Adobe Fixes Critical Vulnerabilities in Connect and AEM Forms

www.news4hackers.com-adobe-fixes-critical-vulnerabilities-in-connect-and-aem-forms-adobe-fixes-critical-vulnerabilities-in-connect-and-aem-forms

Adobe released updates on Tuesday to address 36 security issues across its product suite, including critical vulnerabilities in Adobe Connect and Experience Manager (AEM) Forms.

Adobe Connect and AEM Forms Updates

The Adobe Connect patch resolves nine flaws, six of which are classified as critical and could enable arbitrary code execution and privilege escalation. These vulnerabilities, assigned identifiers such as CVE-2026-75682, CVE-2026-75684, CVE-2026-75686, CVE-2026-75689, CVE-2026-75697, and CVE-2026-75698, involve SQL injection, cross-site scripting (XSS), and improper input validation. Additional fixes include high-severity flaws related to path traversal, improper certificate validation, and XSS vulnerabilities, which could result in unauthorized file system access, security bypasses, and code execution.

Critical Vulnerabilities in Adobe Connect

The AEM Forms update addresses six vulnerabilities, three of which are critical and pose risks of code execution and privilege escalation. These issues, tracked as CVE-2026-75745, CVE-2026-81995, and CVE-2026-82000, stem from incorrect authorization configurations, flawed input validation, and server-side request forgery (SSRF) weaknesses. The patch also resolves three high-severity vulnerabilities involving SSRF, XSS, and cross-site request forgery (CSRF), which could lead to privilege escalation, code execution, and security feature bypasses.

Critical Vulnerabilities in AEM Forms

Both updates carry a priority 2 rating, indicating that users should implement the fixes within 30 days.

Additional Vulnerabilities in Other Adobe Products

In addition to the Connect and AEM Forms updates, Adobe addressed multiple high- and medium-severity vulnerabilities in products such as InDesign, Content Credentials SDK, Bridge, Substance 3D Modeler, and Premiere Pro. Exploitation of these flaws could result in application denial-of-service (DoS) attacks, security feature bypasses, arbitrary code execution, and memory exposure. The company has not identified any of these vulnerabilities being actively exploited in real-world scenarios. Further details are available in Adobe’s security bulletins.

Conclusion and Recommendations

The updates follow a broader trend of software vendors addressing critical flaws in widely used tools. Organizations are advised to prioritize patching to mitigate risks associated with the identified vulnerabilities. No evidence of malicious activity linked to these issues has been reported to date.



About Author

en_USEnglish