Adobe PSIRT — Security Bulletins
adobe-psirt · A · candidate
https://helpx.adobe.com/security/security-bulletin.html
Added 2026-08-07 to close a measured discovery-latency gap: Adobe has produced three separate waves of critical unauthenticated code-execution-class flaws in the Campaign/ColdFusion line since early July 2026 (APSB26-68/69, APSB26-114, APSB26-120), and this pipeline has been finding each one via NCSC-NL or CERT-FR relay rather than from the vendor. APSB26-120 published 2026-08-03 and reached this pipeline on 2026-08-07 through an NCSC-NL advisory dated 08-06. FETCH (probed 2026-08-07): https://helpx.adobe.com/security.html returns the 4 NEWEST bulletins with dates and is the right recency entry point; https://helpx.adobe.com/security/security-bulletin.html returns the full historical index (814 APSB ids in one fetch) and is the right target for a backfill or a specific-id lookup. Per-bulletin pages (helpx.adobe.com/security/products/<product>/<apsb-id>.html) carry an explicit per-CVE table of CWE / impact / severity / CVSS base score / CVSS vector, so CVE-to-score mapping is transcribable without positional guessing — prefer it over NVD, whose description text for CVE-2026-48331 characterises the impact as privilege escalation where Adobe's own table records arbitrary code execution.
Cited in 5 entries
Citation cadence
Citation days per ISO week (6 weeks of coverage span, total 4).
- Adobe Campaign Classic APSB26-120 — three more unauthenticated CVSS 10.0 code-execution flaws, and last week's build 9398 is the version they affect2026-08-07
- CVE-2026-48449 — Adobe Campaign Classic: an authorization flaw gives unauthenticated arbitrary code execution (CVSS 10.0), on-premise and hybrid deployments only2026-08-02
- Vulnerability status roll-up — 2026-W27: what moved, what to patch on the exploited-flaw clock vs the monthly cycle2026-07-05
- Looking ahead — 2026-W272026-07-05
- CVE-2026-48276, -48277, -48281, -48282, -48283, -48316 — Adobe ColdFusion: six CVSS 10.0 unauthenticated RCE paths2026-07-02