VYPR
Vypr IntelligenceAI-generatedAug 27, 2026· 26 CVEs

Adobe Inc.: 25 Vulnerabilities Disclosed Across Multiple Products, Including Critical Flaws

Adobe Inc. disclosed 25 vulnerabilities across its product suite from Aug 25-27, 2026, including critical code execution flaws in Campaign Classic and numerous memory corruption bugs.

Key findings

  • 25 Adobe vulnerabilities disclosed Aug 25-27, 2026, spanning multiple products.
  • Critical OS Command Injection flaws in Adobe Campaign Classic (CVE-2026-76197, CVE-2026-76195, CVE-2026-76193).
  • Numerous High-severity buffer overflow and memory corruption bugs in Substance 3D suite.
  • Denial-of-service vulnerabilities in CAI Content Credentials, some exploitable without user interaction.
  • Risks include arbitrary code execution, memory exposure, and DoS across diverse Adobe applications.

On August 25 and 27, 2026, Adobe Inc. disclosed a significant batch of 25 vulnerabilities affecting various products, including Adobe Campaign Classic, Substance 3D applications, DNG SDK, CAI Content Credentials, Illustrator, and Adobe XD. The vulnerabilities, disclosed over a two-day period, range in severity from Medium to Critical, with several allowing for arbitrary code execution or denial-of-service conditions. This coordinated disclosure highlights potential risks across Adobe's diverse software ecosystem.

A cluster of three critical OS Command Injection vulnerabilities (CVE-2026-76197, CVE-2026-76195, CVE-2026-76193) were disclosed for Adobe Campaign Classic (ACC). These flaws, affecting version 7.4.4 build 9400 and earlier, could allow unauthenticated remote attackers to execute arbitrary code. Adobe released a Priority 1 security update for ACC, noting that while no exploitation in the wild was known, the severity and network-exposed attack conditions necessitate prompt patching.

The Substance 3D suite was also heavily impacted. Substance 3D Painter saw six vulnerabilities disclosed, including five High-severity Heap-based Buffer Overflow or out-of-bounds write/read flaws (CVE-2026-75750, CVE-2026-75749, CVE-2026-75769, CVE-2026-75768, CVE-2026-75767, CVE-2026-75766), and one High-severity Untrusted Search Path vulnerability (CVE-2026-75768), all potentially leading to arbitrary code execution. Substance 3D Sampler had two High-severity vulnerabilities: a Heap-based Buffer Overflow (CVE-2026-34674) and an out-of-bounds write (CVE-2026-71382), also capable of arbitrary code execution. Substance 3D Designer had two High-severity vulnerabilities: an out-of-bounds write (CVE-2026-71564) and a Heap-based Buffer Overflow (CVE-2026-48433). Additionally, CVE-2026-75752, a Medium-severity out-of-bounds read, affects Painter and could lead to memory disclosure.

Adobe CAI Content Credentials faced three disclosed vulnerabilities. Two are High-severity Integer Underflow (Wrap or Wraparound) flaws (CVE-2026-71442, CVE-2026-71444), and one is a High-severity Improper Input Validation vulnerability (CVE-2026-71443). These vulnerabilities do not require user interaction and can lead to application denial-of-service. Another Medium-severity Improper Input Validation vulnerability (CVE-2026-76198) in CAI Content Credentials could lead to arbitrary file system read, requiring user interaction. A Medium-severity Integer Underflow vulnerability (CVE-2026-7189) also affects CAI Content Credentials, leading to denial-of-service.

Other affected products include DNG SDK, which has two Medium-severity vulnerabilities: an out-of-bounds write (CVE-2026-34620) and an out-of-bounds read (CVE-2026-34616), both affecting versions 1.7.1 2502 and earlier and potentially leading to denial-of-service or memory exposure, respectively, requiring user interaction. Illustrator has a Medium-severity out-of-bounds read vulnerability (CVE-2026-71441) that could lead to memory disclosure. Adobe XD is affected by a High-severity Buffer Overflow vulnerability (CVE-2026-71399) that could result in arbitrary code execution.

The batch of vulnerabilities underscores the importance of timely patching across Adobe's product line. Users are advised to consult Adobe's security bulletins for specific version information and apply updates promptly to mitigate the risks of code execution and denial-of-service attacks.

The disclosures were made on August 25 and 27, 2026. The critical vulnerabilities in Adobe Campaign Classic were detailed in APSB26-134. The CAI Content Credentials vulnerabilities were highlighted as a group of DoS flaws that do not require user interaction.

Key vulnerabilities include:

  • Critical OS Command Injection flaws in Adobe Campaign Classic (CVE-2026-76197, CVE-2026-76195, CVE-2026-76193).
  • Multiple High-severity Heap-based Buffer Overflow and out-of-bounds write vulnerabilities in Substance 3D Painter and Sampler.
  • Denial-of-service vulnerabilities in CAI Content Credentials, some without user interaction requirements.
  • Memory exposure risks through out-of-bounds read vulnerabilities in DNG SDK and Illustrator.
  • Arbitrary code execution potential in Adobe XD via a buffer overflow.

All affected users should refer to Adobe's official security advisories for detailed information and apply the necessary patches to secure their systems. The broad range of affected products indicates a need for comprehensive security management for organizations utilizing Adobe software.

CVE-2026-34620, CVE-2026-34616, CVE-2026-34674, CVE-2026-76198, CVE-2026-76197, CVE-2026-76195, CVE-2026-76193, CVE-2026-76189, CVE-2026-75770, CVE-2026-75769, CVE-2026-75768, CVE-2026-75767, CVE-2026-75766, CVE-2026-75752, CVE-2026-75750, CVE-2026-75749, CVE-2026-71564, CVE-2026-71444, CVE-2026-71443, CVE-2026-71442, CVE-2026-71441, CVE-2026-71399, CVE-2026-71382, CVE-2026-71360, CVE-2026-48433.

AI-written article. Grounded in 26 CVE records listed below.