Adobe patches dozens of RCE flaws across product suite
Adobe issued fixes for over 30 vulnerabilities in Bridge, Connect, InDesign, Premiere Pro, Substance 3D, AEM Forms and the Content Credentials SDK, some allowing arbitrary code execution.
MS-ISAC published an advisory detailing multiple vulnerabilities across a broad set of Adobe products, including Adobe Bridge, Adobe Connect, InDesign, Premiere Pro, Substance 3D Modeler, Adobe Experience Manager (AEM) Forms, and the Content Credentials/C2PA SDK. The most severe issues — heap and stack-based buffer overflows, out-of-bounds read/write, uncontrolled recursion, and NULL pointer dereference bugs — could allow arbitrary code execution in the context of the logged-on user, giving an attacker the ability to install programs, alter or delete data, or create new accounts, with impact scaling to the privileges of the affected account. Adobe Connect additionally carries multiple SQL injection, stored/reflected XSS, path traversal, and improper certificate validation flaws, while AEM Forms includes SSRF, CSRF, and authorization issues, and the Content Credentials SDK has several input validation, resource consumption, and integer overflow bugs.
There are no reports of in-the-wild exploitation for any of these vulnerabilities at time of publication. Affected versions span current and LTS release lines for each product (e.g., Adobe Bridge 15.1.7/16.0.6 and earlier, Adobe Connect 12.11 and earlier, InDesign ID20.5.4/ID21.5 and earlier, AEM 6.5 Forms 6.5.25 and earlier, and c2patool/c2pa Rust SDK versions up to v0.26.70/v0.89.2). Defenders should prioritize patching based on exposure — internet-facing AEM Forms and Adobe Connect deployments carrying injection and SSRF flaws warrant the fastest attention, while desktop application vulnerabilities (Bridge, InDesign, Premiere Pro, Substance 3D) are most relevant where users open untrusted files or media.
Standard mitigations apply: patch to the latest stable channel releases, enforce least privilege so exploitation impact is limited for non-administrative users, enable anti-exploitation and application allowlisting controls, and monitor for anomalous process/file behavior consistent with client-side exploitation (ATT&CK T1203, Exploitation for Client Execution). Given the breadth of products and the mix of severities, organizations should treat this as a standard patch-management cycle rather than an emergency response, absent evidence of active exploitation.
Mentioned in this report
Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-adobe-products-could-allow-for-arbitrary-code-execution_2026-099
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free