Multiples vulnérabilités dans les produits Adobe (09 septembre 2026)
Multiple vulnerabilities have been discovered in Adobe products, including Acrobat, Adobe Commerce, and ColdFusion. These vulnerabilities could allow an attacker to execute arbitrary code, achieve privilege escalation, and cause a denial-of-service. Affected products range from older versions of Acrobat Reader and Acrobat to various Commerce B2B versions and ColdFusion. Users are strongly advised to update to the latest versions to mitigate these risks.
Multiple security vulnerabilities have been identified within Adobe products, posing significant risks to users. These vulnerabilities could be exploited to compromise system security and data integrity. The Adobe Security Bulletin APSB26-119 details these issues and recommends immediate action.
**What happened**
Several vulnerabilities exist across Adobe's suite of products. These include:
- **Remote Code Execution (RCE):** Multiple vulnerabilities allow for remote code execution, potentially enabling attackers to execute malicious code on vulnerable systems.
- **Privilege Escalation:** Some vulnerabilities can be leveraged to elevate user privileges, granting attackers greater control over the system.
- **Denial of Service (DoS):** Certain flaws can cause a denial-of-service attack, rendering the affected application unavailable.
- **SQL Injection:** Vulnerabilities exist that could lead to SQL injection attacks.
- **Cross-Site Scripting (XSS):** Vulnerabilities could be exploited to inject malicious scripts into websites.
**Affected Products**
The following Adobe products are affected by these vulnerabilities:
- **Acrobat Reader:** Versions prior to 26.002.21901 (Windows and macOS)
- **Acrobat:** Versions prior to 26.002.21901 (Windows and macOS)
- **Adobe Commerce B2B:** Versions prior to 1.3.4-2026-sep, 1.4.2-2026-sep, 1.5.2-x (2026-sep), 1.5.3-x (2026-sep), and prior to 2.4.4-2026-sep.
- **ColdFusion:** Versions prior to 2023.0.24 and 2025.0.13.
- **Magento Open Source:** Versions prior to 2.4.7-2026-sep.
- **Adobe Commerce B2B:** Versions prior to 1.3.4-2026-sep, 1.4.2-2026-sep, 1.5.2-x (2026-sep), 1.5.3-x (2026-sep), and prior to 2.4.4-2026-sep.
**Technical Details** The vulnerabilities are detailed in Adobe's Security Bulletin APSB26-119 and related bulletins. Specific CVE identifiers include:
- CVE-2026-21269
- CVE-2026-48273
- CVE-2026-75746
- CVE-2026-75993
- CVE-2026-75998
- CVE-2026-75999
- CVE-2026-76000
- CVE-2026-76002
- CVE-2026-76190
- CVE-2026-76200
- CVE-2026-76201
- CVE-2026-76202
- CVE-2026-77108
- CVE-2026-77109
- CVE-2026-77110
- CVE-2026-77111
- CVE-2026-77774
- CVE-2026-79907
- CVE-2026-79908
- CVE-2026-79909
- CVE-2026-79910
- CVE-2026-80159
- CVE-2026-80160
- CVE-2026-80161
- CVE-2026-80162
- CVE-2026-81973
- CVE-2026-81975
- CVE-2026-81976
- CVE-2026-81977
- CVE-2026-81978
- CVE-2026-81979
- CVE-2026-81980
- CVE-2026-81981
- CVE-2026-81982
- CVE-2026-81983
- CVE-2026-81984
- CVE-2026-81985
- CVE-2026-81986
- CVE-2026-81987
- CVE-2026-81988
- CVE-2026-81989
- CVE-2026-81990
- CVE-2026-81991
- CVE-2026-81992
- CVE-2026-81993
- CVE-2026-81994
- CVE-2026-81996
- CVE-2026-81997
- CVE-2026-82001
**Impact**
Exploitation of these vulnerabilities could lead to unauthorized access to sensitive data, system compromise, and denial of service. The potential impact ranges from data breaches and financial loss to disruption of critical services.
**What to do**
- **Update Immediately:** Adobe strongly recommends updating to the latest versions of affected products to patch these vulnerabilities.
- **Refer to Adobe's Security Bulletin:** For detailed information and specific instructions, refer to Adobe's Security Bulletin APSB26-119: [https://helpx.adobe.com/security/products/coldfusion/apsb26-119.html](https://helpx.adobe.com/security/products/coldfusion/apsb26-119.html)
- **Monitor for Exploitation:** Continuously monitor systems for signs of exploitation.
**Why it matters**
These vulnerabilities represent a significant security risk for organizations and individuals relying on Adobe products. Prompt patching is crucial to mitigate the potential damage and maintain a secure environment. The widespread use of these products means a successful exploit could have a broad impact.