ZeroHour

Search: “Adobe Firefly”

19 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

ZDI-26-661: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability

ZDI discloses CVE-2026-81985, a second use-after-free in Adobe Acrobat Reader DC annotation handling enabling remote code execution with CVSS 7.8.

The Zero Day Initiative published ZDI-26-661 covering a use-after-free vulnerability in Adobe Acrobat Reader DC's annotation feature. Exploitation allows arbitrary code execution but requires user interaction, such as opening a malicious file or visiting a malicious page. ZDI rated the flaw CVSS 7.8 and assigned CVE-2026-81985.

Adobe is trying to make its AI generators idiot-proof in Premiere

Adobe adds in-timeline generative media to Premiere, letting editors generate video and audio clips using Firefly, Veo, Runway, Luma, and Kling models.

Adobe's new Generative Media tool lets Premiere editors highlight empty gaps in the timeline and generate context-aware, editable video, sound effects, music, and soundscapes without leaving the project. Editors can choose among underlying models including Adobe Firefly, Google Veo, Runway, Luma, and Kling. Beta AI audio tools can separate overlapping speakers and duck music under speech, and an AI Assistant is coming to After Effects for plain-language project commands.

The Verge · AI · 8d agoAI industry

Adobe security advisory (AV26-888)

Canada's Cyber Centre warns CVE-2026-75650 in Adobe Commerce and Magento Open Source is exploited in the wild; hotfixes and updates are available.

Canadian Centre for Cyber Security advisory AV26-888 (September 8, 2026) covers CVE-2026-75650 in Adobe Commerce, Adobe Commerce B2B and Magento Open Source. Adobe states the vulnerability is being exploited in the wild. Affected versions extend through the August 2026 patch levels across the 2.4.4-2.4.9 branches, with B2B versions 1.3.x-1.5.x also affected. Administrators are urged to apply the available hotfixes and updates.

Instagram’s AI detection is a mess (again)

Instagram is mislabeling ordinary edited photos as AI Content while some AI imagery goes unlabeled, repeating a 2024 detection failure.

The Verge documents weeks of erroneous AI Content labels on Instagram, including images edited only with Canva's Background Remover or an iPhone Photos app, while some generative images escape tagging. Canva said some of its assistive AI tools were being tagged as generative and claims the issue is fixed, though users still report tagging. Meta scans IPTC and C2PA metadata and uses signals like Google's SynthID, but remains vague about detection criteria; one tester found only Meta AI-created or edited images reliably triggered labels, and an image-poisoned photo was tagged. A similar mislabeling wave hit Instagram in 2024.

The Verge · AI · 12d agoAI industry

Adobe security advisory (AV26-808) – Update 1

Canada's Cyber Centre updated Adobe advisory AV26-808 to flag that CVE-2026-71362 in Adobe Commerce is being exploited in the wild.

The Canadian Centre for Cyber Security advisory AV26-808 (Update 1) lists vulnerabilities affecting Adobe products including Campaign Classic, Adobe Commerce, Magento Open Source, ColdFusion 2023/2025, Lightroom Classic, and Content Credentials SDKs. Update 1 notes that open-source reporting indicates CVE-2026-71362 is being exploited in the wild. Users and administrators are urged to review the referenced links and apply updates, including those in Adobe bulletin APSB26-92 for Adobe Commerce.

Canadian Centre for Cyber Securityupdated · 32m agofirst · 6d agoAdvisory in the wild 19 sourcesCVE-2026-71362

Adobe security advisory (AV26-848)

Canada's Cyber Centre relayed Adobe advisories covering vulnerabilities in Campaign Classic, Substance 3D apps, Adobe XD, Illustrator, and C2PA tools.

Bulletin AV26-848 lists Adobe vulnerabilities affecting Campaign Classic (through 7.4.4 build 9400), Substance 3D Designer, Painter, and Sampler, Adobe XD, C2PA Tool, Content Credentials Rust SDK, and Illustrator 2025/2026. The Canadian Centre for Cyber Security encourages users and administrators to review the linked Adobe bulletins and apply updates. Specific CVE identifiers are not enumerated in the advisory text.

Canadian Centre for Cyber Security · 21d agoAdvisory

Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day

Adobe patched over 170 flaws, including in-the-wild zero-day CVE-2026-75650 (CVSS 10) in Adobe Commerce/Magento enabling unauthenticated RCE and web shell deployments.

Adobe released fixes for more than 170 vulnerabilities across Experience Manager, Acrobat Reader, Photoshop and other products. The Commerce zero-day CVE-2026-75650 (CVSS 10) allows unauthenticated code injection leading to remote code execution and has been exploited since September 4. Sansec reported multiple threat actors deploying backdoors and web shells via the bug, dubbed StyleSmuggler, which triggers injected code through Magento's Payment Transaction Failed Reminder email. Adobe also patched critical Campaign Classic command injection CVE-2026-82004 and two critical ColdFusion RCE flaws (CVE-2026-48273, CVE-2026-75746).

SecurityWeek · 7d agoExploit / PoC in the wildCVE-2026-75650CVE-2026-82004CVE-2026-48273+1 CVEs1

Adobe fixes critical Magento zero-day exploited to backdoor servers

Adobe emergency-patches actively exploited max-severity Magento/Adobe Commerce zero-day CVE-2026-75650 (StyleSmuggler), used since Sept 4 to backdoor servers.

Adobe released an emergency hotfix (VULN-39341) for CVE-2026-75650, a max-severity zero-day dubbed StyleSmuggler affecting Adobe Commerce 2.4.4-2.4.9, Adobe Commerce B2B 1.3.3-1.5.3, and Magento Open Source 2.4.6-2.4.9, enabling arbitrary code execution. Sansec reports the flaw has been exploited since at least September 4 to plant a backdoor whose C2 host is disguised as an NTP server, leaving traces like 'Payment Transaction Failed Reminder' emails. A second attacker with unrelated tooling is exploiting the flaw to deploy a 485-byte PHP web shell that collects server details, checks pub/media writability, and exfiltrates data to an oast.site subdomain. Adobe recommends immediate hotpatching plus rotation of all secrets including admin passwords, API keys, database credentials, and SSH keys.

BleepingComputer · 8d agoExploit / PoC in the wildCVE-2026-756501

Adobe patches critical Magento account takeover (APSB26-92)

Adobe ships isolated patches (APSB26-92) for Adobe Commerce and Magento Open Source fixing seven flaws, five Critical including account takeover CVE-2026-71362.

Adobe released isolated security patches under APSB26-92 for Adobe Commerce and Magento Open Source addressing seven vulnerabilities, five of them rated Critical. The critical set includes CVE-2026-71362, which Sansec characterizes as enabling account takeover. Merchots running Magento-based stores are urged to apply the patches.

Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell

Adobe patches actively exploited Magento zero-day CVE-2026-75650 (CVSS 10.0), abused since Sept 4 to deploy a Rust backdoor and PHP web shells.

Adobe released an emergency hotfix (VULN-39341) for CVE-2026-75650 (CVSS 10.0), dubbed StyleSmuggler by Sansec, which abuses Magento's template system via PHP code injection to trigger unauthenticated remote code execution in Adobe Commerce and Magento Open Source. Exploitation began September 4, 2026, with attackers deploying a Rust-based Linux backdoor and a PHP dropper that writes a web shell; one managed server was compromised 50 minutes after the first report. Previdian honeypots recorded 12 exploitation attempts from two unique IPs in China and Romania since September 7, all unsuccessful. Adobe urges merchants to apply the patch and rotate encryption keys.

The Hacker News · 8d agoExploit / PoC in the wildCVE-2026-75650

Adobe Commerce max-severity bug comes under active attack

Attackers are actively exploiting CVE-2026-75650 (CVSS 10.0), an unauthenticated RCE zero-day in Adobe Commerce/Magento, deploying a Rust backdoor on e-commerce servers.

Sansec identified active exploitation of a CVSS 10.0 zero-day (CVE-2026-75650) in Adobe Commerce and Magento Open Source versions 2.4.4 through 2.4.9, dubbed StyleSmuggler. The attack abuses crafted style properties in Magento template processing to execute PHP while rendering a 'Payment Transaction Failed Reminder' email, then launches a Rust backdoor connecting to C2 at 99.84.67.186 disguised as NTP traffic. Exploitation began September 4, 2026; Adobe released emergency hotfix VULN-393411, but Sansec also observed a second attacker deploying a PHP web shell in the product-image cache.

CSO Online · 8d agoExploit / PoC in the wildCVE-2026-75650

Adobe Commerce CVE-2026-71362 Comes Under Attack Shortly After Public Disclosure

Attackers began exploiting critical Adobe Commerce flaw CVE-2026-71362 (CVSS 9.1) for unauthenticated customer account takeover shortly after patch release.

Sansec blocked the first exploitation attempts of CVE-2026-71362 immediately after Adobe published its advisory. The flaw lets unauthenticated attackers switch a customer session to another customer account, hijacking accounts and accessing private data without credentials, admin privileges or user interaction. It affects Adobe Commerce, Commerce B2B and Magento Open Source versions through the July 2026 patches, and Adobe issued isolated patch files APSB26-92 fixing seven vulnerabilities, including stored cross-site scripting and authorization issues.

Security Affairs · Aug 13, 2026Exploit / PoC in the wildCVE-2026-71362

StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack

Sansec details actively exploited StyleSmuggler 0-day (CVE-2026-75650, CVSS 10.0) unauthenticated RCE in Magento and Adobe Commerce, patched by Adobe hotfix APSB26-146.

Sansec is investigating StyleSmuggler, an actively exploited unauthenticated remote code execution chain in Magento Open Source and Adobe Commerce, now tracked as CVE-2026-75650 with CVSS 10.0. Adobe released hotfix VULN-39341 via APSB26-146 (priority 1) on September 7 for versions 2.4.4 through 2.4.9, but stores were being exploited for roughly three days before the fix existed. The implant is a Rust backdoor that disguises itself as kworker, fc-cache, or chronyd processes and exfiltrates host data in MessagePack records sent as fake NTP replies over UDP port 123. Adobe advises rotating the encryption key and every credential it protected, and Sansec stresses patching does not clean already-compromised stores.

Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

Sansec reports active exploitation of an unpatched zero-day, dubbed StyleSmuggler, in Magento and Adobe Commerce, letting attackers backdoor online store servers without authentication.

Sansec disclosed on September 5 that attackers are exploiting an unpatched vulnerability, named StyleSmuggler, in Magento Open Source and Adobe Commerce to achieve unauthenticated remote code execution, with attacks observed starting September 4. All current versions including 2.4.9 are affected, and Adobe has published no advisory, CVE, patch, or workaround, with the next scheduled security release on September 8. Hosting firm Disrex Group independently confirmed two compromised stores (running 2.4.8 and 2.4.7-p2), both breached within the roughly eight-hour window before Sansec's blocking rules went live. The implant is a ~1.9 MB statically linked Rust binary disguised as a Linux kworker process, re-adding a cron entry every five minutes and in one case reading Magento sessions directly from Redis with no outbound traffic.

The Hacker News · 10d agoExploit / PoC in the wild

Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

Adobe patches seven flaws in ColdFusion, Commerce, and Campaign Classic, including actively exploited CVE-2026-71362 enabling customer account takeover.

Adobe issued Priority 1 updates fixing CVSS 10.0 flaws in ColdFusion (CVE-2026-48362, OS command injection) and Campaign Classic (CVE-2026-71398, CVE-2026-27302, incorrect authorization), plus CVE-2026-71362 (CVSS 9.1) in Adobe Commerce and Magento Open Source. Sansec reports threat actors are actively exploiting CVE-2026-71362 to switch customer sessions to other accounts and access private customer data. Adobe-hosted Campaign Classic instances are already remediated, while on-premise deployments are urged to patch within 72 hours. ColdFusion fixes ship in versions 2025.0.12 and 2023.0.23, and Campaign Classic fixes in v7 7.4.4 build 9400.

The Hacker News · Aug 15, 2026Vulnerability in the wildCVE-2026-48362CVE-2026-48273CVE-2026-71384+5 CVEs

LynnReal-Omni: Native multi-modal Video Generation for Agentic Visual Workflows

LynnReal-Omni unifies controllable video generation tasks in a 32B multimodal diffusion transformer, with a 27B Flash variant rendering 540p clips in 377 ms.

LynnReal-Omni is a native multimodal video generation framework built on a 32B shared multimodal diffusion transformer unifying text-to-video, image-conditioned generation, reference guidance, structural control, editing, restoration and long-video generation, accepting heterogeneous inputs like 3D renders and game recordings for agentic visual workflows. A dedicated 27B Flash model enables real-time rendering, producing a 22-frame 540p video in 377 ms on one H100 versus 843 ms for the full model. The work introduces a curated multi-shot audiovisual data pipeline and MSAVP, a 100-prompt, 20-metric evaluation design covering instruction following, plausibility, visual quality, temporal behavior and audio coordination.

Hugging Face daily papers · 2d agoAI research

ZDI-26-603: Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability

Foxit PDF Reader has a second annotation use-after-free vulnerability (CVE-2026-13127, CVSS 7.8) allowing remote code execution via malicious files or pages.

ZDI-26-603 describes a use-after-free vulnerability in the annotation feature of Foxit PDF Reader, tracked as CVE-2026-13127 with a CVSS score of 7.8. Successful exploitation allows remote attackers to execute arbitrary code, but requires user interaction such as visiting a malicious page or opening a malicious file. The advisory does not mention any exploitation in the wild.

ZDI-26-597: Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability

Foxit PDF Reader has a use-after-free vulnerability (CVE-2026-57252, CVSS 7.8) allowing remote code execution via malicious AcroForm content.

ZDI-26-597 describes a use-after-free vulnerability in the AcroForm feature of Foxit PDF Reader, tracked as CVE-2026-57252 with a CVSS score of 7.8. Successful exploitation allows remote attackers to execute arbitrary code, but requires user interaction such as visiting a malicious page or opening a malicious file. The advisory does not mention any exploitation in the wild.