VENDOR

Adobe vulnerabilities: CVEs, exploitation and patches

Every Adobe CVE reviewed by Diras Labs analysts, newest first, with exploitation status and fixes.

  1. CVE-2026-48356
    Adobe Commerce unrestricted file upload leading to remote code execution Adobe Adobe Commerce ·
    • PoC PUBLIC
    CRITICAL 9.3
  2. CVE-2026-48282
    ColdFusion path traversal pre-auth remote code execution Adobe ColdFusion ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    CRITICAL 10
  3. CVE-2026-71362
    Adobe Commerce and Magento incorrect authorization pre-auth privilege escalation Adobe Commerce and Magento ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    CRITICAL 9.1
  4. CVE-2026-75650
    Adobe Commerce and Magento remote code execution via template engine Adobe Commerce and Magento ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    CRITICAL 10
4 CVEs · page 1 of 1