Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution
- •Adobe After Effects 25.6.5 and earlier; 26.2.1 and earlier
- •Adobe Animate 2023 23.0.15 and earlier; 2024 24.0.13 and earlier
- •Adobe Audition 25.6.4 and earlier; 26.0 and earlier
- •Adobe Bridge 15.1.5 (LTS) and earlier; 16.0.3 and earlier
- •Adobe Commerce 2.4.4-p18 and earlier, 2.4.5-p17, 2.4.6-p15, 2.4.7-p10, 2.4.8-p5, 2.4.9
- •Adobe Commerce B2B 1.3.3-p18 and earlier, 1.3.4-p17, 1.4.2-p10, 1.5.2-p5, 1.5.3
- •Adobe Commerce Events 1.6.0 to 1.20.0
- •Adobe Experience Manager (AEM) Cloud Service (CS) Release 2026.5.0 and earlier; 6.5 LTS Service Pack 1 and earlier; 6.5 Service Pack 24 and earlier
- •Adobe Media Encoder 25.6.5 and earlier; 26 and earlier
- •Additional Adobe products covered by APSB26-71 through APSB26-83 (e.g., Audition, Bridge, ColdFusion, Content Authenticity SDK, Illustrator, Magento, Premiere Pro, After Effects, Media Encoder, Animate, AEM, Creative Cloud)
Executive Summary
MS-ISAC Advisory 2026-067 (issued 7/14/2026): multiple vulnerabilities in Adobe products (After Effects, Animate, Audition, Bridge, Commerce/Magento, Experience Manager, Media Encoder, and others) could allow for arbitrary code execution. There are currently no reports of these vulnerabilities being exploited in the wild. Updates are provided across Adobe Security Bulletins APSB26-71 through APSB26-83.
Municipal Impact
MS-ISAC rates the risk as High for large and medium government entities and Medium for small government entities; municipal agencies should update Adobe products promptly.
SMB Impact
MS-ISAC rates the risk as High for large and medium business entities, Medium for small business entities, and Low for home users.
Recommended Actions
- Apply the stable channel updates provided by Adobe to vulnerable systems immediately after appropriate testing.
- Apply the principle of least privilege to all systems and services.
- Follow CIS Safeguards for vulnerability management, automated patch management, and remediation.
Grey Matter Analysis
References
- https://learn.cisecurity.org/e/799323/-creative-cloud-apsb26-77-html/4vzylk/2726897785/h/CoX6C5v9EtICAHLSFWNzWTBlW815rcSTVpC4g8OzEmI
- https://learn.cisecurity.org/e/799323/cts-illustrator-apsb26-79-html/4vzylr/2726897785/h/CoX6C5v9EtICAHLSFWNzWTBlW815rcSTVpC4g8OzEmI
- https://learn.cisecurity.org/e/799323/erience-manager-apsb26-74-html/4vzylc/2726897785/h/CoX6C5v9EtICAHLSFWNzWTBlW815rcSTVpC4g8OzEmI
- https://learn.cisecurity.org/e/799323/oducts-audition-apsb26-71-html/4vzyl2/2726897785/h/CoX6C5v9EtICAHLSFWNzWTBlW815rcSTVpC4g8OzEmI
- https://learn.cisecurity.org/e/799323/products-bridge-apsb26-81-html/4vzyly/2726897785/h/CoX6C5v9EtICAHLSFWNzWTBlW815rcSTVpC4g8OzEmI
- https://learn.cisecurity.org/e/799323/roducts-animate-apsb26-83-html/4vzym5/2726897785/h/CoX6C5v9EtICAHLSFWNzWTBlW815rcSTVpC4g8OzEmI
- https://learn.cisecurity.org/e/799323/roducts-magento-apsb26-73-html/4vzyl8/2726897785/h/CoX6C5v9EtICAHLSFWNzWTBlW815rcSTVpC4g8OzEmI
- https://learn.cisecurity.org/e/799323/s-after-effects-apsb26-78-html/4vzyln/2726897785/h/CoX6C5v9EtICAHLSFWNzWTBlW815rcSTVpC4g8OzEmI
- https://learn.cisecurity.org/e/799323/s-media-encoder-apsb26-72-html/4vzyl5/2726897785/h/CoX6C5v9EtICAHLSFWNzWTBlW815rcSTVpC4g8OzEmI
- https://learn.cisecurity.org/e/799323/ts-premiere-pro-apsb26-76-html/4vzylg/2726897785/h/CoX6C5v9EtICAHLSFWNzWTBlW815rcSTVpC4g8OzEmI
- https://learn.cisecurity.org/e/799323/ucts-coldfusion-apsb26-82-html/4vzym2/2726897785/h/CoX6C5v9EtICAHLSFWNzWTBlW815rcSTVpC4g8OzEmI
- https://learn.cisecurity.org/e/799323/uthenticity-sdk-apsb26-80-html/4vzylv/2726897785/h/CoX6C5v9EtICAHLSFWNzWTBlW815rcSTVpC4g8OzEmI
- https://learn.cisecurity.org/e/799323/security-Home-html/4vzyky/2726897785/h/CoX6C5v9EtICAHLSFWNzWTBlW815rcSTVpC4g8OzEmI
- https://learn.cisecurity.org/e/799323/resources--type-advisory/4vzyk2/2726897785/h/CoX6C5v9EtICAHLSFWNzWTBlW815rcSTVpC4g8OzEmI
Tags
Related Intelligence
Need help with this advisory?
Contact Grey Matter to assess your exposure and prioritize remediation.
Contact Grey Matter