Multiples vulnérabilités dans les produits Adobe (09 septembre 2026)
De multiples vulnérabilités ont été découvertes dans les produits Adobe. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1140/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-820010.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-819900.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-819820.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-819840.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-819890.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-819880.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-771080.48% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-761900.97% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 60% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-819780.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-819910.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
Referenced CVEs
+1 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownNCSC-2026-0362 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe ColdFusionncsc-nl
- unknownNCSC-2026-0361 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Commercencsc-nl
- high[NEU] [hoch] Adobe Acrobat und Acrobat Reader: Mehrere Schwachstellencert-bund
- high[NEU] [hoch] Adobe ColdFusion: Mehrere Schwachstellencert-bund
- highexploited[NEU] [hoch] Adobe Magento: Mehrere Schwachstellencert-bund
- high[UPDATE] [hoch] Adobe ColdFusion: Mehrere Schwachstellencert-bund
- mediumCVE-2026-82001: Acrobat Reader is affected by an Uncontrolled Resource Consumption vulnerability that could le…nvd
- mediumCVE-2026-81997: Acrobat Reader is affected by an Incorrect Authorization vulnerability that could result in a …nvd
- highCVE-2026-81996: Acrobat Reader is affected by an Incorrect Authorization vulnerability that could result in pr…nvd
- highCVE-2026-81994: Acrobat Reader is affected by an Improperly Controlled Modification of Object Prototype Attrib…nvd
- mediumCVE-2026-81993: Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could lead to di…nvd
- highCVE-2026-81992: Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could result in …nvd
More from CERT-FR Avis de sécurité
- unknownMultiples vulnérabilités dans Microsoft Office (09 septembre 2026)2026-09-09
- unknownMultiples vulnérabilités dans les produits Microsoft (09 septembre 2026)2026-09-09
- unknownMultiples vulnérabilités dans Microsoft Azure (09 septembre 2026)2026-09-09
- unknownMultiples vulnérabilités dans Google Chrome (09 septembre 2026)2026-09-09
- unknownVulnérabilité dans les produits ESET (09 septembre 2026)2026-09-09