Adobe Patches Critical Flaws in Connect and AEM Forms
Share
Adobe has released security updates to address 36 vulnerabilities across its software suite, including critical-severity flaws in Adobe Connect and Adobe Experience Manager (AEM) Forms.
The updates for Adobe Connect resolve nine security defects, six of which are classified as critical. These vulnerabilities could allow attackers to perform arbitrary code execution (ACE) or achieve privilege escalation. The defects include SQL injection, cross-site scripting (XSS), and improper input validation flaws.
Specific critical vulnerabilities in Adobe Connect include CVE-2026-75682, CVE-2026-75684, CVE-2026-75686, CVE-2026-75689, CVE-2026-75697, and CVE-2026-75698. High-severity issues such as path traversal and improper certificate validation were also addressed, which could lead to arbitrary file system reads and security feature bypasses.
Vulnerabilities in AEM Forms and Creative Cloud
Adobe also patched six vulnerabilities in AEM Forms, including three critical-severity flaws. These issues, tracked as CVE-2026-75745, CVE-2026-81995, and CVE-2026-82000, involve incorrect authorisation, improper input validation, and server-side request forgery (SSRF). These could result in unauthorised code execution and privilege escalation.
Additional high-severity bugs in AEM Forms include SSRF, XSS, and cross-site request forgery (CSRF) weaknesses. Beyond the enterprise products, Adobe released fixes for various high- and medium-severity vulnerabilities in InDesign, Content Credentials SDK, Bridge, Substance 3D Modeler, and Premiere Pro. These flaws could potentially lead to application denial-of-service (DoS), memory exposure, and security feature bypasses.
Adobe stated it is currently unaware of any instances where these security defects have been exploited in the wild. The company has assigned a priority 2 rating to these updates, advising users to apply the patches within 30 days.




Leave a Reply