logo

Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution

ID: 21fb2bbc-3b6c-5f79-966d-6d5787b3f2e0

STIX ID: report--21fb2bbc-3b6c-5f79-966d-6d5787b3f2e0

Feed Name: CISecurity.org Advisories

Threat Score
70/100

Date Published: 2025-04-08

Date Updated: 2026-04-27

...
...

Multiple vulnerabilities were disclosed across a broad set of Adobe products (Adobe Commerce, Experience Manager Forms, ColdFusion, After Effects, Media Encoder, Bridge, Premiere Pro, Photoshop, Animate, FrameMaker, XMP Toolkit SDK, and others), including critical issues that could result in arbitrary code execution (heap-based buffer overflows, out-of-bounds read/write, deserialization of untrusted data, OS command injection, path traversal, and XSS). The advisory lists specific CVE identifiers for each issue and warns that successful exploitation could allow an attacker to execute code as the logged-on user, install programs, or view/change/delete data; no indicators of active exploitation are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.