2026年9月9日星期三

Adobe Monthly Security Update (September 2026)

Adobe Monthly Security Update (September 2026)

Release Date: 9 Sep 2026 

Adobe has released monthly security update for their products:

 

Vulnerable ProductRisk LevelImpactsNotesDetails (including CVE)
Adobe Experience ManagerMedium Risk Medium RiskRemote Code Execution
Cross-site Scripting
Elevation of Privilege
Security Restriction Bypass
 APSB26-98
Adobe ColdFusionMedium Risk Medium RiskRemote Code Execution
Cross-site Scripting
Elevation of Privilege
Information Disclosure
Denial of Service
 APSB26-119
Adobe PhotoshopMedium Risk Medium RiskRemote Code Execution APSB26-130
Adobe IllustratorMedium Risk Medium RiskRemote Code Execution APSB26-131
Adobe AnimateMedium Risk Medium RiskRemote Code Execution APSB26-132
Adobe Photoshop MobileMedium Risk Medium RiskElevation of Privilege
Security Restriction Bypass
 APSB26-136
Adobe CommerceMedium Risk Medium RiskCross-site Scripting
Elevation of Privilege
Security Restriction Bypass
 APSB26-138
Adobe Acrobat ReaderMedium Risk Medium RiskElevation of Privilege
Information Disclosure
Remote Code Execution
Data Manipulation
Denial of Service
 APSB26-141
Adobe Campaign ClassicMedium Risk Medium RiskRemote Code Execution APSB26-142
Adobe CommerceExtremely High Risk Extremely High RiskRemote Code Execution

CVE-2026-75650 is being exploited in the wild. It is a remote code execution vulnerability in Adobe Commerce, Adobe Commerce B2B and Magento Open Source. Successful exploitation grants an unauthenticated attacker the ability to execute arbitrary code on a vulnerable server. Hence, the risk level is rated as Extremely High Risk.

APSB26-146

 

Number of 'Extremely High Risk' product(s): 1

Number of 'High Risk' product(s): 0

Number of 'Medium Risk' product(s): 9

Number of 'Low Risk' product(s): 0

Evaluation of overall 'Risk Level': Extremely High Risk


Impact

  • Remote Code Execution
  • Cross-Site Scripting
  • Denial of Service
  • Elevation of Privilege
  • Data Manipulation
  • Information Disclosure
  • Security Restriction Bypass

System / Technologies affected

  • Adobe Experience Manager (AEM) AEM Cloud Service (CS) Release 2026.7.0 and earlier versions
  • Adobe Experience Manager (AEM) 6.5 LTS Service Pack 2 and earlier versions
  • Adobe Experience Manager (AEM) 6.5 Service Pack 24 and earlier versions
  • ColdFusion 2025 2025.0.12 and earlier versions
  • ColdFusion 2023 2023.0.23 and earlier versions
  • Photoshop 2026 27.6 and earlier versions
  • Photoshop 2025 26.11.6 and earlier versions
  • Illustrator 2025 29.8.10 and earlier versions
  • Illustrator 2026 30.7 and earlier versions
  • Adobe Animate 2023 23.0.16 and earlier versions
  • Adobe Animate 2024 24.0.14 and earlier versions
  • Adobe Commerce 2.4.9-2026-aug and earlier versions
  • Adobe Commerce B2B 1.5.3-2026-aug and earlier versions
  • Magento Open Source 2.4.9-2026-aug and earlier versions
  • Adobe Acrobat 26.002.21900 and earlier versions
  • Acrobat Reader 26.002.21900 and earlier versions
  • Acrobat 2024 24.001.30383 and earlier versions
  • Adobe Campaign Classic ACC v7: 7.4.4 build 9401 and earlier versions

Solutions

Before installation of the software, please visit the vendor web-site for more details.

  • Apply fixes issued by the vendor. Please refer to 'Details' column in the above table for details of individual product update or run software update.

Vulnerability Identifier


Source


Related Link

沒有留言:

發佈留言

MongoDB 多個漏洞

MongoDB 多個漏洞 發佈日期: 2026年09月10日 於 MongoDB 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、彷冒、遠端執行任意程式碼、洩露敏感資料、資料篡改及繞過保安限制。 影響 阻斷服務 資料洩露 遠端執行程式碼 繞過保安限制...