VORANT. Threat Intelligence Sign in Get the full feed

Adobe patches 50+ RCE flaws across product suite

medium vulnerability retail

Adobe fixed over 50 vulnerabilities in After Effects, Commerce/Magento, Connect, Premiere Pro, Illustrator and other products, several enabling arbitrary code execution.

Adobe has released patches addressing a large batch of vulnerabilities spanning After Effects, Commerce (including Magento Open Source and Commerce B2B), Connect, Media Encoder, Premiere Pro, Substance 3D Designer/Painter/Sampler, the Content Authenticity SDK, and Illustrator. The most severe issues include stack- and heap-based buffer overflows, out-of-bounds read/write, use-after-free, integer overflow/underflow, deserialization of untrusted data, and SSRF, which could allow arbitrary code execution in the context of the logged-on user if a victim opens a malicious file or an attacker exploits a vulnerable web-facing Commerce/Magento instance.

Adobe Commerce and Magento Open Source carry additional risk given their exposure as internet-facing e-commerce platforms, with flaws including incorrect/improper authorization, stored XSS, path traversal, and SSRF that could enable account takeover or server-side compromise beyond simple code execution on an end-user's machine. There are currently no reports of in-the-wild exploitation for any of these vulnerabilities, but given the breadth of affected creative and e-commerce products, organizations should prioritize patching per Adobe's stable channel updates, especially internet-facing Commerce/Magento deployments.

CISA/MS-ISAC recommends standard vulnerability management practices: prompt patch application after testing, least-privilege configurations, application allowlisting, anti-exploitation mitigations, and host-based intrusion detection/prevention to reduce risk from potential future exploitation.

Mentioned in this report

Vulnerabilities CVE-2026-34636CVE-2026-34637CVE-2026-34638CVE-2026-34639CVE-2026-34640CVE-2026-34641CVE-2026-34642CVE-2026-34643CVE-2026-34644CVE-2026-34645CVE-2026-34646CVE-2026-34647CVE-2026-34648CVE-2026-34649CVE-2026-34650CVE-2026-34651CVE-2026-34652CVE-2026-34653CVE-2026-34654CVE-2026-34655CVE-2026-34656CVE-2026-34658CVE-2026-34659CVE-2026-34660CVE-2026-34664CVE-2026-34665CVE-2026-34666CVE-2026-34668CVE-2026-34673CVE-2026-34674CVE-2026-34675CVE-2026-34676CVE-2026-34677CVE-2026-34678CVE-2026-34681CVE-2026-34682CVE-2026-34683CVE-2026-34684CVE-2026-34685CVE-2026-34686

Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-adobe-products-could-allow-for-arbitrary-code-execution_2026-046

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free