news.mlab.sh
Back to the feed
vulnerability

Adobe Patches Critical Flaws in Connect, AEM Forms

CriticalCVSS 10.0
Summary

Adobe has released patches to address 36 security vulnerabilities across its products, including critical flaws in Adobe Connect and AEM Forms. These vulnerabilities could allow attackers to execute code, escalate privileges, and bypass security features. The updates prioritize rapid remediation to mitigate potential risks.

Adobe announced on Tuesday the release of security updates to address 36 vulnerabilities affecting its software suite. These updates focus on critical flaws within Adobe Connect and AEM Forms, alongside fixes for other products like InDesign, Content Credentials SDK, Bridge, Substance 3D Modeler, and Premiere Pro. The vulnerabilities include SQL injection, cross-site scripting (XSS), improper input validation, and path traversal issues. Specifically, Adobe Connect has nine security defects, including six critical issues that could lead to arbitrary code execution and privilege escalation, tracked as CVE-2026-75682, CVE-2026-75684, CVE-2026-75686, CVE-2026-75689, CVE-2026-75697, and CVE-2026-75698. AEM Forms has three critical-severity flaws, including incorrect authorization, improper input validation, and server-side request forgery (SSRF), tracked as CVE-2026-75745, CVE-2026-81995, and CVE-2026-82000. All updates have a priority 2 rating, requiring users to apply them within 30 days. Adobe states that it is currently unaware of any active exploitation of these vulnerabilities. The company encourages users to review their security bulletins for more details and to ensure their systems are protected.

Read the full article at SecurityWeek