PatchSiren

Adobe CVE debriefs · Page 11

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Adobe CVE published 2026-06-09

CVE-2026-34702

CVE-2026-34702 is a Stack-based Buffer Overflow vulnerability affecting Adobe InDesign versions 21.3, 20.5.3, and earlier. This vulnerability could result in arbitrary code execution in the context of the current user, requiring user interaction to open a malicious file. The CVSS score for this vulnerability is 7.8, classified as HIGH.

HIGH Adobe CVE published 2026-06-09

CVE-2026-34701

CVE-2026-34701 is a Heap-based Buffer Overflow vulnerability affecting Adobe InDesign versions 21.3, 20.5.3, and earlier. This vulnerability could result in arbitrary code execution in the context of the current user. Exploitation requires user interaction, as a victim must open a malicious file. The CVSS score for this vulnerability is 7.8, with a severity rating of HIGH.

HIGH Adobe CVE published 2026-06-09

CVE-2026-34700

CVE-2026-34700 is a HIGH-severity vulnerability (CVSS Score: 7.8) affecting Adobe InDesign versions 21.3, 20.5.3, and earlier. The vulnerability is an out-of-bounds write issue that could result in arbitrary code execution in the context of the current user. Exploitation requires user interaction, as a victim must open a malicious file.

HIGH Adobe CVE published 2026-06-09

CVE-2026-34699

CVE-2026-34699 is a Heap-based Buffer Overflow vulnerability affecting Adobe InDesign versions 21.3, 20.5.3, and earlier. This vulnerability could result in arbitrary code execution in the context of the current user, requiring user interaction to open a malicious file. The CVSS score for this vulnerability is 7.8, classified as HIGH severity.

HIGH Adobe CVE published 2026-06-09

CVE-2026-34698

CVE-2026-34698 is a Heap-based Buffer Overflow vulnerability affecting Adobe InDesign versions 21.3, 20.5.3, and earlier. This vulnerability could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction, as a victim must open a malicious file. The CVSS score for this vulnerability is 7.8, indicating a HIGH severity level.

HIGH Adobe CVE published 2026-06-09

CVE-2026-34697

CVE-2026-34697 is a Stack-based Buffer Overflow vulnerability affecting Adobe InDesign versions 21.3, 20.5.3, and earlier. The vulnerability could result in arbitrary code execution in the context of the current user. User interaction is required, as a victim must open a malicious file. The CVSS score for this vulnerability is 7.8, with a severity rating of HIGH.

HIGH Adobe CVE published 2026-06-09

CVE-2026-34696

CVE-2026-34696 is a Use After Free vulnerability affecting Adobe InDesign versions 21.3, 20.5.3, and earlier. This vulnerability could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction, as a victim must open a malicious file. The CVSS score for this vulnerability is 7.8, with a severity rating of HIGH.

HIGH Adobe CVE published 2026-06-09

CVE-2026-34695

CVE-2026-34695 is a Stack-based Buffer Overflow vulnerability affecting Adobe InDesign versions 21.3, 20.5.3, and earlier. This vulnerability could result in arbitrary code execution in the context of the current user. Exploitation requires user interaction, as a victim must open a malicious file.

MEDIUM Adobe CVE published 2026-06-09

CVE-2026-34694

CVE-2026-34694 is a stored Cross-Site Scripting (XSS) vulnerability affecting Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier. A high-privileged attacker could abuse this vulnerability to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field.

HIGH Adobe CVE published 2026-06-09

CVE-2026-34693

CVE-2026-34693 is a reflected Cross-Site Scripting (XSS) vulnerability affecting Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploit depends on conditions beyond the attacker's control. Exploitation of [truncated]

CRITICAL Adobe CVE published 2026-06-09

CVE-2026-34691

CVE-2026-34691 is a stored Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager Forms JEE. Versions LTS SP1, 6.5.24.0 and earlier are affected. An attacker could abuse this vulnerability to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevate [truncated]

LOW Adobe CVE published 2026-06-09

CVE-2026-48289

CVE-2026-48289 is an Improper Input Validation vulnerability in Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier. A low-privileged user could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page.

Known exploited Adobe CVE published 2026-05-20

CVE-2009-3459

This PatchSiren debrief is based on the supplied source corpus for CVE-2009-3459, a heap-based buffer overflow vulnerability in Adobe Acrobat and Reader. The CVE record was published on 2026-05-20T00:00:00.000Z and has not been modified since then. Defenders responsible for managing Adobe Acrobat and Reader installations should assess exposure and apply mitigations per vendor instructions. The vulnerabili [truncated]

HIGH Adobe CVE published 2026-05-12

CVE-2026-34686

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. This could lead to elevated access or control over the victim's account or session when they browse to the page containing the vulnera [truncated]

LOW Adobe CVE published 2026-05-12

CVE-2026-34685

CVE-2026-34685 is a low-severity Adobe Commerce security issue tied to improper input validation. According to the vendor-linked NVD record, a highly privileged attacker can leverage the flaw, with user interaction required, to bypass security measures; NVD rates it CVSS 3.4 (AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:L/A:N).

MEDIUM Adobe CVE published 2026-05-12

CVE-2026-34656

CVE-2026-34656 is a medium-severity improper authorization issue in Adobe Commerce that can let an attacker bypass security features and obtain unauthorized write access if a victim follows a malicious link or visits a compromised page. The NVD record maps the weakness to CWE-285 and cites Adobe's APSB26-49 advisory as the vendor reference.

MEDIUM Adobe CVE published 2026-05-12

CVE-2026-34655

CVE-2026-34655 is a stored cross-site scripting issue in Adobe Commerce that can let a high-privileged attacker plant malicious JavaScript in vulnerable form fields. When a victim later opens the affected page, the script can run in their browser. The CVSS vector shows network reachability, low attack complexity, high privileges required, user interaction required, and changed scope.

HIGH Adobe CVE published 2026-05-12

CVE-2026-34653

CVE-2026-34653 is a high-severity path traversal issue in Adobe Commerce that can let an authenticated attacker with administrative privileges read or write files outside a restricted directory. Adobe and NVD describe no user interaction requirement and a changed scope impact, which raises the risk of file tampering or sensitive data exposure in affected commerce environments.

HIGH Adobe CVE published 2026-05-12

CVE-2026-34652

CVE-2026-34652 is a high-severity availability issue in Adobe Commerce that can let a remote attacker crash the application without any user interaction. NVD rates it 7.5 (HIGH) and maps it to a network-reachable, no-authentication attack surface with complete availability impact. Adobe’s advisory is referenced by NVD for mitigation guidance.

HIGH Adobe CVE published 2026-05-12

CVE-2026-34651

CVE-2026-34651 is a high-severity availability issue in Adobe Commerce and Commerce B2B. According to Adobe’s advisory and the NVD record, an attacker can exhaust system resources over the network without user interaction, leading to application denial-of-service. The issue is classified as CWE-400, Uncontrolled Resource Consumption.

HIGH Adobe CVE published 2026-05-12

CVE-2026-34650

CVE-2026-34650 is a high-severity availability issue in Adobe Commerce. According to the CVE description and NVD analysis, an attacker can trigger uncontrolled resource consumption and exhaust system resources, causing application denial of service without user interaction. Adobe and NVD map the issue to affected Adobe Commerce releases and related CPE entries, with the vulnerability classified as CWE-400 [truncated]

HIGH Adobe CVE published 2026-05-12

CVE-2026-34649

CVE-2026-34649 is a high-severity denial-of-service issue in Adobe Commerce. Adobe and NVD describe it as an uncontrolled resource consumption flaw that can let a remote attacker exhaust system resources and disrupt the application without requiring user interaction.

HIGH Adobe CVE published 2026-05-12

CVE-2026-34648

CVE-2026-34648 is a high-severity Adobe Commerce vulnerability that can let an attacker exhaust system resources and trigger application denial-of-service without user interaction. The supplied NVD record classifies it as CWE-400 with a network-reachable, unauthenticated availability impact.

HIGH Adobe CVE published 2026-05-12

CVE-2026-34647

CVE-2026-34647 is a high-severity SSRF issue in Adobe Commerce that can be used to bypass security features and gain unauthorized read access. Adobe and NVD both note that exploitation requires user interaction, and the scope is changed, which increases the potential impact beyond a simple request-forging bug.

HIGH Adobe CVE published 2026-05-12

CVE-2026-34646

CVE-2026-34646 is a remotely reachable incorrect-authorization issue in Adobe Commerce that can bypass security features and enable unauthorized write access without user interaction. The CVE description and NVD record indicate a high-impact integrity flaw with network access, no authentication required, and no UI dependency. Adobe’s advisory is referenced by NVD, and the affected scope includes the liste [truncated]

HIGH Adobe CVE published 2026-05-12

CVE-2026-34645

CVE-2026-34645 is a high-severity authorization flaw in Adobe Commerce that can let a network attacker bypass security features and obtain unauthorized write access. The issue requires no user interaction and is rated CVSS 7.5, making it a priority fix for internet-exposed commerce environments.

CRITICAL Adobe CVE published 2026-05-12

CVE-2026-34660

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-05-12T19:16:30.930Z and has not been modified since then. The NVD entry is currently Analyzed. CVE-2026-34660 is a Critical Incorrect Authorization vulnerability in Adobe Connect Desktop Application versions 2025.9.15, 2025.8.157, and earlier. An attacker could exploit this vulnerability to inject mali [truncated]

MEDIUM Adobe CVE published 2026-05-12

CVE-2026-34663

The CVE-2026-34663 vulnerability affects Adobe Illustrator versions 29.8.6, 30.3, and earlier, allowing for out-of-bounds read and potential disclosure of sensitive memory. This issue requires user interaction as a victim must open a malicious file. The vulnerability has been assigned a CVSS score of 5.5 and a severity of MEDIUM. Organizations should prioritize patching to prevent potential sensitive info [truncated]

MEDIUM Adobe CVE published 2026-05-12

CVE-2026-34662

CVE-2026-34662 is a NULL Pointer Dereference vulnerability affecting Adobe Illustrator versions 29.8.6, 30.3, and earlier. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. This issue requires user interaction, as a victim must open a malicious file. The vulnerability has a CVSS score of 5.5 and a severity rating of MEDIUM. Adobe has released [truncated]

HIGH Adobe CVE published 2026-05-12

CVE-2026-34661

CVE-2026-34661 is an out-of-bounds write vulnerability in Adobe Illustrator versions 29.8.6, 30.3, and earlier. The vulnerability could result in arbitrary code execution in the context of the current user, requiring user interaction to open a malicious file. This issue has a HIGH severity level with a CVSS score of 7.8. Organizations and individuals using affected versions should apply patches or updates [truncated]