Adobe Warns of Critical Security Flaws Across Popular Software; Urges Immediate Patching

September 23, 2026
Adobe Warns of Critical Security Flaws Across Popular Software; Urges Immediate Patching
  • Adobe flags multiple critical vulnerabilities across Connect, Experience Manager Forms, Bridge, InDesign, Premiere Pro, Substance 3D Modeler, and Content Credentials, with several flaws capable of code execution and privilege escalation.

  • AEM Forms patches fix six flaws, including three critical ones that could enable code execution and privilege escalation, tracked as CVE-2026-75745, CVE-2026-81995, and CVE-2026-82000, tied to improper authorization, input validation, and server-side request forgery.

  • Experience Manager Forms also carries critical vulnerabilities (notably CVE-2026-75745) across all platforms; fixes target platforms such as AEM 6.5 LTS Forms Service Pack 3 and AEM 6.5 Forms 6.5.25 (AEMForms-6.5.0-0134 Hotfix).

  • The updates carry a priority 2 rating, meaning users should apply the patches within 30 days.

  • Adobe’s security advisory page lists patched versions and admin guidance, and the company reports no known active attacks at publication time.

  • Patch cadence remains twice monthly, with new updates issued since July of the current year.

  • Exploitation could lead to DoS, security feature bypass, arbitrary code execution, or memory exposure, though there are no reports of active exploitation in the wild.

  • Patched versions exist for Connect on macOS, Windows (Connect 12.12), and the Android Mobile App (4.5), but admins are urged not to delay patching.

  • Other affected applications remain vulnerable to code execution, DoS, or feature bypass, with exploit specifics varying by product.

  • Readers are directed to Adobe’s security bulletins page for details and related update links.

  • Connect faces seven critical bugs, including CVE-2026-75682 (CVSS 9.9); exploitation could install malware, escalate privileges, or cause other harm across Android, macOS, and Windows.

  • Additional Connect fixes address high-severity path traversal, improper certificate validation, and XSS that could permit arbitrary file reads, security bypass, or code execution.

Summary based on 2 sources


Get a daily email with more Tech stories

Sources

Adobe Patches Critical Flaws in Connect, AEM Forms

More Stories