Adobe released a broad set of security advisories covering creative, enterprise, and e-commerce products, and the Canadian Centre for Cyber Security urged organizations to review and apply the updates. Affected software includes ColdFusion, Adobe Experience Manager (AEM), Adobe Commerce, Magento Open Source, Animate, After Effects, Audition, Bridge, Media Encoder, Premiere, Premiere Pro, Illustrator, Creative Cloud Desktop Application, and Content Credentials tools and SDKs.
Among the disclosed issues, ColdFusion flaws CVE-2026-48363 and CVE-2026-48364 are uncontrolled search path vulnerabilities that can lead to arbitrary code execution when a user opens a malicious file; Animate bugs CVE-2026-48345 and CVE-2026-48350 can also enable code execution via malicious files through OS command injection and path traversal; and AEM vulnerabilities CVE-2026-48310 and CVE-2026-48252 are more severe for internet-facing deployments because they require no user interaction and can allow arbitrary file reads, unauthorized write access, and security feature bypass. Adobe also issued fixes for multiple Adobe Commerce, Adobe Commerce B2B, Magento Open Source, and Adobe Commerce Webhooks Plugin vulnerabilities, including stored XSS, incorrect authorization, improper output encoding, and unrestricted file upload issues, with patched July 2026 releases and Webhooks Plugin version 1.21.0 identified as remediated versions.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security published alert AV26-697 highlighting Adobe's July 14, 2026 security advisories across numerous Adobe products. The notice urged users and administrators to review Adobe's advisories and apply the necessary updates.
CISA updated its Known Exploited Vulnerabilities catalog and added CVE-2026-56155, CVE-2026-56164, CVE-2026-15409, and CVE-2026-15410. The newly listed flaws affected Microsoft ADFS, Microsoft SharePoint Server, and SonicWall SMA1000 appliances.
Adobe disclosed several vulnerabilities affecting Adobe Commerce, Adobe Commerce B2B, Magento Open Source, and the Adobe Commerce Webhooks Plugin, including CVE-2026-48358, CVE-2026-47984, CVE-2026-47995, CVE-2026-48356, and CVE-2026-47994. The notices identified vulnerable version ranges and July 2026 fixed releases, including Webhooks Plugin version 1.21.0.
Adobe disclosed CVE-2026-48310 and CVE-2026-48252 affecting Adobe Experience Manager as a Cloud Service, 6.5 LTS, and 6.5. The issues include path traversal and missing authentication, with Adobe listing fixed versions and hotfix guidance.
Adobe disclosed CVE-2026-48345 and CVE-2026-48350 affecting Adobe Animate 2023 and 2024. The flaws can lead to arbitrary code execution when a victim opens a malicious file, and Adobe identified fixes in versions 23.0.16 and 24.0.14.
Adobe published security advisories covering multiple product lines including ColdFusion, Animate, Experience Manager, Commerce, Magento Open Source, Creative Cloud Desktop Application, Illustrator, and other creative tools. The advisories addressed critical vulnerabilities and provided updated or fixed versions across the affected products.
Adobe disclosed CVE-2026-48363 and CVE-2026-48364 affecting ColdFusion 2025.9 and earlier and 2023.20 and earlier. Both uncontrolled search path element flaws can lead to arbitrary code execution if a user opens a malicious file, and Adobe referenced advisory APSB26-68.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
16 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecyber.gc.ca
Open sourcecyber.gc.ca
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.