Adobe Warns of Critical Security Flaws Across Popular Software; Urges Immediate Patching
September 23, 2026
Adobe warns of multiple critical vulnerabilities across several products, including Connect, Experience Manager Forms, Bridge, InDesign, Premiere Pro, Substance 3D Modeler, and Content Credentials, with some flaws enabling code execution and privilege escalation.
AEM Forms patches fix six vulnerabilities, three of which are critical and could lead to code execution and privilege escalation, tracked as CVE-2026-75745, CVE-2026-81995, and CVE-2026-82000, involving improper authorization, input validation, and SSRF.
Adobe’s September 2026 security release for Connect fixes nine vulnerabilities, including CVE-2026-75682, a highly critical SQL injection with potential for arbitrary code execution.
Mitigations for unpatched environments include network segmentation, reducing exposure, monitoring unusual outbound activity, and aligning patch timing with broader identity and access controls.
ZoomEye exposure shows 142 assets matching the Campaign title, with no indexed assets for the specific CVE; fingerprint counts reflect deployed instances rather than vulnerable hosts.
Patch details point to Campaign Classic 7.4.4 build 9402 as the fixed release, with hosted environments already updated; detection should support moving toward that state.
Updates carry a priority 2 rating, meaning users should apply within 30 days.
Patch guidance treats the SQL injection as a top-priority fix and recommends staging remediation if a single maintenance window cannot cover all patches.
Remediation steps include upgrading to 12.12 and Android App to 4.5, validating patch levels on internet-facing instances, prioritizing CVE-2026-75682 in staged patches, restricting admin interfaces during patching, and auditing high-risk accounts.
Adobe’s advisory lists patched versions and admin guidance; the company reports no known active attacks at publication.
Affected environments span on-premises, managed deployments, and internet-facing servers, with special attention to internet-facing servers, VPN-reachable internal deployments, and mobile clients.
Telemetry guidance emphasizes preserving logs and audit trails, noting unauthenticated flaws can generate activity before login events.
Summary based on 4 sources
