PatchSiren

Adobe CVE debriefs · Page 2

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Adobe CVE published 2026-09-08

CVE-2026-82005

CVE-2026-82005 is a high-severity vulnerability in Adobe Photoshop that could allow arbitrary code execution if a user opens a malicious file. This out-of-bounds write vulnerability requires user interaction, potentially leading to significant impact on affected systems. Defenders should assess exposure and prioritize verification of user interactions with file attachments. The CVE record and NVD entry pr [truncated]

HIGH Adobe CVE published 2026-09-08

CVE-2026-76199

CVE-2026-76199 is a high-severity Uncontrolled Search Path Element vulnerability in Adobe Photoshop that could lead to arbitrary code execution. This issue requires user interaction, as a victim must open a malicious file. The vulnerability affects Photoshop versions 26.0 through 26.11.7 and 27.0 through 27.7. It is crucial for defenders to assess exposure and prioritize updates to prevent potential code [truncated]

HIGH Adobe CVE published 2026-09-08

CVE-2026-76190

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-08T20:18:24.157Z and has not been modified since then. The NVD entry is currently Analyzed. This Eval Injection vulnerability in Adobe ColdFusion could result in arbitrary code execution in the context of the current user. Defenders should assess exposure and apply remediation, especially in context [truncated]

MEDIUM Adobe CVE published 2026-09-08

CVE-2026-76002

CVE-2026-76002 is a reflected Cross-Site Scripting (XSS) vulnerability in Adobe ColdFusion. An attacker could exploit this vulnerability by convincing a victim to visit a URL referencing a vulnerable page, potentially leading to malicious JavaScript execution within the victim's browser context. This type of vulnerability is particularly concerning as it can be exploited remotely without requiring any aut [truncated]

MEDIUM Adobe CVE published 2026-09-08

CVE-2026-76000

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-08T20:18:23.893Z and has not been modified since then. The NVD entry is currently Analyzed. Defenders responsible for Adobe ColdFusion installations should assess exposure and prioritize verification and potential remediation due to the potential for application denial-of-service. The vulnerability [truncated]

HIGH Adobe CVE published 2026-09-08

CVE-2026-75999

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-08T20:18:23.760Z and has not been modified since then. The NVD entry is currently Analyzed. The vulnerability is an Improper Input Validation issue in Adobe ColdFusion, which could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vul [truncated]

HIGH Adobe CVE published 2026-09-08

CVE-2026-75998

CVE-2026-75998 is an Improper Access Control vulnerability in Adobe ColdFusion that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. This vulnerability has a high severity with a CVSS score of 7.5, indicating a significant risk to [truncated]

HIGH Adobe CVE published 2026-09-08

CVE-2026-75993

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-08T20:18:23.493Z and has not been modified since then. The NVD entry is currently Analyzed. This reflected XSS vulnerability in Adobe ColdFusion requires user interaction and has a CVSS score of 8.5, potentially leading to elevated access or control over the victim's account or session. Defenders sh [truncated]

HIGH Adobe CVE published 2026-09-08

CVE-2026-75992

CVE-2026-75992 is an out-of-bounds write vulnerability in Adobe Illustrator that could result in arbitrary code execution. This CVE was published on 2026-09-08T20:18:23.373Z and was last modified on 2026-09-18T14:18:36.687Z. The NVD entry is currently Analyzed. The vulnerability affects Adobe Illustrator versions 29.0 to 29.8.11 and 30.0 to 30.8. User interaction is required to exploit the vulnerability, [truncated]

HIGH Adobe CVE published 2026-09-08

CVE-2026-75991

CVE-2026-75991 is an Improper Input Validation vulnerability in Adobe Illustrator that could result in arbitrary code execution. User interaction is required to exploit this issue. The vulnerability affects Adobe Illustrator, potentially leading to code execution upon opening malicious files. This issue requires immediate attention from Adobe Illustrator users, particularly those in creative and design te [truncated]

HIGH Adobe CVE published 2026-09-08

CVE-2026-75990

CVE-2026-75990 is an Incorrect Authorization vulnerability in Adobe Illustrator that could result in arbitrary code execution. This CVE was published on 2026-09-08T20:18:22.583Z and was last modified on 2026-09-18T14:21:29.320Z. The NVD entry is currently Analyzed. The vulnerability requires user interaction, as a victim must open a malicious file, and its exploitation could lead to arbitrary code executi [truncated]

HIGH Adobe CVE published 2026-09-08

CVE-2026-75863

CVE-2026-75863 is a high-severity Integer Overflow or Wraparound vulnerability in Adobe Photoshop, affecting versions 26.0 through 26.11.7 and 27.0 through 27.7. An attacker could exploit this vulnerability by tricking a user into opening a malicious file, potentially leading to arbitrary code execution in the user's context. This issue requires user interaction and has a CVSS score of 7.8, indicating hig [truncated]

HIGH Adobe CVE published 2026-09-08

CVE-2026-75862

Adobe Photoshop is vulnerable to an Integer Overflow or Wraparound, which could result in arbitrary code execution in the context of the current user. This issue requires user interaction, as a victim must open a malicious file. The vulnerability has a high CVSS score of 7.8, indicating high severity. Users must be cautious when handling image files from untrusted sources and keep Adobe Photoshop up-to-da [truncated]

HIGH Adobe CVE published 2026-09-08

CVE-2026-75771

CVE-2026-75771 is an Integer Overflow or Wraparound vulnerability in Adobe Photoshop that could result in arbitrary code execution in the context of the current user. This issue requires user interaction as a victim must open a malicious file. The vulnerability has a high CVSS score of 7.8, indicating significant risk. Defenders should verify exposure, restrict user access to untrusted files, and apply pa [truncated]

CRITICAL Adobe CVE published 2026-09-08

CVE-2026-75746

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-08T20:18:22.120Z and has not been modified since then. The NVD entry is currently Analyzed. This critical SQL injection vulnerability in Adobe ColdFusion could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability wit [truncated]

MEDIUM Adobe CVE published 2026-09-08

CVE-2026-75740

CVE-2026-75740 is a stored Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager that could allow a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. This vulnerability has a CVSS score of 5.4 and a severity of MEDIUM. Defenders should asses [truncated]

MEDIUM Adobe CVE published 2026-09-08

CVE-2026-75738

A stored Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager could allow a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. The vulnerability's scope has been changed. Defenders should assess exposure and apply patches or mitigations to p [truncated]

MEDIUM Adobe CVE published 2026-09-08

CVE-2026-75735

CVE-2026-75735 is a stored Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager that could allow a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. This vulnerability has a CVSS score of 5.4 and is considered MEDIUM severity. The vulnerabi [truncated]

MEDIUM Adobe CVE published 2026-09-08

CVE-2026-75733

A stored Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager could allow a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. The vulnerability affects Adobe Experience Manager instances, and defenders should assess exposure and implement c [truncated]

MEDIUM Adobe CVE published 2026-09-08

CVE-2026-75729

CVE-2026-75729 is a stored Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager that could allow a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. The vulnerability affects Adobe Experience Manager deployments, and defenders should assess [truncated]

MEDIUM Adobe CVE published 2026-09-08

CVE-2026-75722

CVE-2026-75722 is a DOM-based Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. This requires user interaction, as a victim must visit a crafted webpage. The vulnerability has a medium severity and can lead to potential malicious JavaScrip [truncated]

MEDIUM Adobe CVE published 2026-09-08

CVE-2026-75716

CVE-2026-75716 is a DOM-based Cross-Site Scripting (XSS) vulnerability affecting Adobe Experience Manager. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. This requires user interaction, as a victim must visit a crafted webpage. The vulnerability has a medium CVSS score, indicating a moderate level of risk [truncated]

MEDIUM Adobe CVE published 2026-09-08

CVE-2026-75711

CVE-2026-75711 is a DOM-based Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. This requires user interaction, as a victim must visit a crafted webpage. The vulnerability has a medium severity and is classified as a DOM-based XSS issue. A [truncated]

MEDIUM Adobe CVE published 2026-09-08

CVE-2026-75709

CVE-2026-75709 is a DOM-based Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. This requires user interaction, as a victim must visit a crafted webpage. The vulnerability has a CVSS score of 5.4 and MEDIUM severity. Successful exploitatio [truncated]

MEDIUM Adobe CVE published 2026-09-08

CVE-2026-75706

CVE-2026-75706 is a DOM-based Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. This requires user interaction, as a victim must visit a crafted webpage. The vulnerability has a CVSS score of 5.4 and a severity of MEDIUM. Affected administ [truncated]

MEDIUM Adobe CVE published 2026-09-08

CVE-2026-75700

CVE-2026-75700 is a DOM-based Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. This requires user interaction, as a victim must visit a crafted webpage. The vulnerability has a CVSS score of 5.4 and is classified as MEDIUM severity. Defen [truncated]

MEDIUM Adobe CVE published 2026-09-08

CVE-2026-75692

CVE-2026-75692 is a DOM-based Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. This requires user interaction, as a victim must visit a crafted webpage. The vulnerability has a medium severity and a CVSS score of 5.4. Defenders should ver [truncated]

MEDIUM Adobe CVE published 2026-09-08

CVE-2026-75683

CVE-2026-75683 is a DOM-based Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. This requires user interaction, as a victim must visit a crafted webpage. The vulnerability has a CVSS score of 5.4 and MEDIUM severity. Affected administrator [truncated]

MEDIUM Adobe CVE published 2026-09-08

CVE-2026-75677

CVE-2026-75677 is a DOM-based Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. This requires user interaction, as a victim must visit a crafted webpage. The vulnerability has a medium severity and requires defenders to assess their exposu [truncated]

MEDIUM Adobe CVE published 2026-09-08

CVE-2026-75674

CVE-2026-75674 is a DOM-based Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. This requires user interaction, as a victim must visit a crafted webpage. The vulnerability has a medium severity and requires defenders to prioritize patching [truncated]