Adobe released security updates for a broad set of products including Acrobat and Reader, Experience Manager, Media Encoder, Illustrator, After Effects, Animate, InDesign, PDFL SDK, Connect, Photoshop, Premiere Pro, Bridge, FrameMaker, and multiple Substance 3D applications. The advisories cover 165 vulnerabilities, including 45 rated critical, with impacts spanning remote code execution, privilege escalation, unauthorized access to sensitive data, security feature bypass, and denial of service.
Many of the most severe issues can be triggered by opening specially crafted files, creating a significant risk for desktop creative tools such as Acrobat, Illustrator, After Effects, and Media Encoder, while some Adobe Connect flaws can be exploited remotely without authentication and include reflected XSS and privilege-escalation issues. Adobe published product-specific bulletins for affected offerings such as APSB24-92 for Acrobat, APSB24-69 for Experience Manager, APSB24-93 for Media Encoder, APSB24-94 for Illustrator, and APSB24-95 for After Effects, and urged customers to upgrade to the patched versions immediately.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
Adobe published security bulletins and updates for multiple products including Acrobat, After Effects, Illustrator, Media Encoder, and Experience Manager. CSIRT.SK reported that the broader December release addressed 165 vulnerabilities, including 45 rated critical, and Adobe recommended immediate upgrades to the fixed versions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
csirt.sk
Open sourcehelpx.adobe.com
Open sourcehelpx.adobe.com
Open sourcehelpx.adobe.com
Open sourcehelpx.adobe.com
Open sourcehelpx.adobe.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.