Multiple vulnerabilities in Adobe products (August 13, 2026)
Multiple vulnerabilities have been discovered in Adobe products. Some of them allow an attacker to cause arbitrary remote code execution, privilege escalation and remote denial of service.
CSIRTS triage
- What
- Multiple vulnerabilities in Adobe products allow remote code execution, privilege escalation, and denial of service.
- Who is affected
- Adobe product users across affected applications (specific products unspecified).
- Urgency
- High; remote code execution and privilege escalation pose critical risk.
- Action
- Identify affected Adobe products and apply patches for the listed CVEs.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1017/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-484110.77% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 53% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-484400.55% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 44% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-212790.47% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-483750.52% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 42% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-484150.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-256520.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-713866.6% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 93% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-484120.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-713840.37% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 29% of all EPSS-scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Adobe Magento: Multiple Vulnerabilitiescert-bund
- unknownNCSC-2026-0294 [1.00] [M/H] Vulnerabilities patched in Adobe ColdFusionncsc-nl
- high[NEW] [high] Adobe ColdFusion: Multiple Vulnerabilitiescert-bund
- unknownNCSC-2026-0292 [1.00] [M/H] Vulnerabilities patched in Adobe Commercencsc-nl
- criticalCVE-2026-71362: Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in pr…nvd
- highCVE-2026-48416: Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a …nvd
- highCVE-2026-48415: Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a …nvd
- highCVE-2026-48414: Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be …nvd
- highCVE-2026-48413: Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be …nvd
- lowCVE-2026-48412: Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in pr…nvd
- mediumCVE-2026-48411: Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a …nvd
- highCVE-2026-71387: ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitr…nvd
More from CERT-FR Avis de sécurité
- unknownMultiple vulnerabilities in Keycloak (August 25, 2026)2026-08-25
- unknownMultiple vulnerabilities in Cisco IOS XE (August 25, 2026)2026-08-25
- unknownMultiple vulnerabilities in LibreNMS (August 24, 2026)2026-08-24
- unknownMultiple vulnerabilities in Metabase (August 24, 2026)2026-08-24
- unknownVulnerability in SPIP (August 21, 2026)2026-08-21