< ciso
brief />
Tag Banner

All news with #adobe tag

41 articles

Adobe Commerce flaw exploited to hijack customer accounts

๐Ÿ”’ Adobe patched a critical incorrect-authorization vulnerability (CVE-2026-71362) in its Commerce and Magento platforms after researchers observed exploitation attempts that can let attackers switch customer sessions and access private data. Sansec's Shield WAF reportedly blocked attacks and found the flaw required no account, admin rights, or user interaction. Administrators are urged to apply the August 2026 isolated patches after ensuring the correct -p release is installed.
read more โ†’

Adobe issues urgent patches for critical ColdFusion flaws

๐Ÿ”’ Adobe released security updates to address multiple critical vulnerabilities in ColdFusion, Commerce, and Campaign Classic. Several flaws carry maximum or near-maximum CVSS scores and could enable arbitrary code execution or privilege escalation. Updates for ColdFusion and Campaign Classic are rated Priority 1, and on-premise Campaign Classic customers must patch promptly; Adobe-hosted instances are already remediated.
read more โ†’

Adobe fixes CVSS 10.0 flaw in Campaign Classic

๐Ÿ›ก๏ธ Adobe released updates for Campaign Classic (ACC) to patch a maximum-severity authorization vulnerability (CVE-2026-48449, CVSS 10.0) that could enable arbitrary code execution without user interaction. The fixes, delivered in ACC v7.4.3 build 9398 for Windows and Linux, also address a high-severity SQL injection (CVE-2026-48448, CVSS 8.6) enabling arbitrary file reads. Adobe additionally remediated eight critical-rated flaws in Adobe Bridge that could lead to privilege escalation and code execution, crediting multiple external researchers. Users are urged to apply the updates promptly for protection.
read more โ†’

NVIDIA Leads New Open Secure AI Alliance Initiative

๐Ÿ›ก๏ธ NVIDIA has convened nearly 40 technology firms to form the Open Secure AI Alliance, a coalition aimed at building open source security tools for AI, announced on July 27. Members include Adobe, Cisco, Microsoft, CloudStrike, SpaceX, SAP and the Linux Foundation, while notable frontier model developers such as Google, Anthropic and OpenAI are absent. The alliance will focus on finding, fixing and disclosing vulnerabilities, and aims to create an open defense stack for agents, covering identity, isolation, secure model formats and secure coding workflows.
read more โ†’

Adobe Acrobat Chrome Extension UXSS Flaw Exposes Data

๐Ÿ›ก๏ธ Researchers disclosed a now-patched vulnerability chain in the Adobe Acrobat Chrome extension (ID: efaidnbmnnnibpcajpcglclefindmkaj) affecting versions up to 26.5.2.2. Tracked as CVE-2026-48294 and dubbed HermeticReader by Guardio Labs, the UXSS-class issue (CVSS 7.4) allowed cross-origin read access to session-bound data after simple user interaction. Exploitation required visiting a crafted page that triggers the extension's vulnerable code path, enabling attackers to extract WhatsApp Web content without credentials or malware.
read more โ†’

Adobe Chrome extension flaw exposed WhatsApp data

๐Ÿ”’ The Adobe Acrobat extension for Chrome contained a chain of vulnerabilities (CVE-2026-48294, dubbed HermeticReader) that let attacker-controlled websites access conversations and other data rendered in WhatsApp Web without authentication. Guardio researchers showed the flaw allowed web pages to write into the extension's storage, activate its WhatsApp integration (Hermes), and issue DOM-manipulating commands to a WhatsApp tab. Adobe patched the issue in version 26.5.2.3; users should ensure they have the update.
read more โ†’

Mozilla, Google, Adobe and VMware issue critical patches

๐Ÿ›ก๏ธ Mozilla, Google, Adobe and VMware released updates addressing multiple critical vulnerabilities across Firefox, Chrome, Adobe products, and VMware Avi Load Balancer. Mozilla patched two critical Firefox bugs (CVE-2026-15718, CVE-2026-15719) with exploit code publicly disclosed and fixed in Firefox 152.0.6. Google fixed 15 Chrome vulnerabilities including two critical Ozone use-after-free flaws, and Adobe addressed 88 issues across ColdFusion, Commerce, Experience Manager, and Illustrator. Broadcom remediated a critical authentication bypass in VMware Avi Load Balancer (CVE-2026-47865). Organizations are advised to apply updates promptly to mitigate risk.
read more โ†’

CISA directs federal patch for ColdFusion zero-day

๐Ÿ”’ The U.S. Cybersecurity and Infrastructure Security Agency has ordered federal agencies to patch an actively exploited, maximum-severity vulnerability in Adobe ColdFusion (CVE-2026-48282) by Friday. Adobe published fixes for affected ColdFusion versions last week and urged administrators to install updates immediately. The flaw enables unauthenticated remote code execution in low-complexity attacks and has been observed in the wild soon after disclosure. CISA added the issue to its KEV catalog and invoked BOD 26-04 to enforce remediation timelines for FCEB agencies.
read more โ†’

CISA Adds Four Newly Exploited Vulnerabilities

๐Ÿ›ก๏ธ The US Cybersecurity and Infrastructure Security Agency (CISA) added four vulnerabilities to its Known Exploited Vulnerabilities catalog, citing active exploitation. The flaws include critical Adobe ColdFusion path traversal (CVE-2026-48282), Joomlack Page Builder improper access control (CVE-2026-56290), Langflow authorization bypass (CVE-2026-55255), and JoomShaper SP Page Builder unrestricted file upload (CVE-2026-48908). Exploitation observed ranged from immediate post-disclosure attacks to targeted campaigns stealing credentials and deploying web shells. Agencies are urged to apply patches by July 10, 2026.
read more โ†’

Adobe warns of exploited maximum severity ColdFusion flaw

๐Ÿ›ก๏ธ Adobe has urged ColdFusion customers to patch immediately after at least one maximum severity flaw was reported as being exploited. The company released fixes for 11 CVEs in the APSB26-68 bulletin on June 30, six carrying a CVSS score of 10. Researchers reported that CVE-2026-48282, a path traversal allowing potential arbitrary code execution, was targeted within hours of disclosure. There are 775 exposed ColdFusion instances online, increasing the risk for rapid exploitation.
read more โ†’

Max-severity Adobe ColdFusion flaw being actively exploited

๐Ÿ”ง Adobe has issued emergency updates to fix a maximum-severity ColdFusion vulnerability (CVE-2026-48282) that is now being actively exploited, the Canadian Center for Cyber Security (CCCS) warned. The flaw affects ColdFusion 2025.9, 2023.20, and earlier, enabling unauthenticated remote code execution on unpatched systems. Adobe urges administrators to install the patch immediately, and Shadowserver reports nearly 800 exposed ColdFusion instances online.
read more โ†’

Adobe adds second monthly Patch Tuesday cycle

๐Ÿ›ก๏ธ Adobe will publish security updates twice each month to address faster vulnerability discovery and exploitation. The company will keep its existing second-Tuesday schedule and add a fourth-Tuesday release starting July, applying to advisories with CVEs needing customer action. Adobe cited increased threats and investment in vulnerability discovery as drivers for the new cadence. The change mirrors industry trends toward more frequent patching.
read more โ†’

Adobe fixes critical ColdFusion and Campaign flaws

๐Ÿ›ก๏ธ Adobe released urgent patches addressing multiple maximum-severity vulnerabilities in ColdFusion and Adobe Campaign Classic, including several CVSS 10.0 issues. The ColdFusion fixes are included in ColdFusion 2023 Update 21 and ColdFusion 2025 Update 10, while the Campaign patch is in ACC v7: 7.4.3 build 9397. Adobe reports no known active exploitation and credited external researchers for several reports.
read more โ†’

Adobe fixes seven critical ColdFusion and Campaign flaws

๐Ÿ›ก๏ธ Adobe released patches addressing seven maximum-severity vulnerabilities in ColdFusion and Campaign Classic. These issues allow low-complexity, no-interaction attacks and were assigned priority 1, prompting administrators to update within 72 hours. Six flaws impact ColdFusion 2025.9, 2023.20 and earlier, enabling remote code execution, while one affects on-premises Campaign Classic builds and may permit arbitrary code execution in the user context.
read more โ†’

Amazon Quick expands integrations with 16 new connectors

๐Ÿ”— Amazon Quick now connects to 16 additional tools including Adobe, Figma, WhatsApp, Snowflake, and Smartsheet, enabling teams to act on insights without switching context. The new connectors span productivity, design, analytics, financial intelligence, commerce, and communication, so teams can build cross-tool workflows inside Quick. Integrations are available in all AWS Regions where Amazon Quick is offered.
read more โ†’

June Patch Tuesday: Record CVE Count and Critical Fixes

๐Ÿ”’ June Patch Tuesday brought an unprecedented wave of fixes: Microsoft released over 200 CVEs including three disclosed zero-days and 32 critical patches, while SAP and Adobe patched multiple high-severity enterprise flaws. Microsoft warns this increase may become the new normal as AI accelerates vulnerability discovery, urging risk-based prioritization and automated patching. Administrators should urgently assess critical kernel, Active Directory, Hyper-V, and Exchange fixes.
read more โ†’

Talos Discloses TP-Link, Photoshop, OpenVPN, Norton Flaws

๐Ÿ”’ Cisco Talos disclosed multiple vulnerabilities affecting TPโ€‘Link, Adobe Photoshop, OpenVPN, and Norton VPN. Most issues were patched by vendors under Ciscoโ€™s thirdโ€‘party disclosure policy; the Norton installer flaw was observed in use before a patch was available. The TPโ€‘Link Archer AX53 firmware contains eight issues including buffer overflow and several command injection and configโ€‘control flaws that allow code execution or arbitrary file access. Talos recommends applying vendor updates and using updated Snort rules to detect exploitation.
read more โ†’

April Patch Tuesday: Critical Flaws in SAP, Adobe, Microsoft

๐Ÿ”’ April's Patch Tuesday addresses critical vulnerabilities across major vendors. Patches fix a near-critical SQL injection in SAP (CVE-2026-27681) that enables arbitrary database commands, an actively exploited RCE in Adobe Acrobat Reader (CVE-2026-34621), and numerous high-severity Microsoft, Fortinet, and ColdFusion issues. FortiSandbox fixes close authentication-bypass and command-injection holes, while Adobe's ColdFusion updates remediate multiple code execution and path-traversal flaws. Organizations should prioritize vendor updates and apply mitigations where immediate patching is not possible.
read more โ†’

CISA Adds Six Actively Exploited Flaws in Major Software

๐Ÿ›ก๏ธ CISA on Apr 14, 2026 added six vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after observing active exploitation. The flaws affect Fortinet FortiClient EMS, Microsoft components (Exchange Server, Windows drivers, Host Process for Windows Tasks, VBA) and Adobe Acrobat Reader, and include SQL injection, deserialization, out-of-bounds read, use-after-free and insecure library loading. Federal civilian agencies must remediate by April 27, 2026.
read more โ†’

Adobe issues emergency patch for Acrobat/Reader zero-day

๐Ÿ”’ Adobe released an emergency security update to fix a zero-day tracked as CVE-2026-34621, which has been exploited since at least December to bypass Acrobat/Reader sandbox protections. The flaw lets malicious PDFs invoke privileged JavaScript APIs (for example util.readFileIntoStream() and RSS.addFeed()) to read local files and exfiltrate data with no user interaction beyond opening the file. Affected versions of Acrobat DC, Acrobat Reader DC and Acrobat 2024 have fixes available; Adobe urges users to update via Help > Check for Updates or by downloading the installer.
read more โ†’