< ciso
brief />
Tag Banner

All news with #adobe tag

45 articles

Multiple Vendor Vulnerabilities and Vendor Patches

🔒 Cisco Talos disclosed multiple vulnerabilities affecting Adobe, Apple, Foxit Reader, and Microsoft. The vendors have issued patches in accordance with Cisco’s disclosure policy. Snort rule updates are available to detect exploitation, and Talos posts ongoing vulnerability advisories on its site. Affected components include Photoshop installer, macOS CoreWLAN, Foxit PDF JavaScript features, and several Windows kernel drivers.
read more →

CISA Alerts: Active Exploits in WSO2, Adobe, SharePoint

⚠️ CISA warns that multiple critical and high-severity vulnerabilities in WSO2, Adobe Commerce, Microsoft SharePoint, and Mikrotik RouterOS are being actively exploited. Two critical flaws—CVE-2026-5430 in WSO2 and CVE-2026-71362 in Adobe Commerce—were added to the Known Exploited Vulnerabilities catalog with federal mitigation deadlines. Agencies must patch or mitigate by the specified dates, and organizations are urged to prioritize these fixes.
read more →

CISA Adds Critical WSO2 and Adobe Flaws to KEV

🔒 CISA has added two critical vulnerabilities—affecting WSO2 and Adobe Commerce/Magento—to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. The flaws include a path traversal and unrestricted file upload in WSO2 leading to remote code execution, and an authorization bypass in Adobe Commerce that allows customer account takeover. Federal agencies are advised to patch by September 27, 2026.
read more →

Adobe issues emergency patch for Magento zero-day

🛡️ Adobe has released emergency patches addressing a maximum-severity zero-day, CVE-2026-75650, actively exploited in Adobe Commerce and Magento Open Source. Sansec dubbed the flaw "StyleSmuggler" after detecting exploitation beginning September 4, 2026. The vulnerability enables PHP code injection via Magento's template system to generate a malicious email and achieve remote code execution. A VULN-39341 hotfix and encryption key rotation are required to remediate affected versions.
read more →

Adobe Commerce flaw exploited to hijack customer accounts

🔒 Adobe patched a critical incorrect-authorization vulnerability (CVE-2026-71362) in its Commerce and Magento platforms after researchers observed exploitation attempts that can let attackers switch customer sessions and access private data. Sansec's Shield WAF reportedly blocked attacks and found the flaw required no account, admin rights, or user interaction. Administrators are urged to apply the August 2026 isolated patches after ensuring the correct -p release is installed.
read more →

Adobe issues urgent patches for critical ColdFusion flaws

🔒 Adobe released security updates to address multiple critical vulnerabilities in ColdFusion, Commerce, and Campaign Classic. Several flaws carry maximum or near-maximum CVSS scores and could enable arbitrary code execution or privilege escalation. Updates for ColdFusion and Campaign Classic are rated Priority 1, and on-premise Campaign Classic customers must patch promptly; Adobe-hosted instances are already remediated.
read more →

Adobe fixes CVSS 10.0 flaw in Campaign Classic

🛡️ Adobe released updates for Campaign Classic (ACC) to patch a maximum-severity authorization vulnerability (CVE-2026-48449, CVSS 10.0) that could enable arbitrary code execution without user interaction. The fixes, delivered in ACC v7.4.3 build 9398 for Windows and Linux, also address a high-severity SQL injection (CVE-2026-48448, CVSS 8.6) enabling arbitrary file reads. Adobe additionally remediated eight critical-rated flaws in Adobe Bridge that could lead to privilege escalation and code execution, crediting multiple external researchers. Users are urged to apply the updates promptly for protection.
read more →

NVIDIA Leads New Open Secure AI Alliance Initiative

🛡️ NVIDIA has convened nearly 40 technology firms to form the Open Secure AI Alliance, a coalition aimed at building open source security tools for AI, announced on July 27. Members include Adobe, Cisco, Microsoft, CloudStrike, SpaceX, SAP and the Linux Foundation, while notable frontier model developers such as Google, Anthropic and OpenAI are absent. The alliance will focus on finding, fixing and disclosing vulnerabilities, and aims to create an open defense stack for agents, covering identity, isolation, secure model formats and secure coding workflows.
read more →

Adobe Acrobat Chrome Extension UXSS Flaw Exposes Data

🛡️ Researchers disclosed a now-patched vulnerability chain in the Adobe Acrobat Chrome extension (ID: efaidnbmnnnibpcajpcglclefindmkaj) affecting versions up to 26.5.2.2. Tracked as CVE-2026-48294 and dubbed HermeticReader by Guardio Labs, the UXSS-class issue (CVSS 7.4) allowed cross-origin read access to session-bound data after simple user interaction. Exploitation required visiting a crafted page that triggers the extension's vulnerable code path, enabling attackers to extract WhatsApp Web content without credentials or malware.
read more →

Adobe Chrome extension flaw exposed WhatsApp data

🔒 The Adobe Acrobat extension for Chrome contained a chain of vulnerabilities (CVE-2026-48294, dubbed HermeticReader) that let attacker-controlled websites access conversations and other data rendered in WhatsApp Web without authentication. Guardio researchers showed the flaw allowed web pages to write into the extension's storage, activate its WhatsApp integration (Hermes), and issue DOM-manipulating commands to a WhatsApp tab. Adobe patched the issue in version 26.5.2.3; users should ensure they have the update.
read more →

Mozilla, Google, Adobe and VMware issue critical patches

🛡️ Mozilla, Google, Adobe and VMware released updates addressing multiple critical vulnerabilities across Firefox, Chrome, Adobe products, and VMware Avi Load Balancer. Mozilla patched two critical Firefox bugs (CVE-2026-15718, CVE-2026-15719) with exploit code publicly disclosed and fixed in Firefox 152.0.6. Google fixed 15 Chrome vulnerabilities including two critical Ozone use-after-free flaws, and Adobe addressed 88 issues across ColdFusion, Commerce, Experience Manager, and Illustrator. Broadcom remediated a critical authentication bypass in VMware Avi Load Balancer (CVE-2026-47865). Organizations are advised to apply updates promptly to mitigate risk.
read more →

CISA directs federal patch for ColdFusion zero-day

🔒 The U.S. Cybersecurity and Infrastructure Security Agency has ordered federal agencies to patch an actively exploited, maximum-severity vulnerability in Adobe ColdFusion (CVE-2026-48282) by Friday. Adobe published fixes for affected ColdFusion versions last week and urged administrators to install updates immediately. The flaw enables unauthenticated remote code execution in low-complexity attacks and has been observed in the wild soon after disclosure. CISA added the issue to its KEV catalog and invoked BOD 26-04 to enforce remediation timelines for FCEB agencies.
read more →

CISA Adds Four Newly Exploited Vulnerabilities

🛡️ The US Cybersecurity and Infrastructure Security Agency (CISA) added four vulnerabilities to its Known Exploited Vulnerabilities catalog, citing active exploitation. The flaws include critical Adobe ColdFusion path traversal (CVE-2026-48282), Joomlack Page Builder improper access control (CVE-2026-56290), Langflow authorization bypass (CVE-2026-55255), and JoomShaper SP Page Builder unrestricted file upload (CVE-2026-48908). Exploitation observed ranged from immediate post-disclosure attacks to targeted campaigns stealing credentials and deploying web shells. Agencies are urged to apply patches by July 10, 2026.
read more →

Adobe warns of exploited maximum severity ColdFusion flaw

🛡️ Adobe has urged ColdFusion customers to patch immediately after at least one maximum severity flaw was reported as being exploited. The company released fixes for 11 CVEs in the APSB26-68 bulletin on June 30, six carrying a CVSS score of 10. Researchers reported that CVE-2026-48282, a path traversal allowing potential arbitrary code execution, was targeted within hours of disclosure. There are 775 exposed ColdFusion instances online, increasing the risk for rapid exploitation.
read more →

Max-severity Adobe ColdFusion flaw being actively exploited

🔧 Adobe has issued emergency updates to fix a maximum-severity ColdFusion vulnerability (CVE-2026-48282) that is now being actively exploited, the Canadian Center for Cyber Security (CCCS) warned. The flaw affects ColdFusion 2025.9, 2023.20, and earlier, enabling unauthenticated remote code execution on unpatched systems. Adobe urges administrators to install the patch immediately, and Shadowserver reports nearly 800 exposed ColdFusion instances online.
read more →

Adobe adds second monthly Patch Tuesday cycle

🛡️ Adobe will publish security updates twice each month to address faster vulnerability discovery and exploitation. The company will keep its existing second-Tuesday schedule and add a fourth-Tuesday release starting July, applying to advisories with CVEs needing customer action. Adobe cited increased threats and investment in vulnerability discovery as drivers for the new cadence. The change mirrors industry trends toward more frequent patching.
read more →

Adobe fixes critical ColdFusion and Campaign flaws

🛡️ Adobe released urgent patches addressing multiple maximum-severity vulnerabilities in ColdFusion and Adobe Campaign Classic, including several CVSS 10.0 issues. The ColdFusion fixes are included in ColdFusion 2023 Update 21 and ColdFusion 2025 Update 10, while the Campaign patch is in ACC v7: 7.4.3 build 9397. Adobe reports no known active exploitation and credited external researchers for several reports.
read more →

Adobe fixes seven critical ColdFusion and Campaign flaws

🛡️ Adobe released patches addressing seven maximum-severity vulnerabilities in ColdFusion and Campaign Classic. These issues allow low-complexity, no-interaction attacks and were assigned priority 1, prompting administrators to update within 72 hours. Six flaws impact ColdFusion 2025.9, 2023.20 and earlier, enabling remote code execution, while one affects on-premises Campaign Classic builds and may permit arbitrary code execution in the user context.
read more →

Amazon Quick expands integrations with 16 new connectors

🔗 Amazon Quick now connects to 16 additional tools including Adobe, Figma, WhatsApp, Snowflake, and Smartsheet, enabling teams to act on insights without switching context. The new connectors span productivity, design, analytics, financial intelligence, commerce, and communication, so teams can build cross-tool workflows inside Quick. Integrations are available in all AWS Regions where Amazon Quick is offered.
read more →

June Patch Tuesday: Record CVE Count and Critical Fixes

🔒 June Patch Tuesday brought an unprecedented wave of fixes: Microsoft released over 200 CVEs including three disclosed zero-days and 32 critical patches, while SAP and Adobe patched multiple high-severity enterprise flaws. Microsoft warns this increase may become the new normal as AI accelerates vulnerability discovery, urging risk-based prioritization and automated patching. Administrators should urgently assess critical kernel, Active Directory, Hyper-V, and Exchange fixes.
read more →