Adobe is a multinational software company known for its creative, marketing, and document management products, including web platform components such as Adobe ColdFusion and Adobe Experience Manager (AEM).
Overview
Adobe is a multinational software company known for its creative, marketing, and document management products, including web platform components such as Adobe ColdFusion and Adobe Experience Manager (AEM). These platforms are widely used to build and manage web applications and content, making them attractive targets for threat actors; recent reports indicate attackers targeting ColdFusion deployments and the existence of critical vulnerabilities in ColdFusion and AEM, underscoring cybersecurity risk and the need for timely patching and monitoring.
Related Threat Clusters
-
Adobe Issues Critical Patches for Flash and PDF Vulnerabilities
Adobe has released urgent patches for critical vulnerabilities in its Flash, Reader, and Acrobat applications. The first patch addresses a zero-day flaw in the Authplay component, while the second targets a JavaScript…
2 articles · Updated January 23, 2026 -
Multiple Critical Vulnerabilities Exploited in SonicWall and SharePoint Systems
In July 2026, several critical vulnerabilities were exploited, impacting SonicWall SMA1000 appliances and SharePoint servers. Two zero-day vulnerabilities, CVE-2026-15409 and CVE-2026-15410, were discovered in SonicWall…
2 articles · Updated July 28, 2026 -
Critical Exploitation of Ruby on Rails Vulnerability CVE-2026-66066 Confirmed
Threat actors are actively exploiting CVE-2026-66066, a critical Ruby on Rails vulnerability known as KindaRails2Shell, which allows unauthenticated attackers to read arbitrary files from servers, potentially leading to…
5 articles · Updated August 31, 2026 -
Critical Access Control Bypass in Adobe ColdFusion (CVE-2023-29298)
Rapid7 disclosed an access control bypass vulnerability in Adobe ColdFusion, identified as CVE-2023-29298, which affects versions 2018u16, 2021u6, and 2023. The vulnerability allows attackers to access restricted…
60 articles · Updated June 29, 2026 -
UNC6783 Exploits BPOs for Data Extortion via Phishing Campaigns
The Google Threat Intelligence Group (GTIG) reported that a financially motivated cybercriminal group, UNC6783, is targeting business process outsourcing (BPO) companies to infiltrate high-value organizations across…
8 articles · Updated April 8, 2026 -
Adobe Patches 52 Critical Vulnerabilities in Multiple Products
Adobe has released security patches addressing 52 vulnerabilities across 10 products, including After Effects, Connect, and Premiere Pro. The most critical vulnerability, CVE-2026-34659, allows for arbitrary code…
2 articles · Updated May 13, 2026 -
Adobe Acrobat Extension Vulnerability Enables WhatsApp Data Theft
A critical vulnerability in the Adobe Acrobat Chrome extension, tracked as CVE-2026-48294 and named HermeticReader, allows attackers to access WhatsApp Web data without authentication. The flaw affects approximately 329…
8 articles · Updated July 22, 2026 -
Five-Month Espionage Campaign Targets Stock Exchange Executive's Email
A five-month-long espionage campaign targeted the email account of a senior executive at a major global stock exchange. The attackers gained access to sensitive information, including emails, calendar events, and…
9 articles · Updated June 3, 2026 -
Smoke#Screen Campaign Uses Fake Updates to Install Remote Access Tool
The Smoke#Screen campaign exploits social engineering tactics to install the legitimate ScreenConnect RMM tool on compromised systems, providing attackers with remote access. Targeting both Windows and macOS, the…
8 articles · Updated August 4, 2026 -
Anthropic's Claude Mythos Preview Sparks Cybersecurity Revolution
Anthropic has announced the launch of Project Glasswing, utilizing its unreleased AI model, Claude Mythos Preview, to identify and exploit thousands of critical software vulnerabilities across major operating systems…
1399 articles · Updated April 7, 2026
Recent Intelligence Reports
- Huntress says — www.huntress.com · September 1, 2026
- Critical Ruby on Rails Vulnerability in Attackers' Crosshairs — Securityweek · August 31, 2026
- How AI — Bleepingcomputer · August 5, 2026
- How AI — Bleepingcomputer · August 5, 2026
- SMOKE#SCREEN Campaign Abuses ScreenConnect to Give Attackers Remote Control Access — Securityaffairs.Co · August 5, 2026
- Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code… — Develeap · August 2, 2026
- >> Read this brief on krypteiasec.com — krypteiasec.com · July 29, 2026
- Daily Threat Brief: July 27, 2026 — Buttondown · July 28, 2026