CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Adobe security advisory (AV26-697)

critical
Serial number: AV26–697 Date: July 14, 2026 On July 14, 2026, Adobe published security advisories to address critical vulnerabilities in the following products: Adobe After Effects - version 25.6.5 and prior Adobe After Effects - version 26.2.1 and prior Adobe Animate 2023 - version 23.0.15 and prior Adobe Animate 2024 - version 24.0.13 and prior Adobe Audition - version 25.6.4 and prior Adobe Audition - version 26.0 and prior Adobe Bridge - version 15.1.5 (LTS) and prior Adobe Bridge - version 16.0.3 and prior Adobe Commerce B2B - multiple versions Adobe Commerce - multiple versions Adobe Commerce Events - version 1.6.0 to 1.20.0 Adobe Experience Manager (AEM) - version AEM Cloud Service (CS) Release 2026.5.0 and prior Adobe Experience Manager (AEM) - version 6.5 LTS Service Pack 1 and prior Adobe Experience Manager (AEM) - version 6.5 Service Pack 24 and prior Adobe Media Encoder - version 25.6.5 and prior Adobe Media Encoder - version 26.2.2 and prior Adobe Premiere - version 26.2.2 and prior Adobe Premiere Pro - version 25.6.5 and prior ColdFusion 2025 Update 10 and earlier versions ColdFusion 2023 Update 21 and earlier versions ColdFusion 2021 - version 2021.0.0.323925 and prior ColdFusion 2023 - version 2023.0.0.330468 and prior ColdFusion 2025 - version 2023.0.0.331385 and prior Content Credentials Command-Line Tool - version c2patool-v0.17.0 and prior Content Credentials JS SDK - version @contentauth/c2pa-web@0.7.0 and prior Content Credentials Rust SDK - version c2pa-v0.84.0 and prior Creative Cloud Desktop Application - version 6.9.1.1 and prior Illustrator 2025 - version 29.8.7 and prior Illustrator 2026 - version 30.5 and prior Magento Open Source - multiple versions The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates. Adobe Security Advisories

CSIRTS triage

What
Adobe published security advisories to address critical vulnerabilities in multiple products.
Who is affected
Users of affected Adobe products including After Effects, Animate, Audition, Bridge, and Commerce.
Urgency
Remediation is critical as the vulnerabilities are severe, although no exploitation has been reported yet.
Action
Review the advisories and apply the necessary updates for the affected products.

AI-assisted analysis generated from the source advisory — verify against the original.

Details

Source
Canadian Centre for Cyber Security (CA · national-cert · site)
Severity
critical
Published
2026-07-14
Exploitation
Not in CISA KEV at last sync

Original advisory: https://cyber.gc.ca/en/alerts-advisories/adobe-security-advisory-av26-697

More from Canadian Centre for Cyber Security