Adobe security advisory (AV26-953)
Canada's cyber centre warned of vulnerabilities in AEM, Connect, Bridge, and other Adobe products.
On September 23, 2026, the Canadian Centre for Cyber Security issued advisory AV26-953 on Adobe vulnerabilities disclosed as of September 22. Affected products include AEM 6.5 Forms JEE through 6.5.25, AEM 6.5 LTS Forms through SP2, Bridge, Connect and its Android app, C2PA tooling, InDesign, Premiere, and Substance 3D Modeler. The bulletin lists vulnerable version ceilings but does not name CVE identifiers or report active exploitation.
- Canadian advisory AV26-953 was published on September 23, 2026.
- Affected lines include AEM Forms, Connect, Bridge, InDesign, and Premiere.
- C2PA Tool and the Content Credentials Rust SDK are included.
- The bulletin names no CVE identifiers and reports no exploitation.
Full article138 words · extracted from cyber.gc.ca · click to collapse
Serial number: AV26-953
Date: September 23, 2026
As of September 22, 2026, Adobe is affected by vulnerabilities in the following products:
- AEM 6.5 Forms JEE
- Prior to or equal to 6.5.25
- AEM 6.5 LTS Forms JEE
- Prior to or equal to 6.5 LTS SP2
- Adobe Bridge
- Prior to or equal to 15.1.7 (LTS)
- Prior to or equal to 16.0.6
- Adobe Connect
- Prior to or equal to 12.11
- Adobe Connect Android Mobile App
- Prior to or equal to 4.4
- C2PA Tool
- Prior to or equal to c2patool-v0.26.70
- Content Credentials Rust SDK
- Prior to or equal to c2pa-v0.89.2
- InDesign Desktop
- Prior to or equal to ID20.5.4
- Prior to or equal to ID21.5
- Premiere
- Prior to or equal to 25.6.5
- Prior to or equal to 26.3.2
- Substance3D - Modeler
- Prior to or equal to 1.22.6
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/adobe-security-advisory-av26-953