Adobe Patches Critical Flaws in Connect, AEM Forms
Adobe patched 36 vulnerabilities, including critical code-execution SQL injection, XSS, and SSRF flaws in Connect and Experience Manager Forms; no known exploitation.
Adobe released patches for 36 vulnerabilities, with critical flaws in Adobe Connect and Experience Manager (AEM) Forms. The Connect update fixes nine bugs, six of them critical (SQL injection, XSS, improper input validation) enabling arbitrary code execution and privilege escalation. AEM Forms gets six fixes including three critical issues (incorrect authorization, improper input validation, SSRF) leading to code execution and privilege escalation. Both bulletins carry priority 2 rating (patch within 30 days); Adobe is not aware of in-the-wild exploitation.
- Adobe Connect: 9 fixes, 6 critical, enabling code execution and privilege escalation.
- AEM Forms: 6 fixes, 3 critical SSRF/authorization/input validation issues.
- Both updates rated priority 2, meaning apply within 30 days.
- No exploitation in the wild reported by Adobe.
Vulnerabilities mentionedAll →
- CVE-2026-756829.9—Authenticated SQL Injection Leading to Code Execution in Adobe Connectpublished · Adobe Connect+5 related
- CVE-2026-7574510.0—Unauthenticated RCE via Broken Authorization in Adobe Experience Manager Forms JEEpublished · Adobe Experience Manager Forms (JEE deployment)+1 related
Full article288 words · extracted from securityweek.com · click to collapse
Adobe on Tuesday rolled out patches for 36 vulnerabilities across its products, including critical-severity flaws in Connect and Experience Manager (AEM) Forms.
The Adobe Connect update resolves nine security defects, including six critical issues that could be exploited for arbitrary code execution and privilege escalation.
Tracked as CVE-2026-75682, CVE-2026-75684, CVE-2026-75686, CVE-2026-75689, CVE-2026-75697, and CVE-2026-75698, they are described as SQL injection, cross-site scripting (XSS), and improper input validation flaws.
The update also fixes high-severity path traversal, improper certificate validation, and XSS weaknesses that could lead to arbitrary file system read, security feature bypass, and arbitrary code execution.
Adobe patched six vulnerabilities in AEM Forms, including three critical-severity flaws leading to code execution and privilege escalation.
Described as incorrect authorization, improper input validation, and server-side request forgery (SSRF), the critical issues are tracked as CVE-2026-75745, CVE-2026-81995, and CVE-2026-82000.
Advertisement. Scroll to continue reading.
The AEM Forms patches also fix three high-severity SSRF, XSS, and cross-site request forgery (CSRF) bugs leading to privilege escalation, code execution, and security feature bypass.
Both security updates have a priority 2 rating, meaning that users should apply them within the next 30 days.
On Tuesday, Adobe also announced fixes for multiple high- and medium-severity vulnerabilities in InDesign, Content Credentials SDK, Bridge, Substance 3D Modeler, and Premiere Pro.
Successful exploitation of these security defects could lead to application denial-of-service (DoS), security feature bypass, arbitrary code execution, and memory exposure.
Adobe says it is not aware of any of these security flaws being exploited in the wild. Additional information is available on the company’s security bulletins page.
Related: Chrome 154 Patches 108 Vulnerabilities
Related: Arista Urges Immediate Patching of Exploited VCO Zero-Day
Related: Chrome, Firefox Updates Patch 115 Vulnerabilities
Related: Check Point, Kaspersky, Tanium Patch Product Vulnerabilities