Adobe released security updates for 36 vulnerabilities across products including Adobe Connect, Adobe Experience Manager (AEM) Forms, Bridge, Content Credentials Rust SDK, C2PA Tool, InDesign, Premiere Pro, and Substance 3D Modeler. The fixes cover nine critical- and 17 high-severity issues, with impacts including arbitrary code execution, privilege escalation, security-feature bypass, information disclosure, and denial of service.
Adobe Connect fixes include critical SQL injection, cross-site scripting, and input-validation flaws affecting Android, macOS, and Windows; CVE-2026-75682 carries a CVSS score of 9.9 and could allow malicious code deployment and execution, while CVE-2026-75684 can enable privilege escalation. AEM Forms also received patches for critical authorization, input-validation, and server-side request forgery issues, including code-execution flaw CVE-2026-75745. Adobe reports no known in-the-wild exploitation, but advises customers to apply the updates and hotfixes; Connect and AEM Forms advisories are rated priority 2, calling for remediation within 30 days.

See real exploitation activity before you spend the cycle.
1 event from the most recent confirmed update back to the earliest known activity.
Adobe released security patches for 36 vulnerabilities affecting products including Connect, Experience Manager Forms, Bridge, Content Credentials, InDesign, Substance 3D Modeler, and Premiere Pro. The updates addressed critical flaws in Connect and AEM Forms that could enable arbitrary code execution or privilege escalation; Adobe said it was unaware of active exploitation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
securityweek.com
Open sourceacn.gov.it
Open sourceheise.de
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.