PatchSiren

Adobe CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Adobe CVE published 2026-08-03

CVE-2026-48399

Adobe Campaign Classic (ACC) is affected by a Violation of Secure Design Principles vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. The CVE record was published on 2026-08-03T23:16:46.693Z and has not been modified since th [truncated]

CRITICAL Adobe CVE published 2026-08-03

CVE-2026-48333

The CVE record for CVE-2026-48333 indicates an Incorrect Authorization vulnerability in Adobe Campaign Classic (ACC), which could result in privilege escalation. The vulnerability has a CVSS score of 9.8, indicating a CRITICAL severity. Exploitation of this issue does not require user interaction. Organizations should be aware of this vulnerability and take steps to mitigate it. The affected versions are [truncated]

CRITICAL Adobe CVE published 2026-08-03

CVE-2026-48331

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. This issue does not require user interaction and has a CVSS score of 10 with Critical severity. The vulnerability's scope is changed. Organizations should review and address this vulnerability promptly to prevent potential attacks. The CVE record was published on 2026-0 [truncated]

CRITICAL Adobe CVE published 2026-07-30

CVE-2026-48449

The CVE-2026-48449 record describes an Incorrect Authorization vulnerability in Adobe Campaign Classic (ACC), which could result in arbitrary code execution in the context of the current user. The vulnerability has a CVSS score of 10 and severity of CRITICAL. Exploitation does not require user interaction, and the scope is changed. Organizations should review and apply patches or updates provided by Adobe [truncated]

HIGH Adobe CVE published 2026-07-30

CVE-2026-48448

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record for CVE-2026-48448 was published on 2026-07-30T03:16:24.810Z and has not been modified since then. The NVD entry is currently Analyzed. Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead to disclosure of sensitive [truncated]

HIGH Adobe CVE published 2026-07-28

CVE-2026-48395

Adobe Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. The vulnerability exists due to an Untrusted Search Path issue in Adobe Bridge, allowing [truncated]

HIGH Adobe CVE published 2026-07-28

CVE-2026-48394

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-28T19:17:35.627Z and has not been modified since then. CVE-2026-48394 is an out-of-bounds write vulnerability in Adobe Bridge that could result in arbitrary code execution. This issue requires user interaction to open a malicious file. The vulnerability affects users of Adobe Bridge, especially thos [truncated]

HIGH Adobe CVE published 2026-07-28

CVE-2026-48393

Adobe Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. The CVE record was published on 2026-07-28T19:17:35.503Z and has not been modified since then. The NVD entry is currently Analyzed.

HIGH Adobe CVE published 2026-07-28

CVE-2026-48392

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-28T19:17:35.377Z and has not been modified since then. The vulnerability is an out-of-bounds write issue in Adobe Bridge that could lead to arbitrary code execution in the context of the current user. Exploitation requires user interaction, specifically opening a malicious file. The issue affects Ad [truncated]

HIGH Adobe CVE published 2026-07-28

CVE-2026-48391

Adobe Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

HIGH Adobe CVE published 2026-07-28

CVE-2026-48390

Adobe Bridge is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read and write access. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. This vulnerability has a high impact on confidentiality, integrity, and availability. Secu [truncated]

HIGH Adobe CVE published 2026-07-28

CVE-2026-48374

The CVE-2026-48374 vulnerability is a Path Traversal issue in Adobe Bridge, allowing for arbitrary file system read. This requires user interaction, as a victim must open a malicious file. The CVSS score is 7.8, classified as HIGH. Affected product context suggests that administrators and users of Adobe Bridge versions prior to 15.1.7 or 16.0.6 are impacted. Evidence is limited to public sources and may n [truncated]

HIGH Adobe CVE published 2026-07-20

CVE-2026-48389

CVE-2026-48389 is a Stack-based Buffer Overflow vulnerability in Adobe DNG SDK versions 1.7.1 2536 and earlier. The vulnerability could result in arbitrary code execution in the context of the current user if a victim opens a malicious file. This issue requires user interaction, and the affected product deployments should be reviewed to assign an owner for follow-up. The CVE record was published on 2026-0 [truncated]

HIGH Adobe CVE published 2026-07-17

CVE-2026-48373

CVE-2026-48373 is a Heap-based Buffer Overflow vulnerability in Acrobat Reader, which could result in arbitrary code execution in the context of the current user. The CVE record was published on 2026-07-17T20:17:21.290Z and has not been modified since then. This vulnerability requires user interaction, as a victim must open a malicious file. The affected product is Acrobat Reader, and the vulnerability cl [truncated]

MEDIUM Adobe CVE published 2026-07-14

CVE-2026-48357

CVE-2026-48357 is an Uncontrolled Resource Consumption vulnerability in CAI Content Credentials that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user interaction. The vulnerability has a CVSS score of 6.2 and a severity of MEDIUM.

MEDIUM Adobe CVE published 2026-07-14

CVE-2026-48354

CVE-2026-48354 is an Integer Overflow or Wraparound vulnerability in CAI Content Credentials, which could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation does not require user interaction. The vulnerability has a CVSS score of 6.2 and a severity of MEDIUM. Users and administrators shou [truncated]

MEDIUM Adobe CVE published 2026-07-14

CVE-2026-48353

CVE-2026-48353 is an Improper Input Validation vulnerability in Adobe CAI Content Credentials. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope by opening a malicious file. This vulnerability requires user interaction, as a victim must open a malicious file for exploitation to occur. The CVSS score for this vulnerability is 5.5, indic [truncated]

HIGH Adobe CVE published 2026-07-14

CVE-2026-48351

CVE-2026-48351 is an Improper Input Validation vulnerability in CAI Content Credentials, a software application that may be used in various environments. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation does not require user interaction. The vulnerability has a CVSS score of 7.5, indicating a high severity level. Security teams a [truncated]

HIGH Adobe CVE published 2026-07-14

CVE-2026-48337

CVE-2026-48337 is an out-of-bounds write vulnerability in Adobe Illustrator that could result in arbitrary code execution. This vulnerability requires user interaction, as a victim must open a malicious file. The vulnerability has a CVSS score of 7.8 and is considered HIGH severity. Affected product deployments should be reviewed for potential exposure, and owners should be assigned for follow-up. Officia [truncated]

HIGH Adobe CVE published 2026-07-14

CVE-2026-48336

CVE-2026-48336 is an out-of-bounds write vulnerability in Adobe Illustrator that could result in arbitrary code execution in the context of the current user. This vulnerability requires user interaction, as a victim must open a malicious file. The vulnerability affects Adobe Illustrator versions 29.0 through 29.8.9 and 30.0 through 30.6. The CVSS score for this vulnerability is 7.8, indicating a high seve [truncated]

HIGH Adobe CVE published 2026-07-14

CVE-2026-48335

CVE-2026-48335 is an out-of-bounds write vulnerability in Adobe Illustrator that could result in arbitrary code execution. This issue requires user interaction as a victim must open a malicious file. The vulnerability affects Adobe Illustrator users, who should take precautions to avoid opening files from untrusted sources. The CVSS score of 7.8 indicates high severity.

CRITICAL Adobe CVE published 2026-07-14

CVE-2026-48334

CVE-2026-48334 is an Improper Input Validation vulnerability in Adobe Illustrator that could result in arbitrary code execution. This issue requires user interaction, as a victim must open a malicious file. The scope is changed. Users should be cautious when opening files from untrusted sources. The vulnerability has a CVSS score of 9.3 and is considered CRITICAL. Security teams and administrators respons [truncated]

MEDIUM Adobe CVE published 2026-07-14

CVE-2026-48312

CVE-2026-48312 is an Improper Input Validation vulnerability in Adobe's CAI Content Credentials. This vulnerability could allow an attacker to bypass security measures and gain unauthorized write access. The exploitation of this issue does not require user interaction. Affected products include c2pa, c2pa-web, and c2patool. Organizations should prioritize patching to prevent potential security breaches.

MEDIUM Adobe CVE published 2026-07-14

CVE-2026-48302

CVE-2026-48302 is an Improper Input Validation vulnerability in CAI Content Credentials, which could lead to an application denial-of-service condition. An attacker could exploit this vulnerability to crash the application. The vulnerability has a CVSS score of 6.2 and a severity of MEDIUM. Exploitation of this issue does not require user interaction. Security teams and administrators should be aware of t [truncated]

MEDIUM Adobe CVE published 2026-07-14

CVE-2026-48298

CVE-2026-48298 is an Integer Underflow vulnerability in CAI Content Credentials that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction. This vulnerability has a CVSS score of 6.2 and a severity of MEDIUM. Security teams should review [truncated]

MEDIUM Adobe CVE published 2026-07-14

CVE-2026-48296

CVE-2026-48296 is an Integer Underflow (Wrap or Wraparound) vulnerability in CAI Content Credentials, a critical component for managing digital content. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation does not require user interaction. The vulnerability has a CVSS score of 6.2 and a severity of MEDIUM. Security teams and adminis [truncated]

HIGH Adobe CVE published 2026-07-14

CVE-2026-48290

CVE-2026-48290 is a Server-Side Request Forgery (SSRF) vulnerability in CAI Content Credentials. The vulnerability could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user [truncated]

HIGH Adobe CVE published 2026-07-14

CVE-2026-48287

The CVE record for CVE-2026-48287 was published on 2026-07-14T22:17:00.713Z and has not been modified since then. The NVD entry is currently Analyzed. This Untrusted Search Path vulnerability in Adobe CAI Content Credentials could result in arbitrary code execution in the context of the current user. Exploitation requires user interaction, such as visiting a maliciously crafted URL or interacting with a c [truncated]

HIGH Adobe CVE published 2026-07-14

CVE-2026-48275

CVE-2026-48275 is an Untrusted Search Path vulnerability in Adobe Illustrator that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. The CVSS score is 8.6, and the severity is HIGH. This vulnerability affects users of Adobe Illustrator, particularly those using ver [truncated]

HIGH Adobe CVE published 2026-07-14

CVE-2026-48370

CVE-2026-48370 is an out-of-bounds write vulnerability in Adobe Media Encoder that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. The vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. The CVSS vector is CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, indicat [truncated]

HIGH Adobe CVE published 2026-07-14

CVE-2026-48369

CVE-2026-48369 is an out-of-bounds write vulnerability in Adobe Premiere Pro that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. The vulnerability has a CVSS score of 7.8, indicating high severity. Users should be cautious when opening files from untrusted sources and ensure they [truncated]

HIGH Adobe CVE published 2026-07-14

CVE-2026-48367

CVE-2026-48367 is an out-of-bounds write vulnerability in Adobe After Effects. The vulnerability could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction, as a victim must open a malicious file. This vulnerability is considered High severity, with a CVSS score of 7.8. Users of Adobe After Effects should be aware of this vulnerability [truncated]

HIGH Adobe CVE published 2026-07-14

CVE-2026-48366

CVE-2026-48366 is an out-of-bounds write vulnerability in Adobe Media Encoder that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. The vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. Users of Adobe Media Encoder versions 25.6.5 and earlier, as well as 26. [truncated]

HIGH Adobe CVE published 2026-07-14

CVE-2026-48344

CVE-2026-48344 is a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Adobe Creative Cloud Desktop Application. The vulnerability could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. The scope of the vulnerability has been changed. Users should [truncated]

HIGH Adobe CVE published 2026-07-14

CVE-2026-48343

CVE-2026-48343 is an out-of-bounds write vulnerability in Adobe Bridge that could result in arbitrary code execution in the context of the current user. This vulnerability requires user interaction, as a victim must open a malicious file. The vulnerability has a CVSS score of 7.8, indicating a high severity level. Affected users should apply patches from Adobe for Adobe Bridge versions prior to 15.1.5 or [truncated]

HIGH Adobe CVE published 2026-07-14

CVE-2026-48342

CVE-2026-48342 is an Integer Overflow or Wraparound vulnerability in Adobe Bridge, which could result in arbitrary code execution in the context of the current user. This vulnerability requires user interaction, as a victim must open a malicious file for exploitation to occur. The CVSS score for this vulnerability is 7.8, indicating a high severity level. Affected users should apply patches immediately to [truncated]

HIGH Adobe CVE published 2026-07-14

CVE-2026-48341

CVE-2026-48341 is an out-of-bounds write vulnerability in Adobe Bridge that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. This vulnerability is considered High severity and has a CVSS score of 7.8. Users of Adobe Bridge versions prior to 15.1.5 or 16.0.3 are affected.

HIGH Adobe CVE published 2026-07-14

CVE-2026-48340

CVE-2026-48340 is an Untrusted Pointer Dereference vulnerability in Adobe Bridge that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. The vulnerability has a CVSS score of 7.8, indicating a high severity level. Users of Adobe Bridge versions prior to 15.1.5 or 16.0.3 are affected [truncated]

HIGH Adobe CVE published 2026-07-14

CVE-2026-48339

CVE-2026-48339 is a Heap-based Buffer Overflow vulnerability in Adobe Bridge. The vulnerability could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. This vulnerability has a CVSS score of 7.8 and a HIGH severity rating. It exists in Adobe Bridge versions prior to 15.1.5 and 16.0.3. An [truncated]

MEDIUM Adobe CVE published 2026-07-14

CVE-2026-48338

CVE-2026-48338 is a Path Traversal vulnerability in Adobe ColdFusion that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. The vulnerability has a CVSS score of 6.8 and a severity of MEDIUM. Administrators and users should review a [truncated]

CRITICAL Adobe CVE published 2026-07-14

CVE-2026-48324

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T21:16:59.023Z and has not been modified since then. The NVD entry is currently Modified. This Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Adobe ColdFusion could result in arbitrary code execution in the context of the current user. An atta [truncated]

CRITICAL Adobe CVE published 2026-07-14

CVE-2026-48322

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record for CVE-2026-48322 was published on 2026-07-14T21:16:58.920Z and has not been modified since then. Adobe ColdFusion is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability, which could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exp [truncated]

HIGH Adobe CVE published 2026-07-14

CVE-2026-48320

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record for CVE-2026-48320 was published on 2026-07-14T21:16:58.703Z and has not been modified since then. The NVD entry is currently Analyzed. This reflected Cross-Site Scripting (XSS) vulnerability in Adobe ColdFusion allows an attacker to inject malicious scripts into a web page, potentially gaining elevated access or control ov [truncated]

CRITICAL Adobe CVE published 2026-07-14

CVE-2026-48319

A Path Traversal vulnerability was discovered in Adobe ColdFusion, which could allow an attacker with high privileges to execute arbitrary code in the context of the current user. The vulnerability, tracked as CVE-2026-48319, has a CVSS score of 9.1 and is considered critical. Exploitation of this issue does not require user interaction. This vulnerability affects Adobe ColdFusion versions 2023 and 2025, [truncated]

HIGH Adobe CVE published 2026-07-14

CVE-2026-48311

CVE-2026-48311 is an out-of-bounds write vulnerability in Adobe Bridge that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. This vulnerability has been rated as HIGH with a CVSS score of 7.8. The CVSS vector for this vulnerability is CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. U [truncated]

MEDIUM Adobe CVE published 2026-07-14

CVE-2026-48308

CVE-2026-48308 is an Improper Input Validation vulnerability in Premiere Pro that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed. This vulnerability has a CVSS sc [truncated]

CRITICAL Adobe CVE published 2026-07-14

CVE-2026-48284

The CVE-2026-48284 vulnerability in Adobe ColdFusion is caused by Improper Input Validation, which could result in arbitrary code execution in the context of the current user. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction. Scope is changed. Organizations should prioritize patching to prevent potential arbit [truncated]

HIGH Adobe CVE published 2026-07-14

CVE-2026-48272

CVE-2026-48272 is an Uncontrolled Search Path Element vulnerability in Adobe Creative Cloud Desktop that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed. This vulnerability has a high CVSS score of 7.8, indicating high severity. Users of A [truncated]

HIGH Adobe CVE published 2026-07-14

CVE-2026-48270

CVE-2026-48270 is an out-of-bounds write vulnerability in Adobe Premiere Pro that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. The vulnerability has a high severity with a CVSS score of 7.8. Users should be cautious when opening files from unknown sources and ensure that Adobe [truncated]

HIGH Adobe CVE published 2026-07-14

CVE-2026-48269

CVE-2026-48269 is a Heap-based Buffer Overflow vulnerability in Adobe Premiere Pro that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. This vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. The vulnerability requires user interaction, as a victim must open [truncated]