Skip to content
Adobe Patches Critical Flaws in Connect, AEM Forms

Adobe Patches Critical Flaws in Connect, AEM Forms

Securityweek September 23, 2026

Adobe on Tuesday rolled out patches for 36 vulnerabilities across its products, including critical-severity flaws in Connect and Experience Manager (AEM) Forms.

The Adobe Connect update resolves nine security defects, including six critical issues that could be exploited for arbitrary code execution and privilege escalation.

Tracked as CVE-2026-75682, CVE-2026-75684, CVE-2026-75686, CVE-2026-75689, CVE-2026-75697, and CVE-2026-75698, they are described as SQL injection, cross-site scripting (XSS), and improper input validation flaws.

The update also fixes high-severity path traversal, improper certificate validation, and XSS weaknesses that could lead to arbitrary file system read, security feature bypass, and arbitrary code execution.

Adobe patched six vulnerabilities in AEM Forms, including three critical-severity flaws leading to code execution and privilege escalation.

Described as incorrect authorization, improper input validation, and server-side request forgery (SSRF), the critical issues are tracked as CVE-2026-75745, CVE-2026-81995, and CVE-2026-82000.

The AEM Forms patches also fix three high-severity SSRF, XSS, and cross-site request forgery (CSRF) bugs leading to privilege escalation, code execution, and security feature bypass.

Both security updates have a priority 2 rating, meaning that users should apply them within the 30 days.

On Tuesday, Adobe also announced fixes for multiple high- and medium-severity vulnerabilities in InDesign, Content Credentials SDK, Bridge, Substance 3D Modeler, and Premiere Pro.

Successful exploitation of these security defects could lead to application denial-of-service (DoS), security feature bypass, arbitrary code execution, and memory exposure.

Adobe says it is not aware of any of these security flaws being exploited in the wild. Additional information is available on the company’s security bulletins page.

Related: Chrome 154 Patches 108 Vulnerabilities

Related: Arista Urges Immediate Patching of Exploited VCO Zero-Day

Related: Chrome, Firefox Updates Patch 115 Vulnerabilities

Related: Check Point, Kaspersky, Tanium Patch Product Vulnerabilities

Chrome 154 Patches 108 Vulnerabilities

The browser update resolves several critical-severity memory safety and memory corruption flaws.

Arista Urges Immediate Patching of Exploited VCO Zero-Day

Remote attackers could trigger the critical-severity flaw to access privileged internal functionality.

Critical F5 BIG-IP Vulnerability Exploited as Zero-Day

Unauthenticated attackers could send malicious traffic to BIG-IP to achieve remote code execution.

Check Point Patches Exploited Management Server Zero-Day

The critical-severity flaw could allow unauthenticated attackers to upload and execute arbitrary scripts.

Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers

A Chinese threat actor has exploited the bug to exfiltrate sensitive information from nearly 1,000 ZyXEL switches.

WordPress Patches ‘Click2Shell’ Vulnerability

The bug lets attackers automatically install and preview themes and could lead to remote code execution.

Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities

Attackers could exploit the flaws to cause denial-of-service conditions, disclose memory, or modify memory.

Artificial Intelligence

AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code

Hacktron researchers earned a bug bounty after demonstrating access to OpenAI employee accounts.