VYPR
Vypr IntelligenceAI-generatedAug 11, 2026· 25 CVEs

Adobe: 25 Vulnerabilities Across Multiple Products Disclosed in Single Batch

Adobe disclosed 25 vulnerabilities on August 11, 2026, impacting multiple products including Campaign Classic, Commerce, and Lightroom Classic, with critical flaws enabling code execution.

Key findings

  • 25 vulnerabilities disclosed across Adobe Campaign Classic, Commerce, Lightroom Classic, CAI Content Credentials, and ColdFusion on August 11, 2026.
  • Critical vulnerabilities in ACC and Commerce allow for arbitrary code execution and privilege escalation.
  • Lightroom Classic faces High-severity risks including Path Traversal and Out-of-Bounds Write vulnerabilities.
  • CVE-2026-71362 in Adobe Commerce was reportedly exploited immediately after disclosure.
  • A total of 15 vulnerabilities were disclosed for Adobe C2pa Web's CAI Content Credentials component.

On August 11, 2026, Adobe disclosed a significant batch of 25 vulnerabilities affecting multiple products, including Adobe Campaign Classic (ACC), Adobe Commerce, Lightroom Classic, CAI Content Credentials, and ColdFusion. The vulnerabilities, disclosed within a one-hour window, range in severity from Low to Critical, with several Critical and High-severity flaws carrying the potential for arbitrary code execution and privilege escalation. This coordinated disclosure event highlights a broad range of security weaknesses across Adobe's diverse product ecosystem.

Several critical vulnerabilities were identified in Adobe Campaign Classic (ACC). CVE-2026-71398 and CVE-2026-27302, both rated Critical with a CVSS score of 10.0, are Incorrect Authorization vulnerabilities that could lead to arbitrary code execution without user interaction. Additionally, CVE-2026-48381, a Critical SQL Injection vulnerability (CVSS 9.0), also allows for arbitrary code execution in ACC.

Adobe Commerce was impacted by a series of vulnerabilities, including Incorrect Authorization flaws like CVE-2026-71362 (Critical, CVSS 9.1), which could lead to privilege escalation. CVE-2026-48416 and CVE-2026-48415, both High severity, also involve Incorrect Authorization, potentially leading to security feature bypasses. Furthermore, two stored Cross-Site Scripting (XSS) vulnerabilities, CVE-2026-48414 and CVE-2026-48413, rated High, could allow attackers to inject malicious scripts. CVE-2026-48412, a Low severity Incorrect Authorization vulnerability, could result in privilege escalation for already high-privileged attackers.

Lightroom Classic users face High-severity risks from multiple vulnerabilities. CVE-2026-48441, a Path Traversal vulnerability (CVSS 8.6), could allow arbitrary file system reads. A cluster of eight High-severity Out-of-Bounds Write vulnerabilities (CVE-2026-48411 and CVE-2026-48404 through CVE-2026-48410, all CVSS 7.8) could lead to arbitrary code execution with user interaction. Another High-severity vulnerability, CVE-2026-48397 (CVSS 8.6), is a Deserialization of Untrusted Data flaw, also potentially leading to arbitrary code execution with user interaction. CVE-2026-47940, an Integer Overflow or Wraparound vulnerability (CVSS 7.8), also poses an arbitrary code execution risk requiring user interaction. CVE-2026-48447, a High severity Incorrect Authorization vulnerability (CVSS 7.7), could also lead to arbitrary code execution.

ColdFusion is affected by CVE-2026-71387 and CVE-2026-71386, both High severity (CVSS 8.8). CVE-2026-71387 is an Incorrect Authorization vulnerability, while CVE-2026-71386 is a Cross-Site Scripting (XSS) vulnerability. Both could lead to arbitrary code execution, though exploitation is restricted to an administrative network zone by default.

The CAI Content Credentials component within Adobe's C2pa Web product saw 15 vulnerabilities disclosed, including Medium-severity Improper Input Validation (CVE-2026-71390, CVSS 4.0) leading to security feature bypass, and an Integer Underflow vulnerability (CVE-2026-71389, CVSS 6.2) that could cause a denial-of-service.

Following the disclosure, CVE-2026-71362, a critical Adobe Commerce vulnerability, was reportedly targeted by hackers immediately after its public release, according to webstore security firm Sansec. This exploitation occurred despite Adobe's statement of no evidence of in-the-wild exploitation prior to patching.

Adobe has released security updates to address these vulnerabilities. Users are strongly urged to apply these patches promptly to mitigate the risks associated with these critical flaws across their Adobe products. The coordinated nature of this disclosure emphasizes the importance of timely patching and security vigilance for users of Adobe software.

CVE-2026-71398, CVE-2026-71362, CVE-2026-48447, CVE-2026-48441, CVE-2026-48416, CVE-2026-48415, CVE-2026-48414, CVE-2026-48413, CVE-2026-48412, CVE-2026-48411, CVE-2026-48410, CVE-2026-48409, CVE-2026-48408, CVE-2026-48407, CVE-2026-48406, CVE-2026-48405, CVE-2026-48404, CVE-2026-48397, CVE-2026-48381, CVE-2026-47940, CVE-2026-27302, CVE-2026-71390, CVE-2026-71389, CVE-2026-71387, CVE-2026-71386

AI-written article. Grounded in 25 CVE records listed below.