Adobe PSIRT, Security Bulletins
adobe-psirt · A · active
https://helpx.adobe.com/security/security-bulletin.html
Added 2026-08-07 to close a measured discovery-latency gap: Adobe has produced three separate waves of critical unauthenticated code-execution-class flaws in the Campaign/ColdFusion line since early July 2026 (APSB26-68/69, APSB26-114, APSB26-120), and this pipeline has been finding each one via NCSC-NL or CERT-FR relay rather than from the vendor. APSB26-120 published 2026-08-03 and reached this pipeline on 2026-08-07 through an NCSC-NL advisory dated 08-06. FETCH (probed 2026-08-07): https://helpx.adobe.com/security.html returns the 4 NEWEST bulletins with dates and is the right recency entry point; https://helpx.adobe.com/security/security-bulletin.html returns the full historical index (814 APSB ids in one fetch) and is the right target for a backfill or a specific-id lookup. Per-bulletin pages (helpx.adobe.com/security/products/<product>/<apsb-id>.html) carry an explicit per-CVE table of CWE / impact / severity / CVSS base score / CVSS vector, so CVE-to-score mapping is transcribable without positional guessing, prefer it over NVD, whose description text for CVE-2026-48331 characterises the impact as privilege escalation where Adobe's own table records arbitrary code execution. | 2026-08-08: promoted candidate -> active. The state digest counted 4 distinct contributing runs, past the 3-run promotion bar. | 2026-08-15: recipe repaired, health probe reported it unreachable on webfetch, but the bridge's url subcommand returned the full bulletin index this run; fetch_method switched webfetch -> bridge.
Cited in 6 entries
Citation cadence
Citation days per ISO week (11 weeks of coverage span, total 6).
- CVE-2026-75650 ("StyleSmuggler"), Magento/Adobe Commerce: unauthenticated CVSS 10.0 RCE via template-engine injection, exploited three days before Adobe's hotfix existed2026-09-08
- Adobe August 2026 Patch Day: ColdFusion ships a CVSS 10.0 unauthenticated OS command injection, and Campaign Classic ships two more unauthenticated CVSS 10.0 flaws in the same release2026-08-28
- CVE-2026-71362, Adobe Commerce and Magento Open Source: an unauthenticated attacker switches a customer session to another customer's account (CVSS 9.1), and a WAF vendor reports it is already blocking attempts2026-08-16
- Adobe Campaign Classic APSB26-120, three more unauthenticated CVSS 10.0 code-execution flaws, and last week's build 9398 is the version they affect2026-08-07
- CVE-2026-48449, Adobe Campaign Classic: an authorization flaw gives unauthenticated arbitrary code execution (CVSS 10.0), on-premise and hybrid deployments only2026-08-02
- CVE-2026-48276, -48277, -48281, -48282, -48283, -48316, Adobe ColdFusion: six CVSS 10.0 unauthenticated RCE paths2026-07-02