Adobe Patches Critical Flaws in Connect, AEM Forms

Adobe’s latest batch of security patches addresses 36 vulnerabilities across various products, including critical flaws in its Connect and Experience Manager (AEM) Forms applications. The updates aim to fix several high-severity weaknesses that could lead to unauthorized code execution, privilege escalation, and data exposure.

The Adobe Connect update resolves nine security defects, with six classified as critical. These flaws, tracked under the CVE-2026-75682 to CVE-2026-75698 identifiers, include SQL injection, cross-site scripting (XSS), and improper input validation vulnerabilities. The remaining three issues are categorized as high-severity path traversal, improper certificate validation, and XSS weaknesses that could result in arbitrary file system read, security feature bypass, and code execution.

In addition to the Connect patches, Adobe has also addressed six vulnerabilities in AEM Forms. Among these, three critical flaws – CVE-2026-75745, CVE-2026-81995, and CVE-2026-82000 – can be exploited for code execution and privilege escalation due to incorrect authorization, improper input validation, and server-side request forgery (SSRF). The AEM Forms patches also fix high-severity SSRF, XSS, and cross-site request forgery (CSRF) bugs that could lead to privilege escalation, code execution, and security feature bypass.

Both the Adobe Connect and AEM Forms updates carry a priority 2 rating, meaning users should apply them within the next 30 days. This urgency is due to the potential impact of exploiting these vulnerabilities, which could result in unauthorized access to sensitive data or system compromise.

Adobe has also released patches for multiple high- and medium-severity vulnerabilities across other products, including InDesign, Content Credentials SDK, Bridge, Substance 3D Modeler, and Premiere Pro. Successful exploitation of these security defects could lead to application denial-of-service (DoS), security feature bypass, arbitrary code execution, and memory exposure.

It’s worth noting that Adobe has stated it is not aware of any of the vulnerabilities being exploited in the wild. However, with the potential for significant impact, users are advised to review the available patches and apply them as soon as possible to ensure their systems remain secure.

As a practical takeaway, we recommend that all users check Adobe’s security bulletins page for more information on the latest updates. Users should also prioritize applying these patches within the recommended timeframe to minimize potential risks. By staying up-to-date with the latest security patches and best practices, you can help protect your organization from the ever-evolving landscape of cybersecurity threats.


Source: SecurityWeek — 2026-09-23