These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
The CVE-2026-34642 vulnerability is a Heap-based Buffer Overflow issue affecting Adobe After Effects versions 26.0, 25.6.4, and earlier. This vulnerability requires user interaction, as it involves opening a malicious file, and could result in arbitrary code execution in the context of the current user. The CVSS score for this vulnerability is 7.8, classified as HIGH severity. The CVE record was published [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-05-12T18:17:10.447Z and has not been modified since then. CVE-2026-34640 is an Integer Overflow or Wraparound vulnerability in Adobe Media Encoder versions 26.0.2, 25.6.4, and earlier. The vulnerability could result in arbitrary code execution in the context of the current user if a victim opens a mali [truncated]
CVE-2026-34632 is an Uncontrolled Search Path Element vulnerability in Adobe Photoshop Installer. A low-privileged local attacker could exploit this vulnerability by manipulating the search path used by the application to locate critical resources, potentially causing unauthorized code execution. Exploitation required user interaction, as a user had to be running the installer. This vulnerability has a hi [truncated]
CVE-2026-27310 is a Heap-based Buffer Overflow vulnerability affecting Adobe Bridge versions 16.0.2, 15.1.4, and earlier. The vulnerability could result in arbitrary code execution in the context of the current user, requiring user interaction to open a malicious file. This issue is considered High severity with a CVSS score of 7.8. Users of Adobe Bridge should apply updates to mitigate this vulnerability [truncated]
Adobe Photoshop Desktop versions 27.4 and earlier contain an out-of-bounds read vulnerability (CWE-125) triggered when parsing a crafted file. The flaw allows a read past the end of an allocated memory structure, which an attacker could leverage to achieve code execution in the context of the current user. Successful exploitation requires user interaction—the victim must open a malicious file. The vulnera [truncated]
CVE-2026-27222 is a stored Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager that could allow a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. The vulnerability's scope is changed, and defenders should assess exposure, especially in d [truncated]
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in Adobe Experience Manager versions 6.5.24, FP11.7 and earlier. This issue requires user interaction, where an attacker could manipulate the DOM environment to execute malicious JavaScript within the context of the victim's browser. The CVE record was published on 2026-04-14T18:16:56.450Z and has not been modified since then. Administrators and [truncated]
The CVE-2026-27246 record details a DOM-based Cross-Site Scripting (XSS) vulnerability in Adobe Connect versions 2025.3, 12.10, and earlier. This vulnerability could potentially allow an attacker to inject malicious scripts into a web page, gaining elevated access or control over a victim's account or session. Exploitation requires user interaction, such as visiting a maliciously crafted URL or interactin [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-14T18:16:55.890Z and has not been modified since then. The CVE-2026-27245 vulnerability affects Adobe Connect versions 2025.3, 12.10, and earlier, allowing for reflected Cross-Site Scripting (XSS) attacks. An attacker could exploit this vulnerability to inject malicious scripts into a web page, pote [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-14T18:16:55.730Z and has not been modified since then. The CVE-2026-27243 vulnerability affects Adobe Connect versions 2025.3, 12.10, and earlier, allowing for reflected Cross-Site Scripting (XSS) attacks. An attacker could exploit this vulnerability to inject malicious scripts into a web page, pote [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-14T17:16:51.283Z and has not been modified since then. The CVE-2026-34626 vulnerability is an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') issue affecting Adobe Acrobat Reader. This vulnerability could result in arbitrary file system read in the context o [truncated]
The CVE-2026-34622 vulnerability affects Adobe Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362, and earlier. It is caused by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability, which could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must [truncated]
CVE-2026-27291 is an out-of-bounds write vulnerability in Adobe InDesign versions 20.5.2, 21.2, and earlier. The vulnerability could result in arbitrary code execution in the context of the current user if a victim opens a malicious file. User interaction is required for exploitation. The CVSS score is 7.8 with a HIGH severity rating. Affected users should apply patches or updates to prevent potential exp [truncated]
CVE-2026-27285 is a Heap-based Buffer Overflow vulnerability affecting Adobe InDesign Desktop versions 20.5.2, 21.2, and earlier. The vulnerability could lead to application denial-of-service. User interaction is required for exploitation, as a victim must open a malicious file. This issue has a CVSS score of 5.5 and is considered medium-severity. Organizations should prioritize patching or mitigating thi [truncated]
CVE-2026-27283 is a Use After Free vulnerability affecting Adobe InDesign versions 20.5.2, 21.2, and earlier. This vulnerability could result in arbitrary code execution in the context of the current user if a victim opens a malicious file. The vulnerability has a CVSS score of 7.8 and is rated HIGH in severity. Successful exploitation requires user interaction. The CVE record was published on 2026-04-14T [truncated]
A stored Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager could allow a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. The vulnerability's scope has been changed. Defenders should assess their exposure and prioritize remediation, esp [truncated]
CVE-2026-34621 affects Adobe Acrobat and Reader and is described as a prototype pollution vulnerability. CISA listed it in the Known Exploited Vulnerabilities catalog on 2026-04-13, which means defenders should treat it as an active risk and move quickly on vendor guidance and remediation.
CVE-2020-9715 is identified by CISA as a known exploited vulnerability affecting Adobe Acrobat. The available record describes the issue as a use-after-free vulnerability and directs defenders to apply vendor mitigations. CISA added the CVE to its Known Exploited Vulnerabilities catalog on 2026-04-13 and set a remediation due date of 2026-04-27.
Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. This vulnerability requires user interaction to open a malicious file. The affected product is used for 3D modeling and texturing, and the vulnerability could potentially allow attackers to execute malicious code on the user's syst [truncated]
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and have limited impact to the integrity and availability of data. The exploit depends on conditions beyond the attacker's cont [truncated]
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability. This vulnerability could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields, potentially leading to session takeover and increasing confidentiality and integrity impact to high. The CVE record w [truncated]
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability. This high-severity vulnerability, with a CVSS score of 7.5, could result in a Security feature bypass, allowing attackers to bypass security measures and gain unauthorized view access of data. Exploitation does not require user interaction. The vul [truncated]
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. A high-privileged attacker could exploit this vulnerability to manipulate server-side requests and access unauthorized resources. This SSRF vulnerability has a CVSS score of 5.5 and a MEDIUM [truncated]
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. This vulnerability has a medium severity and requires user interaction, with exploitation potentially leading to unauthorized action [truncated]
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful [truncated]
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability. This vulnerability could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. The CVE record was published on 2026-03-11T01: [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-11T01:16:57.110Z and has not been modified since then. Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be execu [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-11T01:16:56.413Z and has not been modified since then. The vulnerability affects Adobe Experience Manager versions 6.5.23 and earlier, allowing low-privileged attackers to inject malicious scripts into vulnerable form fields. This stored Cross-Site Scripting (XSS) vulnerability can lead to malicious [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-11T01:16:56.240Z and has not been modified since then. Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScrip [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-11T01:16:56.077Z and has not been modified since then. The vulnerability affects Adobe Experience Manager versions 6.5.23 and earlier, allowing low-privileged attackers to inject malicious scripts into vulnerable form fields. This stored Cross-Site Scripting (XSS) vulnerability has a CVSS score of 5 [truncated]