Back to Feed
VulnerabilitiesSep 23, 2026

Adobe Patches Critical Flaws in Connect, AEM Forms

Adobe patches 36 vulnerabilities, including critical flaws in Connect and AEM Forms.

Summary

Adobe has released patches for 36 vulnerabilities across its product suite, with a significant focus on critical flaws in Adobe Connect and Experience Manager (AEM) Forms. These critical vulnerabilities could allow for arbitrary code execution and privilege escalation. While Adobe is not aware of any active exploitation in the wild, users are advised to apply the patches promptly.

Full text

Adobe on Tuesday rolled out patches for 36 vulnerabilities across its products, including critical-severity flaws in Connect and Experience Manager (AEM) Forms. The Adobe Connect update resolves nine security defects, including six critical issues that could be exploited for arbitrary code execution and privilege escalation. Tracked as CVE-2026-75682, CVE-2026-75684, CVE-2026-75686, CVE-2026-75689, CVE-2026-75697, and CVE-2026-75698, they are described as SQL injection, cross-site scripting (XSS), and improper input validation flaws. The update also fixes high-severity path traversal, improper certificate validation, and XSS weaknesses that could lead to arbitrary file system read, security feature bypass, and arbitrary code execution. Adobe patched six vulnerabilities in AEM Forms, including three critical-severity flaws leading to code execution and privilege escalation. Described as incorrect authorization, improper input validation, and server-side request forgery (SSRF), the critical issues are tracked as CVE-2026-75745, CVE-2026-81995, and CVE-2026-82000.Advertisement. Scroll to continue reading. The AEM Forms patches also fix three high-severity SSRF, XSS, and cross-site request forgery (CSRF) bugs leading to privilege escalation, code execution, and security feature bypass. Both security updates have a priority 2 rating, meaning that users should apply them within the next 30 days. On Tuesday, Adobe also announced fixes for multiple high- and medium-severity vulnerabilities in InDesign, Content Credentials SDK, Bridge, Substance 3D Modeler, and Premiere Pro. Successful exploitation of these security defects could lead to application denial-of-service (DoS), security feature bypass, arbitrary code execution, and memory exposure. Adobe says it is not aware of any of these security flaws being exploited in the wild. Additional information is available on the company’s security bulletins page. Related: Chrome 154 Patches 108 Vulnerabilities Related: Arista Urges Immediate Patching of Exploited VCO Zero-Day Related: Chrome, Firefox Updates Patch 115 Vulnerabilities Related: Check Point, Kaspersky, Tanium Patch Product Vulnerabilities Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire BigCommerce Data Stolen via Ribon Apps HackRecent ZyXEL Switch Vulnerability Exploited by Chinese HackersMalicious B-tree NPM Package Accumulates Millions of DownloadsWordPress Patches ‘Click2Shell’ VulnerabilityFake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ StealerRatHat Android Trojan Uses AI for AutomationCrowdSec Confirms Source Code Stolen in Supply Chain AttackOrganizations Warned of 3 Exploited Linux Kernel Vulnerabilities Latest News AI-Powered Phishing Platform EvilTokens Disrupted by MicrosoftChrome 154 Patches 108 VulnerabilitiesA Look at AI Doomsday Scenarios That Researchers Say Could Put Humanity at RiskOuterlimit Raises $16 Million to Stop Rogue AI Agents From Causing HarmArista Urges Immediate Patching of Exploited VCO Zero-DayCritical F5 BIG-IP Vulnerability Exploited as Zero-DayShinyHunters Claims FBI Hack, Demands Retraction of Threat ReportCheck Point Patches Exploited Management Server Zero-Day Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Building Continuous Authorization at Scale September 23, 2026 Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required. Register People on the MoveGwen Gann has become State Chief Information Security Officer for the State of Washington at WaTech.Pietr Lindahal has been named Vice President and Chief Information Security Officer at Boston Scientific.AI agent identity and enforcement company FIOR has appointed Gemma Ungoed-Thomas as Adviser.More People On The MoveExpert Insights “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Flipboard Reddit Whatsapp Whatsapp Email

Indicators of Compromise

  • cve — CVE-2026-75682
  • cve — CVE-2026-75684
  • cve — CVE-2026-75686
  • cve — CVE-2026-75689
  • cve — CVE-2026-75697
  • cve — CVE-2026-75698
  • cve — CVE-2026-75745
  • cve — CVE-2026-81995
  • cve — CVE-2026-82000

Entities

Adobe Connect (product)Adobe Experience Manager (AEM) Forms (product)Adobe (vendor)InDesign (product)Content Credentials SDK (product)Bridge (product)