www.securityweek.com 23 Sept 2026, 11:40 UTC

Adobe Patches Critical Connect and AEM Forms Flaws Enabling Code Execution

Adobe Patches Critical Connect and AEM Forms Flaws Enabling Code Execution

ADOBE has released patches for 36 vulnerabilities, including critical flaws in Adobe Connect and Experience Manager (AEM) Forms. The Connect update addresses nine defects, six of them critical, that could allow arbitrary code execution or privilege escalation. Tracked as CVE-2026-75682, CVE-2026-75684, CVE-2026-75686, CVE-2026-75689, CVE-2026-75697 and CVE-2026-75698, they involve SQL injection, cross-site scripting (XSS) and improper input validation.

The update also fixes high-severity path-traversal, certificate-validation and XSS vulnerabilities, with potential consequences including arbitrary file-system reads, security-feature bypasses and code execution.

Six vulnerabilities were fixed in AEM Forms, including three critical issues that could lead to code execution and privilege escalation. These are described as incorrect authorisation, improper input validation and server-side request forgery (SSRF), and tracked as CVE-2026-75745, CVE-2026-81995 and CVE-2026-82000. Three additional high-severity SSRF, XSS and cross-site request-forgery flaws could enable privilege escalation, code execution or security-feature bypasses. Adobe rated both updates priority 2, recommending that customers apply them within the next 30 days.

Adobe also patched high- and medium-severity vulnerabilities in InDesign, Content Credentials SDK, Bridge, Substance 3D Modeler and Premiere Pro. Potential impacts include denial-of-service, security-feature bypass, arbitrary code execution and memory exposure. Adobe said it was not aware of any of the vulnerabilities being exploited in the wild and directed users to its security bulletins for further information.

View full article

Article by CyberSIXT