Adobe security advisory (AV26-888) – Update 1
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Serial Number: AV26-888 Date: September 8, 2026 As of September 8, 2026, Adobe is affected by a vulnerability in the following products: Adobe Acrobat Multiple versions Adobe Animate 2023 Prior to or equal to 2023.0.16 Adobe Animate 2024 Prior to or equal to 0.14 Adobe Campaign Classic Prior to or equal to ACC v7: 7.4.4 build 9401 Adobe ColdFusion 2023 Prior to or equal to 2023.0.23 Adobe ColdFusion 2025 Prior to or equal to 0.12 Adobe Commerce All except Hotfix for CVE-2026-7565 Prior to or equal to 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug Adobe Commerce B2B All except Hotfix for CVE-2026-7565 Prior to or equal to 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug Adobe Experience Manager (AEM) Prior to or equal to AEM Cloud Service (CS) Release 2026.7.0 Prior to or equal to 5 LTS Service Pack 2 Prior to or equal to 5 Service Pack 24 and earlier Adobe Illustrator 2025 Prior to or equal to 8.10 Adobe Illustrator 2026 Prior to or equal to 7 Adobe Photoshop 2025 Prior to or equal to 11.6 Adobe Photoshop 2026 Prior to or equal to 6 Magento Open Source All except Hotfix for CVE-2026-7565 Prior to or equal to 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug Adobe indicates that CVE-2026-75650 is exploited in the wild. Update 1 On September 8, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-75650 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Adobe Product Security Incident Response Team CISA KEV: CVE-2026-75650
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/adobe-security-advisory-av26-888
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-75650.69% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 51% of all EPSS-scored CVEs.
- Exploitation confirmedCVE-2026-75650Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 81% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-7565 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-75650 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- criticalexploited[UPDATE] [kritisch] Adobe Magento Open Source: Schwachstelle ermöglicht Ausführen von beliebigem Programmcode …cert-bund
- highexploited[NEU] [hoch] Adobe Magento: Mehrere Schwachstellencert-bund
- unknownexploitedAdobe Monthly Security Update (September 2026)hkcert
- highexploitedCISA Adds Four Known Exploited Vulnerabilities to Catalogcisa
- unknownexploitedNCSC-2026-0344 [1.00] [H/H] Kwetsbaarheid verholpen in Adobe Commerce en Magentoncsc-nl
- criticalexploitedCVE-2026-75650: Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engi…cisa-kev
- unknownexploitedVulnérabilité dans les produits Adobe (08 septembre 2026)cert-fr-avis
- criticalexploitedCVE-2026-75650: Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Templat…nvd
More from Canadian Centre for Cyber Security
- unknownFortra security advisory (AV26-906)2026-09-10
- unknownPalo Alto Networks security advisory (AV26-905)2026-09-10
- unknownAL26-019 - Vulnerabilities impacting Citrix NetScaler ADC and NetScaler Gateway - CVE-2026-19490 and CVE-2026-…2026-09-09
- unknownCitrix security advisory (AV26-833) - Update 12026-09-09
- criticalCisco security advisory (AV26-197) – Update 32026-09-09