Back Securityweek Adobe Patches Critical Flaws in Connect, AEM Forms
Adobe on Tuesday rolled out patches for 36 vulnerabilities across its products, including critical-severity flaws in Connect and Experience Manager (AEM) Forms.
The Adobe Connect update resolves nine security defects, including six critical issues that could be exploited for arbitrary code execution and privilege escalation.
Tracked as CVE-2026-75682, CVE-2026-75684, CVE-2026-75686, CVE-2026-75689, CVE-2026-75697, and CVE-2026-75698, they are described as SQL injection, cross-site scripting (XSS), and improper input validation flaws.
The update also fixes high-severity path traversal, improper certificate validation, and XSS weaknesses that could lead to arbitrary file system read, security feature bypass, and arbitrary code execution.
Adobe patched six vulnerabilities in AEM Forms, including three critical-severity flaws leading to code execution and privilege escalation.
Described as incorrect authorization, improper input validation, and server-side request forgery (SSRF), the critical issues are tracked as CVE-2026-75745, CVE-2026-81995, and CVE-2026-82000.
The AEM Forms patches also fix three high-severity SSRF, XSS, and cross-site request forgery (CSRF) bugs leading to privilege escalation, code execution, and security feature bypass.
Both security updates have a priority 2 rating, meaning that users should apply them within the 30 days.
On Tuesday, Adobe also announced fixes for multiple high- and medium-severity vulnerabilities in InDesign, Content Credentials SDK, Bridge, Substance 3D Modeler, and Premiere Pro.
Successful exploitation of these security defects could lead to application denial-of-service (DoS), security feature bypass, arbitrary code execution, and memory exposure.
Adobe says it is not aware of any of these security flaws being exploited in the wild. Additional information is available on the company’s security bulletins page.
Related: Chrome 154 Patches 108 Vulnerabilities
Related: Arista Urges Immediate Patching of Exploited VCO Zero-Day
Related: Chrome, Firefox Updates Patch 115 Vulnerabilities
Related: Check Point, Kaspersky, Tanium Patch Product Vulnerabilities
Chrome 154 Patches 108 Vulnerabilities
The browser update resolves several critical-severity memory safety and memory corruption flaws.
Arista Urges Immediate Patching of Exploited VCO Zero-Day
Remote attackers could trigger the critical-severity flaw to access privileged internal functionality.
Critical F5 BIG-IP Vulnerability Exploited as Zero-Day
Unauthenticated attackers could send malicious traffic to BIG-IP to achieve remote code execution.
Check Point Patches Exploited Management Server Zero-Day
The critical-severity flaw could allow unauthenticated attackers to upload and execute arbitrary scripts.
Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers
A Chinese threat actor has exploited the bug to exfiltrate sensitive information from nearly 1,000 ZyXEL switches.
WordPress Patches ‘Click2Shell’ Vulnerability
The bug lets attackers automatically install and preview themes and could lead to remote code execution.
Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities
Attackers could exploit the flaws to cause denial-of-service conditions, disclose memory, or modify memory.
Artificial Intelligence
AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code
Hacktron researchers earned a bug bounty after demonstrating access to OpenAI employee accounts.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
