Skip to content
Patchday: Adobe closes over 120 security vulnerabilities in InDesign & Co.

Patchday: Adobe closes over 120 security vulnerabilities in InDesign & Co.

Heise.De June 10, 2026

On this Patchday, two “critical” security vulnerabilities with the highest rating in Adobe Campaign Classic are considered the most dangerous. Malicious code can thus enter PCs and completely compromise systems. Security updates are available for download. So far, there are no reports that attackers are already exploiting the vulnerabilities.

As a warning message indicates , the Campaign Classic vulnerabilities (CVE-2026-48303, CVE-2026-47938) have the maximum CVSS score of 10 out of 10. How malicious code attacks could proceed in detail is not yet known. Linux and Windows are threatened by this. The developers assure that the security problems have been solved in v7: 7.4.3 build 9396 .

ColdFusion 2023 and 2025 are vulnerable through six vulnerabilities classified as “ critical ” by Adobe. According to a report, all platforms are affected by this . For example, attackers can execute malicious code (CVE-2026-47928), bypass security measures (CVE-2026-47932), or gain higher user privileges (CVE-2026-47929). Here, ColdFusion 2023 Update 20 and ColdFusion 2025 Update 9 provide a remedy.

According to the software manufacturer, two vulnerabilities (CVE-2026-34691, CVE-2026-34693) in Experience Manager Forms for all platforms are also considered “ critical. ” Here, malicious code can enter systems in the form of stored and reflected XSS attacks.

With 56 items, Adobe has closed the most vulnerabilities in Experience Manager. Here, the versions AEM Cloud Service (CS) Release 2026.05, 6.5 LTS Service Pack 2, and 6.5 Service Pack 25 help.

Further information on threatened and repaired versions can be found by admins in the official security advisories.

This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.