← Intelligence Center

Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution

PublishedJul 14, 2026
Updated
VendorAdobe
SeverityHigh
Known ExploitedNo
Advisory IDINTEL-000006
CVEs
CVE-2026-34690CVE-2026-47967CVE-2026-47968CVE-2026-47969CVE-2026-47971CVE-2026-47976CVE-2026-47979CVE-2026-47984CVE-2026-47988CVE-2026-47992CVE-2026-47994CVE-2026-47995CVE-2026-47996CVE-2026-47997CVE-2026-47998CVE-2026-47999CVE-2026-48000CVE-2026-48001CVE-2026-48252CVE-2026-48253CVE-2026-48254CVE-2026-48255CVE-2026-48257CVE-2026-48259CVE-2026-48260CVE-2026-48261CVE-2026-48262CVE-2026-48263CVE-2026-48269CVE-2026-48270CVE-2026-48272CVE-2026-48274CVE-2026-48275CVE-2026-48284CVE-2026-48287CVE-2026-48290CVE-2026-48295CVE-2026-48296CVE-2026-48298CVE-2026-48302CVE-2026-48308CVE-2026-48309CVE-2026-48310CVE-2026-48311CVE-2026-48312CVE-2026-48318CVE-2026-48319CVE-2026-48320CVE-2026-48321CVE-2026-48322CVE-2026-48324CVE-2026-48325CVE-2026-48327CVE-2026-48328CVE-2026-48329CVE-2026-48332CVE-2026-48334CVE-2026-48336CVE-2026-48337CVE-2026-48338CVE-2026-48339CVE-2026-48340CVE-2026-48341CVE-2026-48342CVE-2026-48343CVE-2026-48344CVE-2026-48345CVE-2026-48346CVE-2026-48347CVE-2026-48348CVE-2026-48349CVE-2026-48350CVE-2026-48351CVE-2026-48352CVE-2026-48353CVE-2026-48354CVE-2026-48355CVE-2026-48356CVE-2026-48357CVE-2026-48358CVE-2026-48359CVE-2026-48365CVE-2026-48366CVE-2026-48367CVE-2026-48368CVE-2026-48369CVE-2026-48370
Products
  • Adobe After Effects 25.6.5 and earlier; 26.2.1 and earlier
  • Adobe Animate 2023 23.0.15 and earlier; 2024 24.0.13 and earlier
  • Adobe Audition 25.6.4 and earlier; 26.0 and earlier
  • Adobe Bridge 15.1.5 (LTS) and earlier; 16.0.3 and earlier
  • Adobe Commerce 2.4.4-p18 and earlier, 2.4.5-p17, 2.4.6-p15, 2.4.7-p10, 2.4.8-p5, 2.4.9
  • Adobe Commerce B2B 1.3.3-p18 and earlier, 1.3.4-p17, 1.4.2-p10, 1.5.2-p5, 1.5.3
  • Adobe Commerce Events 1.6.0 to 1.20.0
  • Adobe Experience Manager (AEM) Cloud Service (CS) Release 2026.5.0 and earlier; 6.5 LTS Service Pack 1 and earlier; 6.5 Service Pack 24 and earlier
  • Adobe Media Encoder 25.6.5 and earlier; 26 and earlier
  • Additional Adobe products covered by APSB26-71 through APSB26-83 (e.g., Audition, Bridge, ColdFusion, Content Authenticity SDK, Illustrator, Magento, Premiere Pro, After Effects, Media Encoder, Animate, AEM, Creative Cloud)

Executive Summary

MS-ISAC Advisory 2026-067 (issued 7/14/2026): multiple vulnerabilities in Adobe products (After Effects, Animate, Audition, Bridge, Commerce/Magento, Experience Manager, Media Encoder, and others) could allow for arbitrary code execution. There are currently no reports of these vulnerabilities being exploited in the wild. Updates are provided across Adobe Security Bulletins APSB26-71 through APSB26-83.

Municipal Impact

MS-ISAC rates the risk as High for large and medium government entities and Medium for small government entities; municipal agencies should update Adobe products promptly.

SMB Impact

MS-ISAC rates the risk as High for large and medium business entities, Medium for small business entities, and Low for home users.

Recommended Actions

  1. Apply the stable channel updates provided by Adobe to vulnerable systems immediately after appropriate testing.
  2. Apply the principle of least privilege to all systems and services.
  3. Follow CIS Safeguards for vulnerability management, automated patch management, and remediation.

Grey Matter Analysis

Analysis pending review.

References

Tags

AdobeAfter EffectsAnimateAuditionBridgeCommerceMagentoAEMMedia EncoderColdFusionPremiere ProIllustratorCreative CloudMulti-CVETA0002T1203

Related Intelligence

Need help with this advisory?

Contact Grey Matter to assess your exposure and prioritize remediation.

Contact Grey Matter