PatchSiren

Adobe CVE debriefs · Page 7

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Adobe CVE published 2026-07-14

CVE-2026-48366

CVE-2026-48366 is an out-of-bounds write vulnerability in Adobe Media Encoder that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. The vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. Users of Adobe Media Encoder versions 25.6.5 and earlier, as well as 26. [truncated]

HIGH Adobe CVE published 2026-07-14

CVE-2026-48344

CVE-2026-48344 is a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Adobe Creative Cloud Desktop Application. The vulnerability could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. The scope of the vulnerability has been changed. Users should [truncated]

HIGH Adobe CVE published 2026-07-14

CVE-2026-48343

CVE-2026-48343 is an out-of-bounds write vulnerability in Adobe Bridge that could result in arbitrary code execution in the context of the current user. This vulnerability requires user interaction, as a victim must open a malicious file. The vulnerability has a CVSS score of 7.8, indicating a high severity level. Affected users should apply patches from Adobe for Adobe Bridge versions prior to 15.1.5 or [truncated]

HIGH Adobe CVE published 2026-07-14

CVE-2026-48342

CVE-2026-48342 is an Integer Overflow or Wraparound vulnerability in Adobe Bridge, which could result in arbitrary code execution in the context of the current user. This vulnerability requires user interaction, as a victim must open a malicious file for exploitation to occur. The CVSS score for this vulnerability is 7.8, indicating a high severity level. Affected users should apply patches immediately to [truncated]

HIGH Adobe CVE published 2026-07-14

CVE-2026-48341

CVE-2026-48341 is an out-of-bounds write vulnerability in Adobe Bridge that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. This vulnerability is considered High severity and has a CVSS score of 7.8. Users of Adobe Bridge versions prior to 15.1.5 or 16.0.3 are affected.

HIGH Adobe CVE published 2026-07-14

CVE-2026-48340

CVE-2026-48340 is an Untrusted Pointer Dereference vulnerability in Adobe Bridge that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. The vulnerability has a CVSS score of 7.8, indicating a high severity level. Users of Adobe Bridge versions prior to 15.1.5 or 16.0.3 are affected [truncated]

HIGH Adobe CVE published 2026-07-14

CVE-2026-48339

CVE-2026-48339 is a Heap-based Buffer Overflow vulnerability in Adobe Bridge. The vulnerability could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. This vulnerability has a CVSS score of 7.8 and a HIGH severity rating. It exists in Adobe Bridge versions prior to 15.1.5 and 16.0.3. An [truncated]

MEDIUM Adobe CVE published 2026-07-14

CVE-2026-48338

CVE-2026-48338 is a Path Traversal vulnerability in Adobe ColdFusion that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. The vulnerability has a CVSS score of 6.8 and a severity of MEDIUM. Administrators and users should review a [truncated]

HIGH Adobe CVE published 2026-07-14

CVE-2026-48332

The CVE-2026-48332 vulnerability is a Server-Side Request Forgery (SSRF) issue in Adobe ColdFusion that could allow a low-privileged attacker to bypass security measures and gain unauthorized read access. This vulnerability has a CVSS score of 7.7 and is classified as HIGH severity. The vulnerability was published on 2026-07-14T21:16:59.583Z and has not been modified since then. Administrators and securit [truncated]

LOW Adobe CVE published 2026-07-14

CVE-2026-48329

The CVE-2026-48329 Insufficient Session Expiration vulnerability affects Adobe ColdFusion, potentially allowing high-privileged attackers to bypass security measures and gain unauthorized write access. Organizations using Adobe ColdFusion, especially those with high-privileged users, should be aware of this vulnerability and take necessary actions to mitigate the risk. The CVE record was published on 2026 [truncated]

HIGH Adobe CVE published 2026-07-14

CVE-2026-48328

The CVE-2026-48328 vulnerability is an Improper Input Validation issue in Adobe ColdFusion. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. The vulnerability has a CVSS score of 7.7 and is rated HIGH. Exploitation does not require user interaction, and the scope of the vulnerability has changed. Organizations and administrators usi [truncated]

CRITICAL Adobe CVE published 2026-07-14

CVE-2026-48327

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record for CVE-2026-48327 was published on 2026-07-14T21:16:59.257Z. Adobe ColdFusion is affected by an Incorrect Authorization vulnerability, which could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction, and the scope is changed. The CVSS score for [truncated]

CRITICAL Adobe CVE published 2026-07-14

CVE-2026-48324

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T21:16:59.023Z and has not been modified since then. The NVD entry is currently Modified. This Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Adobe ColdFusion could result in arbitrary code execution in the context of the current user. An atta [truncated]

CRITICAL Adobe CVE published 2026-07-14

CVE-2026-48322

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record for CVE-2026-48322 was published on 2026-07-14T21:16:58.920Z and has not been modified since then. Adobe ColdFusion is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability, which could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exp [truncated]

HIGH Adobe CVE published 2026-07-14

CVE-2026-48320

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record for CVE-2026-48320 was published on 2026-07-14T21:16:58.703Z and has not been modified since then. The NVD entry is currently Analyzed. This reflected Cross-Site Scripting (XSS) vulnerability in Adobe ColdFusion allows an attacker to inject malicious scripts into a web page, potentially gaining elevated access or control ov [truncated]

CRITICAL Adobe CVE published 2026-07-14

CVE-2026-48319

A Path Traversal vulnerability was discovered in Adobe ColdFusion, which could allow an attacker with high privileges to execute arbitrary code in the context of the current user. The vulnerability, tracked as CVE-2026-48319, has a CVSS score of 9.1 and is considered critical. Exploitation of this issue does not require user interaction. This vulnerability affects Adobe ColdFusion versions 2023 and 2025, [truncated]

CRITICAL Adobe CVE published 2026-07-14

CVE-2026-48318

The CVE-2026-48318 vulnerability in Adobe ColdFusion is caused by an improper limitation of a pathname to a restricted directory, leading to a path traversal issue. This allows attackers to access sensitive files and directories outside the intended access scope without requiring user interaction. The vulnerability has a CVSS score of 9.9 and is classified as CRITICAL. Affected products include Adobe Cold [truncated]

HIGH Adobe CVE published 2026-07-14

CVE-2026-48311

CVE-2026-48311 is an out-of-bounds write vulnerability in Adobe Bridge that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. This vulnerability has been rated as HIGH with a CVSS score of 7.8. The CVSS vector for this vulnerability is CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. U [truncated]

MEDIUM Adobe CVE published 2026-07-14

CVE-2026-48308

CVE-2026-48308 is an Improper Input Validation vulnerability in Premiere Pro that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed. This vulnerability has a CVSS sc [truncated]

CRITICAL Adobe CVE published 2026-07-14

CVE-2026-48284

The CVE-2026-48284 vulnerability in Adobe ColdFusion is caused by Improper Input Validation, which could result in arbitrary code execution in the context of the current user. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction. Scope is changed. Organizations should prioritize patching to prevent potential arbit [truncated]

HIGH Adobe CVE published 2026-07-14

CVE-2026-48272

CVE-2026-48272 is an Uncontrolled Search Path Element vulnerability in Adobe Creative Cloud Desktop that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed. This vulnerability has a high CVSS score of 7.8, indicating high severity. Users of A [truncated]

HIGH Adobe CVE published 2026-07-14

CVE-2026-48270

CVE-2026-48270 is an out-of-bounds write vulnerability in Adobe Premiere Pro that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. The vulnerability has a high severity with a CVSS score of 7.8. Users should be cautious when opening files from unknown sources and ensure that Adobe [truncated]

HIGH Adobe CVE published 2026-07-14

CVE-2026-48269

CVE-2026-48269 is a Heap-based Buffer Overflow vulnerability in Adobe Premiere Pro that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. This vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. The vulnerability requires user interaction, as a victim must open [truncated]

MEDIUM Adobe CVE published 2026-07-14

CVE-2026-47979

CVE-2026-47979 is an out-of-bounds read vulnerability in Adobe Media Encoder that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file. This vulnerability has a CVSS score of 5.5 and a severity rating of MEDIUM.

HIGH Adobe CVE published 2026-07-14

CVE-2026-47976

CVE-2026-47976 is an out-of-bounds write vulnerability in Adobe Media Encoder that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. The vulnerability has a CVSS score of 7.8 and a CVSS severity of HIGH. Users of Adobe Media Encoder versions 25.6.5 and earlier, as well as 26.2.2 and [truncated]

HIGH Adobe CVE published 2026-07-14

CVE-2026-47971

CVE-2026-47971 is a Stack-based Buffer Overflow vulnerability in Adobe Media Encoder. The vulnerability could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction, as a victim must open a malicious file. This vulnerability has a CVSS score of 7.8 and a CVSS severity of HIGH. The CVSS vector is CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A [truncated]

MEDIUM Adobe CVE published 2026-07-14

CVE-2026-48371

Adobe Commerce has a stored Cross-Site Scripting (XSS) vulnerability. A low-privileged attacker could inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. This vulnerability exists in various versions of Adobe Commerce, potentially leading to JavaScript execution in a victim's browser. [truncated]

CRITICAL Adobe CVE published 2026-07-14

CVE-2026-48359

Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability, which could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to read sensitive files, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue does not [truncated]

CRITICAL Adobe CVE published 2026-07-14

CVE-2026-48358

CVE-2026-48358 is a CRITICAL vulnerability in Adobe Commerce, with a CVSS score of 9.1. The vulnerability is caused by an Improper Encoding or Escaping of Output, which could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope i [truncated]

MEDIUM Adobe CVE published 2026-07-14

CVE-2026-48355

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. The vulnerability, tracked as CVE-2026-48355, has a CVSS score of 5.4 and a MEDIUM severit [truncated]