Adobe released security updates for After Effects, Audition, Bridge, Illustrator, Substance 3D Painter, and additional products including InDesign, Photoshop, and Adobe Commerce/Magento Open Source, addressing 48 vulnerabilities in total. According to CSIRT.SK, 28 of the flaws are rated critical, and the most severe issues could let an unauthenticated attacker achieve arbitrary code execution if a user is tricked into opening a specially crafted file in affected creative applications.
The advisories also cover weaknesses that could lead to sensitive data exposure, security feature bypass, denial of service, and server-side request forgery (SSRF). Most of the code-execution bugs require user interaction, but the Adobe Commerce/Magento SSRF issue reportedly does not require user interaction, increasing risk for exposed deployments. Organizations using affected Adobe desktop software and commerce platforms were urged to apply the vendor patches promptly.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
Adobe released security updates for Adobe Bridge, Audition, After Effects, Substance 3D Painter, Illustrator, InDesign, Photoshop, and Commerce/Magento Open Source to address 48 vulnerabilities, including 28 rated critical. The most severe issues could allow arbitrary code execution via specially crafted files, and the Commerce/Magento flaw could enable SSRF without user interaction.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
csirt.sk
Open sourcehelpx.adobe.com
Open sourcehelpx.adobe.com
Open sourcehelpx.adobe.com
Open sourcehelpx.adobe.com
Open sourcehelpx.adobe.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.