CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Adobe security advisory (AV26-888) – Update 1

unknownknown exploitedpublic exploitCVE-2026-7565CVE-2026-75650
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Serial Number: AV26-888 Date: September 8, 2026 As of September 8, 2026, Adobe is affected by a vulnerability in the following products: Adobe Acrobat Multiple versions Adobe Animate 2023 Prior to or equal to 2023.0.16 Adobe Animate 2024 Prior to or equal to 0.14 Adobe Campaign Classic Prior to or equal to ACC v7: 7.4.4 build 9401 Adobe ColdFusion 2023 Prior to or equal to 2023.0.23 Adobe ColdFusion 2025 Prior to or equal to 0.12 Adobe Commerce All except Hotfix for CVE-2026-7565 Prior to or equal to 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug Adobe Commerce B2B All except Hotfix for CVE-2026-7565 Prior to or equal to 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug Adobe Experience Manager (AEM) Prior to or equal to AEM Cloud Service (CS) Release 2026.7.0 Prior to or equal to 5 LTS Service Pack 2 Prior to or equal to 5 Service Pack 24 and earlier Adobe Illustrator 2025 Prior to or equal to 8.10 Adobe Illustrator 2026 Prior to or equal to 7 Adobe Photoshop 2025 Prior to or equal to 11.6 Adobe Photoshop 2026 Prior to or equal to 6 Magento Open Source All except Hotfix for CVE-2026-7565 Prior to or equal to 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug Adobe indicates that CVE-2026-75650 is exploited in the wild. Update 1 On September 8, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-75650 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Adobe Product Security Incident Response Team CISA KEV: CVE-2026-75650

Details

Source
Canadian Centre for Cyber Security (CA · national-cert · site)
Severity
unknown
Published
2026-09-08
Exploitation
Observed in the wild (CISA KEV)

Original advisory: https://cyber.gc.ca/en/alerts-advisories/adobe-security-advisory-av26-888

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-7565coverage & exploitation statusNVD · CVE.org
CVE-2026-75650coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from Canadian Centre for Cyber Security