Adobe issued patches for 36 security vulnerabilities affecting several of its products. The updates include fixes for critical-severity flaws in Adobe Connect and Adobe Experience Manager (AEM) Forms, alongside high- and medium-severity issues in other applications.
The Adobe Connect update resolves nine security defects, with six identified as critical. These critical vulnerabilities, tracked as CVE-2026-75682, CVE-2026-75684, CVE-2026-75686, CVE-2026-75689, CVE-2026-75697, and CVE-2026-75698, involve SQL injection, cross-site scripting (XSS), and improper input validation. Successful exploitation could lead to arbitrary code execution and privilege escalation. Additional high-severity flaws addressed include path traversal, improper certificate validation, and XSS, which could result in arbitrary file system reads, security feature bypass, and arbitrary code execution.
Adobe also patched six vulnerabilities in AEM Forms, three of which are critical. These critical issues, CVE-2026-75745, CVE-2026-81995, and CVE-2026-82000, are related to incorrect authorization, improper input validation, and server-side request forgery (SSRF), potentially leading to code execution and privilege escalation. High-severity SSRF, XSS, and cross-site request forgery (CSRF) bugs were also fixed, which could cause privilege escalation, code execution, and security feature bypass.
Beyond Connect and AEM Forms, Adobe released fixes for high- and medium-severity vulnerabilities in InDesign, Content Credentials SDK, Bridge, Substance 3D Modeler, and Premiere Pro. These defects could lead to application denial-of-service (DoS), security feature bypass, arbitrary code execution, and memory exposure. All security updates for Connect and AEM Forms have a priority 2 rating, indicating that users should apply them within 30 days. Adobe has stated it is not aware of any in-the-wild exploitation of these security flaws.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Adobe released patches for 36 vulnerabilities across its products, including critical flaws in Connect and Experience Manager (AEM) Forms that could lead to arbitrary code execution and privilege escalation. These updates address SQL injection, XSS, and server-side request forgery issues, and users are advised to apply them within 30 days.