Adobe released security updates for multiple critical vulnerabilities affecting Adobe FrameMaker Publishing Server, Adobe Commerce, Magento Open Source, and the Adobe Commerce Webhooks extension. The most serious issues include CVE-2024-30299 and CVE-2024-30300 in FrameMaker Publishing Server and CVE-2024-34102 in Adobe Commerce and Magento, with severity reaching CVSS 10.0. Successful exploitation could allow arbitrary code execution, security feature bypass, and privilege escalation.
Adobe also issued critical fixes for Adobe Experience Manager, Creative Cloud Desktop, Photoshop, and Substance 3D Stager to address vulnerabilities that could enable code execution, unauthorized system access, and exposure of sensitive data. National cybersecurity authorities highlighted the breadth and severity of the flaws and urged organizations using affected Adobe products to apply vendor patches immediately in line with Adobe guidance.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Alongside the above fixes, Adobe also released critical security updates for Adobe Experience Manager, Adobe Creative Cloud Desktop, Adobe Photoshop, and Adobe Substance 3D Stager. These updates addressed vulnerabilities that could allow code execution, system access, or unauthorized access to data.
Adobe issued security updates for Adobe FrameMaker Publishing Server, Adobe Commerce, Magento Open Source, and the Adobe Commerce Webhooks extension to fix multiple critical vulnerabilities. The flaws included CVE-2024-30299 and CVE-2024-30300 in FrameMaker Publishing Server and CVE-2024-34102 in Adobe Commerce and Magento, with potential impacts including remote code execution, security feature bypass, and privilege escalation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
kyberturvallisuuskeskus.fi
Open sourcekyberturvallisuuskeskus.fi
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.