Adobe, ownCloud, and GiveWP Vulnerabilities Demand Urgent Action
Adobe faces critical vulnerabilities, CISA adds ownCloud flaw to KEV, and GiveWP plugin RCE demands urgent patching.

Adobe is urging immediate patching for critical vulnerabilities across its ColdFusion and Campaign Classic products. CVE-2026-48282, a path traversal flaw in ColdFusion, carries a CVSS score of 10.0 and allows for arbitrary code execution. Similarly, multiple critical OS command injection and SSRF vulnerabilities in Adobe Campaign Classic, including CVE-2026-76197, CVE-2026-76195, and CVE-2026-76193, also permit unauthenticated remote code execution. These flaws are particularly concerning due to their high severity and potential for widespread impact. Adobe has released patches for these issues, and users are strongly advised to apply them without delay. The Hacker News and SecurityWeek provide further details.
CISA has added CVE-2023-49105, an authentication bypass vulnerability in ownCloud, to its Known Exploited Vulnerabilities (KEV) catalog. This critical flaw allows unauthenticated attackers to access, modify, or delete any file if they know a victim's username and the victim lacks a signing-key configuration. Reports indicate that this vulnerability has already been exploited to steal sensitive data, including nuclear records and naval data from the Philippines. Users of ownCloud are urged to update to version 10.13.1 or later immediately to mitigate this risk. The Hacker News and Cyber Security News have more on this developing story.
A critical deserialization vulnerability in the GiveWP WordPress plugin, tracked as CVE-2026-82222, enables unauthenticated object injection leading to remote code execution. Affecting versions up to 4.16.7.1, this flaw poses a significant risk to WordPress sites utilizing the plugin. While the specific exploitability and prevalence are still being assessed, the critical nature of RCE vulnerabilities warrants immediate attention. Users should update to the latest version of GiveWP to patch this vulnerability. Patchstack Blog offers a technical breakdown.
Adobe Acrobat Reader is facing a critical Prototype Pollution vulnerability, CVE-2026-34621, which could lead to arbitrary code execution. This flaw affects versions up to 24.001.30356 and 26.001.21367. While not yet on the KEV catalog, its critical CVSS score and potential for code execution make it a high-priority target for attackers. Adobe has released patches for this vulnerability, and users should update their Acrobat Reader installations promptly. BleepingComputer and Krebs on Security provide additional context.