# ANSSI Flags Multiple Adobe Product Vulnerabilities

Published: 2026-09-09 · Severity: high · Sectors: technology, retail
Canonical: https://vorant.io/reports/baa98f55-a2e5-509e-90e1-209e59f1a11a/anssi-flags-multiple-adobe-product-vulnerabilities

> ANSSI advisory details numerous vulnerabilities in Acrobat, Acrobat Reader, ColdFusion, Adobe Commerce, and Magento allowing RCE, privilege escalation, and DoS.

France's ANSSI (CERT-FR) issued a bulletin consolidating multiple Adobe security advisories (APSB26-119, APSB26-138, APSB26-141) covering Acrobat 2024, Acrobat Reader, Adobe Acrobat, Adobe Commerce, Adobe Commerce B2B, Magento Open Source, and ColdFusion 2023/2025. The vulnerabilities span a wide range of impact categories including remote code execution, privilege escalation, remote denial of service, SQL injection, cross-site scripting (XSS), confidentiality breaches, and security policy bypass. Dozens of CVEs are referenced across the affected product lines, with no indication in this advisory of active exploitation in the wild.

Affected versions include Acrobat 2024 prior to 24.001.30429, Acrobat Reader and Adobe Acrobat prior to 26.002.21901 (Windows/macOS), ColdFusion 2023 prior to 2023.0.24, ColdFusion 2025 prior to 2025.0.13, and various Adobe Commerce/Magento Open Source branches (2.4.4 through 2.4.9, and B2B extensions 1.3.3 through 1.5.3) prior to their September 2026 patch releases. Organizations running any of these products should apply the vendor-supplied patches referenced in the underlying Adobe security bulletins as soon as possible, prioritizing ColdFusion and Commerce/Magento deployments given the presence of RCE and SQLi issues that could affect exposed e-commerce and application server environments.

This is a routine vendor patch consolidation advisory from a national CERT rather than a report of active exploitation or a novel attack campaign. Defenders should inventory affected Adobe products, confirm patch levels against the versions listed, and track for any subsequent in-the-wild exploitation reporting tied to these CVEs.

## Mentioned in this report

- Vulnerabilities: CVE-2026-21269, CVE-2026-48273, CVE-2026-75746, CVE-2026-75993, CVE-2026-75998, CVE-2026-75999, CVE-2026-76000, CVE-2026-76002, CVE-2026-76190, CVE-2026-76200, CVE-2026-76201, CVE-2026-76202, CVE-2026-77108, CVE-2026-77109, CVE-2026-77110, CVE-2026-77111, CVE-2026-77774, CVE-2026-79907, CVE-2026-79908, CVE-2026-79909, CVE-2026-79910, CVE-2026-80159, CVE-2026-80160, CVE-2026-80161, CVE-2026-80162, CVE-2026-81973, CVE-2026-81975, CVE-2026-81976, CVE-2026-81977, CVE-2026-81978, CVE-2026-81979, CVE-2026-81980, CVE-2026-81981, CVE-2026-81982, CVE-2026-81983, CVE-2026-81984, CVE-2026-81985, CVE-2026-81986, CVE-2026-81987, CVE-2026-81988

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1140

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/baa98f55-a2e5-509e-90e1-209e59f1a11a/anssi-flags-multiple-adobe-product-vulnerabilities.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
