PatchSiren

Adobe CVE debriefs · Page 13

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Adobe CVE published 2026-03-11

CVE-2026-27254

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-11T01:16:55.900Z and has not been modified since then. The NVD entry is currently Analyzed. Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability. A low-privileged attacker could inject malicious scripts into vulnerable form fields, po [truncated]

MEDIUM Adobe CVE published 2026-03-11

CVE-2026-27252

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-11T01:16:55.550Z and has not been modified since then. The vulnerability affects Adobe Experience Manager versions 6.5.23 and earlier, allowing a low-privileged attacker to inject malicious scripts into vulnerable form fields, potentially leading to malicious JavaScript execution in a victim’s brows [truncated]

MEDIUM Adobe CVE published 2026-03-11

CVE-2026-27251

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-11T01:16:55.377Z and has not been modified since then. Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. This vulnerability [truncated]

MEDIUM Adobe CVE published 2026-03-11

CVE-2026-27250

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability. This vulnerability could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. The CVE record was published on 2026-03-11T01: [truncated]

MEDIUM Adobe CVE published 2026-03-11

CVE-2026-27249

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-11T01:16:55.040Z and has not been modified since then. Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. The [truncated]

MEDIUM Adobe CVE published 2026-03-11

CVE-2026-27248

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record for CVE-2026-27248 was published on 2026-03-11T01:16:54.870Z and has not been modified since then. Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability. This vulnerability could be abused by a low-privileged attacker to inject malicious scripts into vulnerabl [truncated]

MEDIUM Adobe CVE published 2026-03-11

CVE-2026-27247

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-11T01:16:54.693Z and has not been modified since then. The vulnerability is a stored Cross-Site Scripting (XSS) in Adobe Experience Manager versions 6.5.23 and earlier. A low-privileged attacker could inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a vic [truncated]

MEDIUM Adobe CVE published 2026-03-11

CVE-2026-27242

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record for CVE-2026-27242 was published on 2026-03-11T01:16:54.343Z and has not been modified since then. Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability. The vulnerability could be abused by a low-privileged attacker to inject malicious scripts into vulnerable [truncated]

MEDIUM Adobe CVE published 2026-03-11

CVE-2026-27241

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-11T01:16:54.163Z and has not been modified since then. Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. The vulnerability r [truncated]

MEDIUM Adobe CVE published 2026-03-11

CVE-2026-27240

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-11T01:16:53.997Z and has not been modified since then. The vulnerability affects Adobe Experience Manager versions 6.5.23 and earlier, allowing low-privileged attackers to inject malicious scripts into vulnerable form fields, potentially leading to security breaches. Organizations should prioritize [truncated]

MEDIUM Adobe CVE published 2026-03-11

CVE-2026-27239

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-11T01:16:53.827Z and has not been modified since then. Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be execu [truncated]

MEDIUM Adobe CVE published 2026-03-11

CVE-2026-27237

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-11T01:16:53.647Z and has not been modified since then. Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. The vulnerability r [truncated]

MEDIUM Adobe CVE published 2026-03-11

CVE-2026-27236

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-11T01:16:53.477Z and has not been modified since then. Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. The vulnerability r [truncated]

MEDIUM Adobe CVE published 2026-03-11

CVE-2026-27235

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-11T01:16:53.300Z and has not been modified since then. This stored Cross-Site Scripting (XSS) vulnerability affects Adobe Experience Manager versions 6.5.23 and earlier, allowing low-privileged attackers to inject malicious scripts into vulnerable form fields. Organizations should prioritize patchin [truncated]

MEDIUM Adobe CVE published 2026-03-11

CVE-2026-27233

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability. A low-privileged attacker could inject malicious scripts into vulnerable form fields, which may be executed in a victim's browser when they browse to the page containing the vulnerable field. This vulnerability has been publicly disclosed and requires immediate attention from organizatio [truncated]

MEDIUM Adobe CVE published 2026-03-11

CVE-2026-27232

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-11T01:16:52.813Z and has not been modified since then. The NVD entry is currently Analyzed. This stored Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager versions 6.5.23 and earlier allows a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious [truncated]

MEDIUM Adobe CVE published 2026-03-11

CVE-2026-27231

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability. This vulnerability could allow an attacker to inject malicious scripts into vulnerable form fields, potentially leading to execution of malicious JavaScript in a victim's browser when they access the page containing the vulnerable field. The CVE record was published on 2026-03-11T01:16:5 [truncated]

MEDIUM Adobe CVE published 2026-03-11

CVE-2026-27230

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record for CVE-2026-27230 was published on 2026-03-11T01:16:52.473Z and has not been modified since then. Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability. This vulnerability could be abused by a low-privileged attacker to inject malicious scripts into vulnerabl [truncated]

MEDIUM Adobe CVE published 2026-03-11

CVE-2026-27228

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-11T01:16:52.137Z and has not been modified since then. Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScrip [truncated]

MEDIUM Adobe CVE published 2026-03-11

CVE-2026-27226

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record for CVE-2026-27226 was published on 2026-03-11T01:16:51.967Z and has not been modified since then. Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vul [truncated]

MEDIUM Adobe CVE published 2026-03-11

CVE-2026-27225

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability. This vulnerability could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. The CVE record was published on 2026-03-11T01: [truncated]

HIGH Adobe CVE published 2026-03-10

CVE-2026-27272

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-10T23:16:44.423Z and has not been modified since then. CVE-2026-27272 is an out-of-bounds write vulnerability in Adobe Illustrator versions 29.8.4, 30.1, and earlier. The vulnerability could result in arbitrary code execution in the context of the current user, requiring user interaction to open a m [truncated]

MEDIUM Adobe CVE published 2026-03-10

CVE-2026-27270

The CVE-2026-27270 vulnerability is an Out-of-bounds Read issue in Adobe Illustrator versions 29.8.4, 30.1, and earlier. This vulnerability could lead to memory exposure incidents if an attacker tricks a victim into opening a malicious file. The vulnerability requires user interaction and has a CVSS score of 5.5, indicating a medium severity. Users of Adobe Illustrator versions 29.8.4, 30.1, and earlier s [truncated]

HIGH Adobe CVE published 2026-03-10

CVE-2026-27278

The CVE-2026-27278 vulnerability is a Use After Free issue in Adobe Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265, and earlier. This vulnerability could result in arbitrary code execution in the context of the current user if a victim opens a malicious file. Organizations and individuals using these versions should apply the vendor-provided patch or update to a fixed version to mitigate [truncated]

MEDIUM Adobe CVE published 2026-03-10

CVE-2026-27221

The CVE-2026-27221 vulnerability is an Improper Certificate Validation issue in Adobe Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265, and earlier. This vulnerability could allow an attacker to spoof the identity of a signer by leveraging the Security feature bypass. User interaction is required for exploitation. Organizations should review their deployments of affected Adobe Acrobat Read [truncated]

HIGH Adobe CVE published 2026-03-10

CVE-2026-27220

The CVE-2026-27220 vulnerability is a Use After Free issue in Adobe Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265, and earlier. This vulnerability could result in arbitrary code execution in the context of the current user, requiring user interaction to open a malicious file. The CVSS score is 7.8, indicating a HIGH severity level. Organizations should prioritize patching this vulnerabi [truncated]

HIGH Adobe CVE published 2026-03-10

CVE-2026-27277

Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. This vulnerability requires user interaction to open a malicious file. The affected product, Substance3D - Stager, is used for 3D rendering and design. The vulnerability has a high CVSS score, indicating a high severity level. To d [truncated]

HIGH Adobe CVE published 2026-03-10

CVE-2026-27275

Substance3D - Stager versions 3.1.7 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. This vulnerability has a high CVSS score of 7.8, indicating high severity. Security teams and administrators should be aware of [truncated]

HIGH Adobe CVE published 2026-03-10

CVE-2026-27273

Substance3D - Stager versions 3.1.7 and earlier are affected by an out-of-bounds write vulnerability, potentially leading to arbitrary code execution in the context of the current user. This issue requires user interaction, typically through opening a malicious file. The vulnerability's impact and severity are detailed in the official CVE Program record and NIST NVD entry.

HIGH Adobe CVE published 2026-03-10

CVE-2026-27269

Adobe Premiere Pro versions 25.5 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file. This issue requires user interaction, as a victim must open a malicious file. The vulnerability could result in a read past the end of an allocated memory structure, potentially allowing an attacker to execute code in the context of the current user. The vulnerability affects Adobe [truncated]