Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
widely-deployed-product-advisoryendpoint-software-vulnerabilityinternet-facing-service-vulnerabilityidentity-authentication-vulnerability

Adobe fixes critical flaws across Acrobat, ColdFusion, Experience Manager, and Campaign

Updated 11d agoFirst seen Jun 9, 202627 sources

Adobe released a broad set of security updates covering Adobe Experience Manager, Acrobat/Reader, ColdFusion, Dreamweaver, InDesign, InCopy, Substance 3D Sampler, Format Plugins, Campaign Classic, and Content Credentials SDK components, prompting alerts from national and regional CERTs including Canada’s Cyber Centre and HKCERT. The advisories span multiple high-severity issues, with affected versions including ColdFusion 2023.19 and 2025.8 and earlier, Dreamweaver 21.7 and earlier, Campaign Classic 7.4.3 build 9394 and earlier, and AEM Forms JEE LTS SP1 / 6.5.24.0 and earlier.

The most serious disclosures include multiple remote code execution bugs in Acrobat/Reader such as CVE-2026-47911, CVE-2026-47912, CVE-2026-47913, CVE-2026-47914, CVE-2026-47915, CVE-2026-47918, and CVE-2026-47919, largely tied to use-after-free conditions and malicious file handling; several ColdFusion flaws including CVE-2026-47928, CVE-2026-47929, CVE-2026-47930, CVE-2026-47931, and CVE-2026-47932 that can enable code execution, security feature bypass, or unauthorized read/write access; AEM Forms JEE stored and reflected XSS issues CVE-2026-34691 and CVE-2026-34693; Campaign Classic issues CVE-2026-47938 and CVE-2026-48303 involving SSRF, privilege escalation, and possible code execution; Dreamweaver arbitrary file read via CVE-2026-47907; and USD Fileformat Plugins heap-based buffer overflows CVE-2026-48291 and CVE-2026-48292. Adobe has issued patches for the affected products, and defenders are being urged to review the vendor bulletins and deploy updates quickly.

Share:
Adobe fixes critical flaws across Acrobat, ColdFusion, Experience Manager, and Campaign
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

15 events from the most recent confirmed update back to the earliest known activity.

15 EVENTS
Jun 9, 202614d ago

Adobe revises Campaign Classic CVE-2026-47938 impact

Adobe modified the CVE-2026-47938 description on this date to change the stated impact from arbitrary code execution to privilege escalation. The CVE remained associated with an SSRF flaw in Adobe Campaign Classic.

CVE-2026-47938 - Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918)

Adobe discloses Campaign Classic vulnerabilities

Adobe disclosed CVE-2026-47938 and CVE-2026-48303 affecting Adobe Campaign Classic 7.4.3 build 9394 and earlier. The issues included SSRF and incorrect authorization flaws with severe impact and no user interaction required.

CVE-2026-47938 - Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918)

Adobe discloses and patches USD-Fileformat-plugins RCE flaws

Adobe publicly disclosed CVE-2026-48291 and CVE-2026-48292 affecting Adobe USD-Fileformat-plugins and issued updates to remediate them. Both heap-based buffer overflow flaws were in the usdGltf plugin and could lead to arbitrary code execution.

ZDI-26-350 | Zero Day Initiative

Adobe updates Acrobat and Reader for coordinated vulnerability release

Adobe released updates and publicly disclosed multiple Acrobat and Reader vulnerabilities in a coordinated release, including CVE-2026-47911 through CVE-2026-47915, CVE-2026-47918, CVE-2026-47919, CVE-2026-47923, and CVE-2026-47924. The issues included remote code execution and information disclosure flaws documented by ZDI advisories.

ZDI-26-347 | Zero Day Initiative

Adobe discloses Dreamweaver arbitrary file read flaw

Adobe disclosed CVE-2026-47907 affecting Dreamweaver Desktop 21.7 and earlier. The improper access control issue could allow arbitrary file system read if a victim opens a malicious file.

CVE-2026-47907 - Dreamweaver Desktop | Improper Access Control (CWE-284)

Adobe discloses multiple ColdFusion vulnerabilities

Adobe disclosed several ColdFusion flaws on this date, including CVE-2026-47928, CVE-2026-47929, CVE-2026-47930, CVE-2026-47931, and CVE-2026-47932. The issues affected ColdFusion 2023.19, 2025.8, and earlier, with impacts including code execution, security feature bypass, incorrect authorization, and path traversal.

CVE-2026-47928 - ColdFusion | Improper Input Validation (CWE-20)

Adobe discloses AEM Forms JEE XSS vulnerabilities

Adobe disclosed CVE-2026-34691 and CVE-2026-34693 affecting Adobe Experience Manager Forms JEE, covering stored and reflected cross-site scripting issues. The flaws affected LTS SP1, version 6.5.24.0, and earlier releases.

CVE-2026-34691 - Adobe Experience Manager Forms JEE | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe publishes broad June 2026 security advisories

Adobe published security advisories addressing critical vulnerabilities across products including Experience Manager, InDesign, InCopy, Substance 3D Sampler, Dreamweaver, Acrobat, Reader, ColdFusion, Format Plugins, Campaign Classic, and Content Credentials SDK components. The Canadian Centre for Cyber Security urged administrators and users to review the advisories and apply updates.

Adobe security advisory (AV26-570) - Canadian Centre for Cyber Security
Apr 30, 20262mo ago

Additional Acrobat Reader flaws reported to Adobe

Two Acrobat Reader DC vulnerabilities later tracked as CVE-2026-47918 and CVE-2026-47919 were reported to Adobe on this date. Both were use-after-free issues involving Annotation object handling that could lead to remote code execution.

ZDI-26-354 | Zero Day Initiative
Apr 10, 20262mo ago

ZeroPath documents Acrobat Reader CVE-2026-34621 RCE flaw

A ZeroPath report described CVE-2026-34621 as a prototype pollution vulnerability in Adobe Acrobat Reader that can lead to arbitrary code execution when a user opens a crafted PDF. The report cited Adobe advisory APSB26-43 as the remediation reference and said affected versions included 24.001.30356 and earlier and 26.001.21367 and earlier.

Brief Summary: CVE-2026-34621 Prototype Pollution in Adobe Acrobat Reader Leading to Arbitrary Code Execution - ZeroPath Blog | ZeroPath
Apr 9, 20263mo ago

Adobe USD-Fileformat-plugins flaw reported to Adobe

The heap-based buffer overflow later tracked as CVE-2026-48292 and ZDI-26-351 was reported to Adobe on this date. The issue affected the usdGltf plugin and could enable arbitrary code execution.

ZDI-26-351 | Zero Day Initiative
Apr 2, 20263mo ago

Adobe Acrobat Pro DC flaw reported to Adobe

The vulnerability later tracked as CVE-2026-47915 and ZDI-26-349 was reported to Adobe on this date. The bug was a use-after-free issue in Annots.api that could lead to remote code execution.

ZDI-26-349 | Zero Day Initiative
Mar 30, 20263mo ago

Multiple Acrobat Reader flaws reported to Adobe

Several vulnerabilities later tracked as CVE-2026-47911, CVE-2026-47912, CVE-2026-47913, CVE-2026-47914, CVE-2026-47923, and CVE-2026-47924 were reported to Adobe on this date, according to ZDI disclosure timelines. These issues affected Adobe Acrobat Reader DC and included remote code execution and information disclosure flaws.

ZDI-26-347 | Zero Day Initiative
Feb 3, 20265mo ago

Adobe Acrobat Reader CVE-2026-27220 reported to Adobe

The use-after-free vulnerability later tracked as CVE-2026-27220 and ZDI-26-355 was reported to Adobe on this date. The flaw affected Adobe Acrobat Reader DC's Annotation object handling and could allow remote code execution if a user opened a malicious file or visited a malicious page.

ZDI-26-355 | Zero Day Initiative
Sep 9, 202510mo ago

ZeroPath documents Acrobat Reader CVE-2025-54257 use-after-free flaw

A ZeroPath report described CVE-2025-54257 as a use-after-free vulnerability in Adobe Acrobat Reader that can enable arbitrary code execution when a user opens a specially crafted malicious PDF. The report said the flaw affects vulnerable Reader versions on Windows and macOS and noted that no public exploit code or detailed exploit chain had been released as of publication.

Adobe Acrobat Reader CVE-2025-54257 Use After Free Vulnerability: Brief Summary and Technical Review - ZeroPath Blog | ZeroPath
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

34 LINKEDOpen in app
Affected products
6 linked
Adobe Acrobat ReaderAcrobat Reader DcColdfusionAdobe Experience ManagerAdobe ReaderDreamweaver Desktop
Organizations
4 linked
AdobeVirustotalSecurityWeekAmpcus Cyber
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.