Adobe has released updates addressing 36 security vulnerabilities across several of its products, with critical concerns identified in Adobe Connect and Experience Manager (AEM) Forms.
Details of Adobe Connect Vulnerabilities
The recent Adobe Connect update tackles nine security issues, six of which hold critical severity. These can be exploited for arbitrary code execution and privilege escalation. The vulnerabilities, tracked as CVE-2026-75682 through CVE-2026-75698, include flaws such as SQL injection, cross-site scripting (XSS), and improper input validation.
Additional high-severity issues addressed involve path traversal, improper certificate validation, and further XSS vulnerabilities. These could potentially lead to unauthorized file system access, security feature bypasses, and arbitrary code execution.
Critical Flaws in AEM Forms
In parallel, Adobe has patched six vulnerabilities in AEM Forms, with three marked as critical. These critical vulnerabilities, identified as CVE-2026-75745, CVE-2026-81995, and CVE-2026-82000, could result in code execution and privilege escalation due to incorrect authorization, improper input validation, and server-side request forgery (SSRF).
The updates also mitigate three high-severity issues, including SSRF, XSS, and cross-site request forgery (CSRF), which can lead to privilege escalation and security feature bypass.
Additional Security Updates
Adobe has assigned a priority 2 rating to both updates, urging users to apply these patches within 30 days. Beyond Connect and AEM Forms, Adobe has also rectified multiple high- and medium-severity vulnerabilities in products like InDesign, Content Credentials SDK, Bridge, Substance 3D Modeler, and Premiere Pro.
These security flaws, if exploited, could cause denial-of-service (DoS) attacks, security feature bypasses, arbitrary code execution, and memory exposure. Fortunately, Adobe reports no known exploitation of these vulnerabilities in the wild yet.
Conclusion and Recommendations
It is essential for users to apply these updates promptly to safeguard against potential threats. Further information on these security updates can be found on Adobe’s security bulletins page. Staying updated on the latest patches is crucial in maintaining software security and protecting against cyber threats.
