Adobe has released Priority 1 security updates for 12 product lines, addressing 88 vulnerabilities. The most critical flaws affect ColdFusion and Adobe Commerce, where attackers could achieve remote code execution.
Adobe’s latest Patch Tuesday delivers security updates for 12 product families, fixing a total of 88 vulnerabilities. The most urgent issues involve 13 security flaws in the ColdFusion web application platform. Eight of these vulnerabilities, including CVE-2026-48318, CVE-2026-48322, and CVE-2026-48284, are rated critical. The flaws include code injection, SQL injection, improper input validation, path traversal, and missing authentication checks.
If exploited, these vulnerabilities could allow attackers to execute arbitrary code and escalate privileges without authorization. The issues have been resolved in ColdFusion 2025 Update 11 and ColdFusion 2023 Update 22. Adobe has assigned the updates its highest Priority 1 rating, emphasizing the urgency of deployment. The release comes just two weeks after an emergency ColdFusion patch that addressed a vulnerability actively exploited shortly after its disclosure.
Critical flaws also affect Commerce and Experience Manager
Beyond ColdFusion, three additional core Adobe products contain critical security vulnerabilities. Adobe Commerce received fixes for 13 security issues, including two critical flaws, CVE-2026-48356 and CVE-2026-48358, which could enable privilege escalation and arbitrary code execution.
Adobe Experience Manager also received patches for 13 vulnerabilities, including the critical issues CVE-2026-48259 and CVE-2026-48359. Adobe Illustrator, meanwhile, fixes a critical improper input validation vulnerability tracked as CVE-2026-48334 that could lead to privilege escalation.
Creative Cloud and additional applications receive security updates
The remaining fixes are spread across several Adobe applications. The Content Credentials SDK received 12 security patches, while Animate, Audition, and Bridge each addressed six vulnerabilities. Adobe also released updates for Media Encoder, including PDF-related security fixes, Premiere Pro with four patches, After Effects with three, and the Creative Cloud Desktop application with two security fixes.
According to Adobe, the company is not aware of any active exploitation of the vulnerabilities addressed in this release at the time of publication. Nevertheless, organizations and individual users are strongly encouraged to install the available updates as soon as possible.
(ll)