# Adobe Patches Dozens of Flaws Across Five Products

Published: 2026-08-11 · Severity: elevated
Canonical: https://vorant.io/reports/a84b872f-d3f5-56ca-87b8-0316c0b69016/adobe-patches-dozens-of-flaws-across-five-products

> Adobe issued patches for over 50 vulnerabilities in ColdFusion, Commerce, Lightroom, Content Credentials SDK, and Campaign Classic, some allowing arbitrary code execution.

CIS/MS-ISAC published an advisory detailing a large batch of vulnerabilities across five Adobe product lines: ColdFusion, Adobe Commerce (including Magento Open Source and Commerce B2B), Lightroom, the Content Credentials SDK (Rust/JS/C2PA tool), and Campaign Classic. The flaws span a wide range of vulnerability classes including OS command injection, eval injection, incorrect authorization, stored XSS, hard-coded cryptographic keys, heap-based buffer overflow, path traversal, deserialization of untrusted data, SSRF, SQL injection, and multiple memory-safety issues (out-of-bounds write, integer overflow/underflow, NULL pointer dereference).

The most severe issues could allow arbitrary code execution in the context of the logged-on user, potentially enabling an attacker to install programs, manipulate or exfiltrate data, or create new privileged accounts. Impact varies by the privilege level of the affected account, with users operating under least-privilege configurations facing reduced risk. No public reporting indicates any of these vulnerabilities are currently being exploited in the wild.

CIS recommends organizations apply Adobe's stable-channel updates after appropriate testing, and reinforces standard hardening measures: least-privilege enforcement, application/script allowlisting, anti-exploitation features, host-based intrusion detection/prevention, and routine vulnerability management and penetration testing programs. Given the breadth of affected products—spanning web application servers, e-commerce platforms, creative software, content-provenance SDKs, and marketing automation—organizations should inventory exposure across all five product lines.

## Mentioned in this report

- Vulnerabilities: CVE-2026-21279, CVE-2026-25652, CVE-2026-34635, CVE-2026-47940, CVE-2026-48273, CVE-2026-48362, CVE-2026-48375, CVE-2026-48376, CVE-2026-48384, CVE-2026-48386, CVE-2026-48397, CVE-2026-48404, CVE-2026-48405, CVE-2026-48406, CVE-2026-48407, CVE-2026-48408, CVE-2026-48409, CVE-2026-48410, CVE-2026-48411, CVE-2026-48412, CVE-2026-48413, CVE-2026-48414, CVE-2026-48415, CVE-2026-48416, CVE-2026-48434, CVE-2026-48436, CVE-2026-48438, CVE-2026-48439, CVE-2026-48440, CVE-2026-48441, CVE-2026-48442, CVE-2026-48443, CVE-2026-48446, CVE-2026-48447, CVE-2026-71362 (templated), CVE-2026-71383, CVE-2026-71384, CVE-2026-71385, CVE-2026-71386, CVE-2026-71387

Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-adobe-products-could-allow-for-arbitrary-code-execution_2026-079

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/a84b872f-d3f5-56ca-87b8-0316c0b69016/adobe-patches-dozens-of-flaws-across-five-products.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
