PatchSiren

Adobe CVE debriefs · Page 8

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Adobe CVE published 2026-07-14

CVE-2026-48350

CVE-2026-48350 is a Path Traversal vulnerability in Adobe Animate that could result in arbitrary code execution. This vulnerability requires user interaction and could allow an attacker to access sensitive files or directories outside the intended restrictions. The vulnerability has a CVSS score of 8.6 and is classified as HIGH severity. Users of Adobe Animate, particularly those who handle sensitive file [truncated]

HIGH Adobe CVE published 2026-07-14

CVE-2026-48349

CVE-2026-48349 is an Incorrect Authorization vulnerability in Adobe Animate that could result in arbitrary code execution. This AI-assisted PatchSiren debrief provides an overview of the vulnerability, recommended actions, and evidence notes. Affected product deployments should be reviewed for potential exposure. The vulnerability has a CVSS score of 8.1 and is classified as HIGH severity. Exploitation of [truncated]

HIGH Adobe CVE published 2026-07-14

CVE-2026-48348

CVE-2026-48348 is an Incorrect Authorization vulnerability in Adobe Animate that could result in arbitrary code execution. This AI-assisted PatchSiren debrief is based on the supplied source corpus. The CVE record was published on 2026-07-14T20:17:07.940Z and has not been modified since then. The NVD entry is currently Analyzed. The vulnerability requires user interaction and depends on conditions beyond [truncated]

HIGH Adobe CVE published 2026-07-14

CVE-2026-48347

CVE-2026-48347 is an OS Command Injection vulnerability in Adobe Animate that could result in arbitrary code execution in the context of the current user. Exploitation requires user interaction, as a victim must open a malicious file. The vulnerability has a CVSS score of 7.7, indicating high severity. It affects Adobe Animate versions 23.0.0 to 23.0.16 and 24.0.0 to 24.0.14. Users of Adobe Animate, parti [truncated]

HIGH Adobe CVE published 2026-07-14

CVE-2026-48346

CVE-2026-48346 is an Untrusted Search Path vulnerability in Adobe Animate that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. The vulnerability exists due to an Untrusted Search Path in Adobe Animate. An attacker could exploit this vulnerability by convincing a user to open a mal [truncated]

HIGH Adobe CVE published 2026-07-14

CVE-2026-48345

CVE-2026-48345 is an OS Command Injection vulnerability in Adobe Animate that could result in arbitrary code execution. This PatchSiren debrief provides an AI-assisted analysis based on the supplied source corpus. The vulnerability has a CVSS score of 8.2 and is classified as HIGH severity. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. [truncated]

HIGH Adobe CVE published 2026-07-14

CVE-2026-48310

CVE-2026-48310 is an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Adobe Experience Manager. The vulnerability could lead to arbitrary file system read, allowing an attacker to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. The scope is changed. This vulnerability has [truncated]

MEDIUM Adobe CVE published 2026-07-14

CVE-2026-48263

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. This vulnerability has a CVSS score of 5.4 and a severity of MEDIUM. The scope of the vulnerability has been changed. Users should review their deployments and take steps to mitigate this vulnerability.

MEDIUM Adobe CVE published 2026-07-14

CVE-2026-48260

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. This type of vulnerability typically involves user interaction, such as visiting a crafted webpage. The scope of this vulnerability is changed, suggesting that the i [truncated]

CRITICAL Adobe CVE published 2026-07-14

CVE-2026-48259

Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could leverage this vulnerability to issue unauthorized server-side requests, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue does not require us [truncated]

MEDIUM Adobe CVE published 2026-07-14

CVE-2026-48257

CVE-2026-48257 is a DOM-based Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. The vulnerability affects Adobe Experience Manager, potenti [truncated]

MEDIUM Adobe CVE published 2026-07-14

CVE-2026-48255

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. This requires user interaction, as a victim must visit a crafted webpage. The vulnerability has a CVSS score of 5.4 and a severity of MEDIUM. The scope of this issue [truncated]

MEDIUM Adobe CVE published 2026-07-14

CVE-2026-48254

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. The vulnerability has a CVSS score of 5.4 and a severity of MEDIU [truncated]

MEDIUM Adobe CVE published 2026-07-14

CVE-2026-48253

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. This requires user interaction, as a victim must visit a crafted webpage. The scope of this vulnerability is changed, indicating potential impact on other components [truncated]

HIGH Adobe CVE published 2026-07-14

CVE-2026-48252

CVE-2026-48252 is an 8.6 HIGH severity vulnerability in Adobe Experience Manager, classified as a Missing Authentication for Critical Function vulnerability. This type of vulnerability could allow an attacker to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction. The CVE record was published on 2026-07-14T20:17:06.053Z and has not been [truncated]

LOW Adobe CVE published 2026-07-14

CVE-2026-48001

The CVE-2026-48001 Information Exposure vulnerability affects Adobe Commerce, potentially leading to limited disclosure of sensitive information. The vulnerability has a CVSS Score of 3.7 (Low) and depends on conditions beyond the attacker's control, with no user interaction required for exploitation. Affected versions include Commerce 2.4.4 through 2.4.9 and Commerce B2B 1.3.3 through 1.5.3. Organization [truncated]

MEDIUM Adobe CVE published 2026-07-14

CVE-2026-47999

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T20:17:05.200Z and has not been modified since then. The NVD entry is currently Analyzed. CVE-2026-47999 is a stored Cross-Site Scripting (XSS) vulnerability in Adobe Commerce and Magento Open Source. A high-privileged attacker could abuse this vulnerability to inject malicious scripts into vulner [truncated]

MEDIUM Adobe CVE published 2026-07-14

CVE-2026-47996

CVE-2026-47996 is an Incorrect Authorization vulnerability in Adobe Commerce, allowing high-privileged attackers to access sensitive files and directories outside intended scopes. The vulnerability was published on 2026-07-14 and has a CVSS score of 6.8. Affected versions include Commerce 2.4.4 to 2.4.9 and Commerce B2B 1.3.3 to 1.5.3. No user interaction is required for exploitation. The scope of this vu [truncated]

HIGH Adobe CVE published 2026-07-14

CVE-2026-47988

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T20:17:04.347Z and has not been modified since then. The NVD entry is currently Analyzed. CVE-2026-47988 is an Incorrect Authorization vulnerability in Adobe Commerce that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain [truncated]

HIGH Adobe CVE published 2026-07-14

CVE-2026-48309

Adobe Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. This high-severity issue requires user interaction, as a victim must open a malicious file. The vulnerability's impact is significant, potentially allowing attackers to execute arbitrary code, emphasizing the need for immediate patching. IT teams and security [truncated]

HIGH Adobe CVE published 2026-07-13

CVE-2026-48364

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-13T21:16:48.337Z and has not been modified since then. ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element vulnerability. This vulnerability could result in arbitrary code execution in the context of the current user if a victim opens a malicious file. [truncated]

HIGH Adobe CVE published 2026-07-13

CVE-2026-48363

CVE-2026-48363 is an Uncontrolled Search Path Element vulnerability affecting Adobe ColdFusion versions 2025.9, 2023.20, and earlier. This vulnerability could result in arbitrary code execution in the context of the current user, requiring user interaction to open a malicious file. The vulnerability's scope is limited to the current user, but it can have significant impacts if exploited. Administrators an [truncated]

Known exploited Adobe CVE published 2026-07-07

CVE-2026-48282

Adobe ColdFusion Path Traversal Vulnerability debrief. A critical vulnerability in Adobe ColdFusion allows for potential path traversal attacks. Administrators and security teams must assess exposure and apply mitigations according to vendor instructions. The vulnerability's impact and exploitation details are limited, emphasizing the need for prompt assessment and mitigation. Affected product deployments [truncated]

MEDIUM Adobe CVE published 2026-07-06

CVE-2026-48267

A NULL Pointer Dereference vulnerability exists in DNG SDK versions 1.7.1 2536 and earlier. This vulnerability could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file. The vulnerability has a CVSS score o [truncated]

CRITICAL Adobe CVE published 2026-07-06

CVE-2026-48316

CVE-2026-48316 is an Improper Input Validation vulnerability affecting ColdFusion versions 2025.9, 2023.20 and earlier. This vulnerability could result in arbitrary code execution in the context of the current user, with exploitation not requiring user interaction. The scope of this vulnerability has been changed. Affected administrators and users should be aware of this vulnerability and take necessary a [truncated]

CRITICAL Adobe CVE published 2026-06-30

CVE-2026-48315

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-06-30T16:16:55.310Z and has not been modified since then. The NVD entry is currently Analyzed. The vulnerability is an Improper Input Validation issue in Adobe ColdFusion versions 2025.9, 2023.20 and earlier. This could result in arbitrary code execution in the context of the current user. An attacker [truncated]

MEDIUM Adobe CVE published 2026-06-30

CVE-2026-48314

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-06-30T16:16:55.200Z and has not been modified since then. The NVD entry is currently Analyzed. This Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Adobe ColdFusion could allow attackers to bypass security features, gaining limited access to unauthorized [truncated]

CRITICAL Adobe CVE published 2026-06-30

CVE-2026-48313

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-06-30T16:16:55.093Z and has not been modified since then. The NVD entry is currently Analyzed. Adobe ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. This could lead to arbitrary file system [truncated]

CRITICAL Adobe CVE published 2026-06-30

CVE-2026-48286

The CVE-2026-48286 record indicates an Incorrect Authorization vulnerability in Adobe Campaign Classic versions 7.4.3 build 9396 and earlier. This vulnerability could result in arbitrary code execution in the context of the current user, with a CVSS score of 10 and severity of CRITICAL. Exploitation does not require user interaction, and the scope is changed. Organizations should review their deployments [truncated]

CRITICAL Adobe CVE published 2026-06-30

CVE-2026-48283

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-06-30T16:16:54.643Z and has not been modified since then. The NVD entry is currently Analyzed. This Unrestricted Upload of File with Dangerous Type vulnerability in Adobe ColdFusion could result in arbitrary code execution in the context of the current user. Affected versions include 2025.9, 2023.20, a [truncated]