CTIPilot

Adobe PSIRT, Security Bulletins

adobe-psirt · A · active

https://helpx.adobe.com/security/security-bulletin.html

vulnsvendor-psirtlang: enfetch failures: 0quiet periods: 2last fetch: 2026-09-14

Added 2026-08-07 to close a measured discovery-latency gap: Adobe has produced three separate waves of critical unauthenticated code-execution-class flaws in the Campaign/ColdFusion line since early July 2026 (APSB26-68/69, APSB26-114, APSB26-120), and this pipeline has been finding each one via NCSC-NL or CERT-FR relay rather than from the vendor. APSB26-120 published 2026-08-03 and reached this pipeline on 2026-08-07 through an NCSC-NL advisory dated 08-06. FETCH (probed 2026-08-07): https://helpx.adobe.com/security.html returns the 4 NEWEST bulletins with dates and is the right recency entry point; https://helpx.adobe.com/security/security-bulletin.html returns the full historical index (814 APSB ids in one fetch) and is the right target for a backfill or a specific-id lookup. Per-bulletin pages (helpx.adobe.com/security/products/<product>/<apsb-id>.html) carry an explicit per-CVE table of CWE / impact / severity / CVSS base score / CVSS vector, so CVE-to-score mapping is transcribable without positional guessing, prefer it over NVD, whose description text for CVE-2026-48331 characterises the impact as privilege escalation where Adobe's own table records arbitrary code execution. | 2026-08-08: promoted candidate -> active. The state digest counted 4 distinct contributing runs, past the 3-run promotion bar. | 2026-08-15: recipe repaired, health probe reported it unreachable on webfetch, but the bridge's url subcommand returned the full bulletin index this run; fetch_method switched webfetch -> bridge.

Cited in 6 entries

Citation cadence

Citation days per ISO week (11 weeks of coverage span, total 6).