Adobe released security updates for InDesign, InCopy, Illustrator, Substance 3D Stager, and Adobe Commerce/Magento, alongside fixes noted for Substance 3D Designer and Photoshop Elements, addressing 45 vulnerabilities in total. According to CSIRT.SK, 23 of the flaws are rated critical, with impact ranging from remote code execution and privilege escalation to security feature bypass, unauthorized access to sensitive data, and denial of service.
The most serious issues affect both desktop creative applications and Adobe Commerce deployments. CSIRT.SK said several Commerce vulnerabilities can be exploited with no user interaction and include authorization failures, access-control weaknesses, path traversal, and stored XSS, while the desktop product flaws include critical memory-corruption bugs that could lead to code execution. Adobe published separate security bulletins for the affected products and urged customers to update to the fixed versions as soon as possible.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
CSIRT.SK published an advisory highlighting the critical Adobe vulnerabilities and urging users and administrators to update affected products to the fixed versions. The notice also warned against opening messages or attachments from untrusted sources.
Adobe released security updates for InDesign, Commerce/Magento, Substance 3D Stager, InCopy, Illustrator, Substance 3D Designer, and Photoshop Elements to address 45 vulnerabilities, including 23 rated critical. The flaws included issues that could lead to remote code execution, privilege escalation, security feature bypass, unauthorized access to sensitive data, and denial of service.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
csirt.sk
Open sourcehelpx.adobe.com
Open sourcehelpx.adobe.com
Open sourcehelpx.adobe.com
Open sourcehelpx.adobe.com
Open sourcehelpx.adobe.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.