Skip to content
Multiple Adobe CVEs Disclosed: High-Risk Vulnerabilities Identified

Multiple Adobe CVEs Disclosed: High-Risk Vulnerabilities Identified

First seen 23 Sep 2026, 00:57 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 23, 2026 at 01:59 UTC
  • Three critical Adobe vulnerabilities disclosed on September 22, 2026.
  • CVE-2026-75743 and CVE-2026-75649 require user interaction for exploitation.
  • CVE-2026-75632 poses a denial-of-service risk without user interaction.

On September 22, 2026, Adobe disclosed three critical vulnerabilities affecting its products: CVE-2026-75743 (CSRF in Adobe Experience Manager Forms JEE), CVE-2026-75632 (Uncontrolled Resource Consumption in CAI Content Credentials), and CVE-2026-75649 (Heap-based Buffer Overflow in Adobe Bridge). CVE-2026-75743 requires user interaction and could allow unauthorized write access, while CVE-2026-75632 can lead to denial-of-service without user interaction. CVE-2026-75649 allows arbitrary code execution upon opening a malicious file. Organizations using these Adobe products, especially those with internet-facing services, are at high risk. Immediate remediation is advised, although the urgency of exploitation varies due to lack of PoC or active exploitation reports. The vulnerabilities could disrupt workflows, cause service outages, and lead to unauthorized changes or data breaches.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-22
CVE-2026-75743 published
Adobe disclosed a CSRF vulnerability in Experience Manager Forms JEE affecting user access.
Redpacketsecurity
2026-09-22
CVE-2026-75632 published
Adobe revealed an Uncontrolled Resource Consumption vulnerability in CAI Content Credentials leading to denial-of-service.
Redpacketsecurity
2026-09-22
CVE-2026-75649 published
Adobe announced a Heap-based Buffer Overflow vulnerability in Adobe Bridge allowing arbitrary code execution.
Redpacketsecurity

More articles in this cluster (3)

Following this threat?

Track CVE-2026-75632 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed