: Official Fix, Exploit Maturity: High, CVSSv3.1: 10.0, CVEs: CVE-2026-75650, Summary: Adobe has released a security update for Adobe Commerce and Magento Open Source. This update resolves a critical vulnerability that could result in arbitrary code execution. Adobe is aware of CVE-2026-75650 being exploited in the wild. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H CVSS:3.1 10.0

KEV ✓ EPSS 0.02 CVSS 10.0 CVE-2026-75650 Adobe Magento obchod FI US IT FR

tg: zneužíváno tg: zranitelnost tg: rozbor tp: malware

· NCSC-FI · Security update available for Adobe Commerce | APSB26-146 · Tenable Research · StyleSmuggler (CVE-2026-75650): Frequently asked questions about Adobe Commerce and Magento zero-day · BleepingComputer · Adobe fixes critical Magento zero-day exploited to backdoor servers · CSIRT Itálie (ACN) · Adobe: rilevato sfruttamento in rete della CVE-2026-75650 · CISA KEV · Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability (CVE-2026-75650) · CERT-FR – avis · Vulnérabilité dans les produits Adobe (08 septembre 2026)

5

Microsoft and Adobe Patch Tuesday, September 2026 Security Update Review

Microsoft kicks off September with its monthly Patch Tuesday release, delivering fixes for security vulnerabilities affecting its products. The security updates are packed with security fixes, providing organizations with important updates to help protect their environments from emerging threats. This Patch Tuesday is Microsoft’s largest security update ever, marking a significant increase over other recent massive releases, including the 570 security flaws fixed in July and 400 fixed in August…

Microsoft Adobe US

tg: zneužíváno tg: zranitelnost tg: přehled

· Qualys · Microsoft and Adobe Patch Tuesday, September 2026 Security Update Review

The September 2026 Security Update Review

Whelp, here we are. Deep into the new normal. With nearly 1,000 CVEs coming out from Microsoft and a healthy release from Adobe as well, there’s a phrase from my military days that comes to mind: embrace the suck. Take an extend break from your regularly scheduled activities as we take a look at the latest security patches from Adobe and Microsoft. If you’d rather watch the full video recap covering the entire release, you can check out the Patch Report webcast on our YouTube channel. It should…

KEV ✓ EPSS 0.02 CVSS 10.0 CVE-2026-55007 CVE-2026-65669 CVE-2026-69465 CVE-2026-69525 CVE-2026-75650 CVE-2026-80097 CVE-2026-81963 CVE-2026-85880 Adobe Microsoft US

tg: zneužíváno tg: zranitelnost tg: přehled

· ZDI Blog · The September 2026 Security Update Review

Adobe security advisory (AV26-888)

Serial Number: AV26-888Date: September 8, 2026 As of September 7, 2026, Adobe is affected by a vulnerability in the following products: Adobe Commerce All except Hotfix for CVE-2026-7565 Prior to or equal to 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug Adobe Commerce B2B All except Hotfix for CVE-2026-7565 Prior to or equal to 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug Magento Open Source All except Hotfix for…

KEV ✓ EPSS 0.02 CVE-2026-7565 CVE-2026-75650 Adobe CA

tg: zneužíváno tg: zranitelnost

· Cyber Centre Kanada · Adobe security advisory (AV26-888)

CISA Adds Four Known Exploited Vulnerabilities to Catalog

CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-75650 Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability CVE-2026-81963 Microsoft Windows Link Following Vulnerability CVE-2026-85880 Microsoft Windows Heap-Based Buffer Overflow Vulnerability CVE-2026-86218 N-able N-central Static Code Injection Vulnerability These types of vulnerabilities…

KEV ✓ EPSS 0.02 CVE-2026-75650 CVE-2026-81963 CVE-2026-85880 CVE-2026-86218 Adobe Magento Microsoft N-able veřejná správa US

tg: zneužíváno tg: zranitelnost tg: regulace

· CISA Advisories · CISA Adds Four Known Exploited Vulnerabilities to Catalog

NCSC-2026-0344 [1.00] [H/H] Kwetsbaarheid verholpen in Adobe Commerce en Magento

Adobe heeft een kwetsbaarheid verholpen in Adobe Commerce en Magento. De kwetsbaarheid bevindt zich in de template engine van Adobe Commerce, waarbij speciale elementen niet correct worden geneutraliseerd. Een aanvaller kan hierdoor op afstand willekeurige code uitvoeren zonder dat er gebruikersinteractie nodig is. Dit gebeurt door misbruik te maken van een gewijzigde scope om privileges te escaleren of de uitvoeringcontext aan te passen. Adobe geeft aan dat deze kwetsbaarheid reeds actief…

Adobe NL

tg: zneužíváno tg: zranitelnost

· NCSC-NL · NCSC-2026-0344 [1.00] [H/H] Kwetsbaarheid verholpen in Adobe Commerce en Magento

2

1

NCSC-2026-0331 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Campaign Classic

Adobe heeft meerdere kwetsbaarheden verholpen in Adobe Campaign Classic. De kwetsbaarheden betreffen een Server-Side Request Forgery (SSRF) en OS Command Injection in Adobe Campaign Classic. De SSRF-kwetsbaarheid maakt het mogelijk voor een aanvaller om verzoeken op de server te manipuleren, wat kan leiden tot het uitvoeren van willekeurige code zonder gebruikersinteractie. De OS Command Injection kwetsbaarheden stellen een aanvaller in staat om willekeurige besturingssysteemcommando's uit te…

Adobe NL

· NCSC-NL · NCSC-2026-0331 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Campaign Classic

3

Adobe security advisory (AV26-848)

Serial Number: AV26-848Date: August 26, 2026 As of August 25, 2026, Adobe is affected by vulnerabilities in the following products: Adobe Campaign Classic Prior to or equal to ACC v7: 7.4.4 build 9400 Adobe Substance 3D Designer Prior to or equal to 16.0.4 Adobe Substance 3D Painter Prior to or equal to 12.1.2 Adobe Substance 3D Sampler Prior to or equal to 6.0.1 Adobe XD Prior to or equal to 60 C2PA Tool Prior to or equal to c2patool-v0.26.70 Content Credentials Rust SDK Prior to or equal to…

Adobe CA

· Cyber Centre Kanada · Adobe security advisory (AV26-848)

Adobe: aggiornamenti di sicurezza

Adobe ha rilasciato aggiornamenti di sicurezza per risolvere molteplici vulnerabilità, di cui 3 con gravità “critica” e 29 con gravità “alta”, nei prodotti Content Credentials Rust SDK, C2PA Tool, Campaign Classic, XD, Substance 3D Sampler, Substance 3D Painter, Substance 3D Designer.

Adobe IT

· CSIRT Itálie (ACN) · Adobe: aggiornamenti di sicurezza

Multible critical vulnerabilities in Adobe Campaign Classic (ACC)

Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 10.0, CVEs: CVE-2026-76197, CVE-2026-76195, CVE-2026-76193, Summary: CVE-2026-76197: Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) CVE-2026-76195 : Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) CVE-2026-76193: Adobe Campaign Classic (ACC)…

EPSS 0.02 CVSS 10.0 CVE-2026-76193 CVE-2026-76195 CVE-2026-76197 Adobe FI

· NCSC-FI · Multible critical vulnerabilities in Adobe Campaign Classic (ACC)

1

17th August – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 17th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Colombia’s Ministry of Justice has experienced a ransomware attack that affected part of its technology infrastructure and disrupted public services related to illicit-drug monitoring and legal processes. Officials confirmed that some files were encrypted but stated that no data theft was detected during the incident. MyDr, Poland’s primary…

KEV ✓ EPSS 0.25 CVSS 9.8 CVE-2026-53413 CVE-2026-65400 CVE-2026-68820 CVE-2026-71362 Microsoft Apple Adobe Zoom veřejná správa zdravotnictví obrana energetika IL

· Check Point Research · 17th August – Threat Intelligence Report

1

3

NCSC-2026-0294 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe ColdFusion

Adobe heeft meerdere kwetsbaarheden verholpen in Adobe ColdFusion versies 2025.0.11, 2023.0.22 en eerdere versies. De kwetsbaarheden in Adobe ColdFusion kunnen door ongeauthenticeerde kwaadwillenden worden misbruikt om willekeurige code uit te voeren op afstand, beveiligingsmaatregelen te omzeilen, rechten te verhogen op het systeem of middels DoS de werking van de applicatie te verstoren.

Adobe NL

· NCSC-NL · NCSC-2026-0294 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe ColdFusion

Adobe security advisory (AV26-808)

Serial number: AV26-808Date: August 12, 2026 As of August 11, 2026, Adobe is affected by vulnerabilities in the following products: Adobe Campaign Classic Prior to or equal to ACC v7: 7.4.3 build 9399 Adobe Commerce Prior to or equal to 2.4.9-2026-jul, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug and 2.4.4-2026-aug Adobe Commerce B2B Prior to or equal to 1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-jul and 1.3.3-2026-jul ColdFusion 2023 Prior to or equal to 2023…

Adobe CA

· Cyber Centre Kanada · Adobe security advisory (AV26-808)

Adobe: aggiornamenti di sicurezza

Adobe ha rilasciato aggiornamenti di sicurezza per risolvere molteplici vulnerabilità, di cui 7 con gravità “critica” e 27 con gravità “alta”, nei prodotti Commerce, Magento, ColdFusion, Campaign Classic, Lightroom Classic, Content Credentials Rust SDK, C2PA Tool, Content Credentials JS SDK.

Adobe IT

· CSIRT Itálie (ACN) · Adobe: aggiornamenti di sicurezza

2

Microsoft and Adobe Patch Tuesday, August 2026 Security Update Review

The August 2026 Microsoft Patch Tuesday release delivers security fixes for vulnerabilities affecting a wide range of Microsoft products and services. As attackers continue to exploit unpatched vulnerabilities, timely patching remains critical for reducing exposure and strengthening enterprise security. Microsoft Patch Tuesday for August 2026 This month’s release addresses 421 vulnerabilities, including 62 critical and 357 important-severity vulnerabilities. In this month’s updates, Microsoft…

Microsoft Adobe US

· Qualys · Microsoft and Adobe Patch Tuesday, August 2026 Security Update Review

The August 2026 Security Update Review

I’ve successfully survived Hacker Summer Camp, and I have returned with a new outlook on patch density. When even Linus Torvalds says that huge updates are the “new normal”, it’s time to readjust what we consider a true bug apocalypse. This month’s release is thankfully smaller than last months, but still huge by historical standards. Take a break from your regularly scheduled activities as we take a look at the latest security patches from Adobe and Microsoft. If you’d rather watch the full…

Adobe Microsoft US

· ZDI Blog · The August 2026 Security Update Review

2

ZDI-26-419: Adobe Creative Cloud AdobeUpdateService Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Adobe Creative Cloud. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.0. The following CVEs are assigned: CVE-2026-48272.

EPSS 0.00 CVSS 7.0 CVE-2026-48272 Adobe US

· Zero Day Initiative · ZDI-26-419: Adobe Creative Cloud AdobeUpdateService Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

ZDI-26-420: Adobe Creative Cloud AGSService Incorrect Permission Assignment Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Adobe Creative Cloud Desktop Application. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-48344.

EPSS 0.00 CVSS 7.8 CVE-2026-48344 Adobe US

· Zero Day Initiative · ZDI-26-420: Adobe Creative Cloud AGSService Incorrect Permission Assignment Local Privilege Escalation Vulnerability

1

The July 2026 Security Update Review

Well folks. Here we are. The bug apocalypse has fully descended upon us. I’ll do my best to sort this out in some way meaningful, but this month’s release shows us the nay-sayers were right, and I’ve got to hand it to the nay-sayers here. Excellent call. Take an extended break from your regularly scheduled activities as we let’s take a look at the latest security patches from Adobe and Microsoft. If you’d rather watch the full video recap covering the entire release, you can check it out here:…

KEV ✓ EPSS 0.85 CVSS 9.9 CVE-2026-50518 CVE-2026-50522 CVE-2026-55008 CVE-2026-55010 CVE-2026-56155 CVE-2026-56164 CVE-2026-56188 CVE-2026-56190 CVE-2026-57092 Adobe Microsoft Apple US

· ZDI Blog · The July 2026 Security Update Review

1

Riasztás Microsoft és Adobe szoftverek 2026 júniusában javított sérülékenységeiről

A Nemzetbiztonsági Szakszolgálat Nemzeti Kiberbiztonsági Intézet riasztást ad ki a Microsoft és az Adobe szoftvereket érintő kritikus kockázati besorolású sérülékenységek kapcsán azok súlyossága, a szoftverek széleskörű elterjedtsége, valamint az egyes biztonsági hibákat érintő aktív kihasználások miatt. A Microsoft tárgyhavi biztonsági csomagjában összesen 206 különböző biztonsági hibát javított, köztük 3 db nulladik napi (zero-day) sebezhetőséget is, […]

Microsoft Adobe HU

· NKI Maďarsko · Riasztás Microsoft és Adobe szoftverek 2026 júniusában javított sérülékenységeiről

1

1

The June 2026 Security Update Review

I’ve made it through Pwn2Own Berlin, had a little vacation, and now I’m back for Patch Tuesday. Microsoft and Adobe didn’t disappoint. In fact, they have heralded my return with the largest Patch Tuesday release ever. Thanks? Take a break from your regularly scheduled activities and let’s take a look at the latest security patches from Adobe and Microsoft. If you’d rather watch the full video recap covering the entire release, you can check it out here: Adobe Patches for June 2026For June,…

KEV ✓ EPSS 0.54 CVSS 10.0 CVE-2025-10263 CVE-2026-32193 CVE-2026-41091 CVE-2026-44815 CVE-2026-45585 CVE-2026-45586 CVE-2026-45657 CVE-2026-47291 CVE-2026-47644 CVE-2026-48567 CVE-2026-49160 CVE-2026-50507 Adobe Microsoft US

· ZDI Blog · The June 2026 Security Update Review

1

The May 2026 Security Update Review

I’m currently in Berlin helping set up for Pwn2Own Berlin, but that doesn’t stop Patch Tuesday from coming, and it’s another big one. At least nothing is listed as being in the wild – for now. Take a break from your regularly scheduled activities and let’s take a look at the latest security patches from Adobe and Microsoft. Due to technical difficulties, there will not be a video companion for this month.Adobe Patches for May 2026For May, Adobe released 10 bulletins addressing 52 unique CVEs in…

Microsoft Adobe US

· ZDI Blog · The May 2026 Security Update Review

1

The April 2026 Security Update Review

It’s time once again for Patch Tuesday, and this one is huge. We’ve also got multiple exploits in the wild, which adds another layer of urgency to this month’s release. Take a break from your regularly scheduled activities, and let’s take a look at the latest security patches from Adobe and Microsoft. If you’d rather watch the full video recap covering the entire release, you can check it out here: Adobe Patches for April 2026For April, Adobe released 12 bulletins addressing 61 unique CVEs in…

Adobe Microsoft US

· ZDI Blog · The April 2026 Security Update Review

1

Announcing Pwn2Own Berlin for 2026

If you just want to read the contest rules, click here. Willkommen zurück, meine Damen und Herren, zu unserem zweiten Wettbewerb in Berlin! That’s correct (if Google translate didn’t steer me wrong). After our inaugural competition last year, Pwn2Own returns to Berlin and OffensiveCon. Outside of our shipping troubles, we had an amazing time and can’t wait to get back.Last year, we added Artificial Intelligence as a category with great results. This year, we’re expanding this and splitting it…

Microsoft VMware Adobe AWS US

· ZDI Blog · Announcing Pwn2Own Berlin for 2026

1

The March 2026 Security Update Review

I am back in the friendly confines of the Mid-South headquarters of TrendAI ZDI (a.k.a. my home office), and am all set for the third patch Tuesday of 2026. Take a break from your regularly scheduled activities and let’s take a look at the latest security patches from Adobe and Microsoft.If you’d rather watch the full video recap covering the entire release, you can check it out here: Adobe Patches for March 2026For March, Adobe released eight bulletins addressing 80 unique CVEs in Adobe…

Adobe Microsoft US

· ZDI Blog · The March 2026 Security Update Review