Adobe Warns of Critical Security Flaws Across Popular Software; Urges Immediate Patching
September 23, 2026
Adobe flags multiple critical vulnerabilities across Connect, Experience Manager Forms, Bridge, InDesign, Premiere Pro, Substance 3D Modeler, and Content Credentials, with several flaws capable of code execution and privilege escalation.
AEM Forms patches fix six flaws, including three critical ones that could enable code execution and privilege escalation, tracked as CVE-2026-75745, CVE-2026-81995, and CVE-2026-82000, tied to improper authorization, input validation, and server-side request forgery.
Experience Manager Forms also carries critical vulnerabilities (notably CVE-2026-75745) across all platforms; fixes target platforms such as AEM 6.5 LTS Forms Service Pack 3 and AEM 6.5 Forms 6.5.25 (AEMForms-6.5.0-0134 Hotfix).
The updates carry a priority 2 rating, meaning users should apply the patches within 30 days.
Adobe’s security advisory page lists patched versions and admin guidance, and the company reports no known active attacks at publication time.
Patch cadence remains twice monthly, with new updates issued since July of the current year.
Exploitation could lead to DoS, security feature bypass, arbitrary code execution, or memory exposure, though there are no reports of active exploitation in the wild.
Patched versions exist for Connect on macOS, Windows (Connect 12.12), and the Android Mobile App (4.5), but admins are urged not to delay patching.
Other affected applications remain vulnerable to code execution, DoS, or feature bypass, with exploit specifics varying by product.
Readers are directed to Adobe’s security bulletins page for details and related update links.
Connect faces seven critical bugs, including CVE-2026-75682 (CVSS 9.9); exploitation could install malware, escalate privileges, or cause other harm across Android, macOS, and Windows.
Additional Connect fixes address high-severity path traversal, improper certificate validation, and XSS that could permit arbitrary file reads, security bypass, or code execution.
Summary based on 2 sources
