Adobe has just rolled out patches for 36 vulnerabilities across its products, including critical flaws in Adobe Connect and Experience Manager (AEM) Forms that could be exploited to execute malicious code or gain unauthorized access. The updates address a range of security issues, from SQL injection and cross-site scripting (XSS) weaknesses to improper input validation and server-side request forgery (SSRF).
The critical vulnerabilities in Adobe Connect have been tracked as CVE-2026-75682, CVE-2026-75684, CVE-2026-75686, CVE-2026-75689, CVE-2026-75697, and CVE-2026-75698. These flaws could be exploited to execute arbitrary code or escalate privileges, potentially allowing attackers to gain control of affected systems. The update also fixes high-severity path traversal, improper certificate validation, and XSS weaknesses that could lead to arbitrary file system read, security feature bypass, and arbitrary code execution.
Adobe AEM Forms has been patched for six vulnerabilities, including three critical-severity flaws leading to code execution and privilege escalation. These issues are tracked as CVE-2026-75745, CVE-2026-81995, and CVE-2026-82000, and have been described as incorrect authorization, improper input validation, and SSRF. The patches also address three high-severity SSRF, XSS, and cross-site request forgery (CSRF) bugs that could lead to privilege escalation, code execution, and security feature bypass.
While Adobe has not reported any known exploits in the wild, users are advised to apply the updates within the next 30 days, as indicated by their priority rating. This is particularly important for organizations using Adobe Connect or AEM Forms, where successful exploitation of these vulnerabilities could have significant consequences.
In addition to the Connect and AEM Forms patches, Adobe has also released fixes for multiple high- and medium-severity vulnerabilities in InDesign, Content Credentials SDK, Bridge, Substance 3D Modeler, and Premiere Pro. These issues could lead to application denial-of-service (DoS), security feature bypass, arbitrary code execution, and memory exposure.
As with any software update, it’s essential to apply these patches promptly to ensure the security of your systems. Adobe has made additional information available on its security bulletins page, which includes detailed descriptions of each vulnerability and mitigation instructions.
Source: SecurityWeek — 2026-09-23