Adobe Monthly Security Update (September 2026)
Adobe has released monthly security update for their products:
| Vulnerable Product | Risk Level | Impacts | Notes | Details (including CVE) |
| Adobe Experience Manager | Medium Risk | Remote Code Execution Cross-site Scripting Elevation of Privilege Security Restriction Bypass | APSB26-98 | |
| Adobe ColdFusion | Medium Risk | Remote Code Execution Cross-site Scripting Elevation of Privilege Information Disclosure Denial of Service | APSB26-119 | |
| Adobe Photoshop | Medium Risk | Remote Code Execution | APSB26-130 | |
| Adobe Illustrator | Medium Risk | Remote Code Execution | APSB26-131 | |
| Adobe Animate | Medium Risk | Remote Code Execution | APSB26-132 | |
| Adobe Photoshop Mobile | Medium Risk | Elevation of Privilege Security Restriction Bypass | APSB26-136 | |
| Adobe Commerce | Medium Risk | Cross-site Scripting Elevation of Privilege Security Restriction Bypass | APSB26-138 | |
| Adobe Acrobat Reader | Medium Risk | Elevation of Privilege Information Disclosure Remote Code Execution Data Manipulation Denial of Service | APSB26-141 | |
| Adobe Campaign Classic | Medium Risk | Remote Code Execution | APSB26-142 | |
| Adobe Commerce | Extremely High Risk | Remote Code Execution | CVE-2026-75650 is being exploited in the wild. It is a remote code execution vulnerability in Adobe Commerce, Adobe Commerce B2B and Magento Open Source. Successful exploitation grants an unauthenticated attacker the ability to execute arbitrary code on a vulnerable server. Hence, the risk level is rated as Extremely High Risk. | APSB26-146 |
Number of 'Extremely High Risk' product(s): 1
Number of 'High Risk' product(s): 0
Number of 'Medium Risk' product(s): 9
Number of 'Low Risk' product(s): 0
Evaluation of overall 'Risk Level': Extremely High Risk
Impact
- Remote Code Execution
- Cross-Site Scripting
- Denial of Service
- Elevation of Privilege
- Data Manipulation
- Information Disclosure
- Security Restriction Bypass
System / Technologies affected
- Adobe Experience Manager (AEM) AEM Cloud Service (CS) Release 2026.7.0 and earlier versions
- Adobe Experience Manager (AEM) 6.5 LTS Service Pack 2 and earlier versions
- Adobe Experience Manager (AEM) 6.5 Service Pack 24 and earlier versions
- ColdFusion 2025 2025.0.12 and earlier versions
- ColdFusion 2023 2023.0.23 and earlier versions
- Photoshop 2026 27.6 and earlier versions
- Photoshop 2025 26.11.6 and earlier versions
- Illustrator 2025 29.8.10 and earlier versions
- Illustrator 2026 30.7 and earlier versions
- Adobe Animate 2023 23.0.16 and earlier versions
- Adobe Animate 2024 24.0.14 and earlier versions
- Adobe Commerce 2.4.9-2026-aug and earlier versions
- Adobe Commerce B2B 1.5.3-2026-aug and earlier versions
- Magento Open Source 2.4.9-2026-aug and earlier versions
- Adobe Acrobat 26.002.21900 and earlier versions
- Acrobat Reader 26.002.21900 and earlier versions
- Acrobat 2024 24.001.30383 and earlier versions
- Adobe Campaign Classic ACC v7: 7.4.4 build 9401 and earlier versions
Solutions
Before installation of the software, please visit the vendor web-site for more details.
- Apply fixes issued by the vendor. Please refer to 'Details' column in the above table for details of individual product update or run software update.


沒有留言:
發佈留言