Close Menu
NCIJ Network NCIJ Network
    What's Hot

    DeepOcean and TFKable plan JV for inter-array cable projects with dedicated vessel

    September 23, 2026

    The Guardian view on the future of the UN: more embattled, but more necessary, than ever | Editorial

    September 23, 2026

    Iran’s president says his country’s people have been ‘victims of terrorism’ by the United States – live | United Nations

    September 23, 2026
    Facebook X (Twitter) Instagram
    Trending
    • DeepOcean and TFKable plan JV for inter-array cable projects with dedicated vessel
    • The Guardian view on the future of the UN: more embattled, but more necessary, than ever | Editorial
    • Iran’s president says his country’s people have been ‘victims of terrorism’ by the United States – live | United Nations
    • No signs Chagos deal can be adapted to suit Trump, say UK officials | Chagos Islands
    • The Guardian view on Russian disinformation: a foreign threat that relies on UK complicity | Editorial
    • Zoox grounds Atlanta test fleet after workers report toxic gas exposure symptoms
    • Adobe Patches Critical Flaws in Connect, AEM Forms
    • Stablecoins hold nearly $200 billion in US debt, but money funds bought the surge
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 23
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Adobe Patches Critical Flaws in Connect, AEM Forms

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 23, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Adobe on Tuesday rolled out patches for 36 vulnerabilities across its products, including critical-severity flaws in Connect and Experience Manager (AEM) Forms.

    The Adobe Connect update resolves nine security defects, including six critical issues that could be exploited for arbitrary code execution and privilege escalation.

    Tracked as CVE-2026-75682, CVE-2026-75684, CVE-2026-75686, CVE-2026-75689, CVE-2026-75697, and CVE-2026-75698, they are described as SQL injection, cross-site scripting (XSS), and improper input validation flaws.

    The update also fixes high-severity path traversal, improper certificate validation, and XSS weaknesses that could lead to arbitrary file system read, security feature bypass, and arbitrary code execution.

    Adobe patched six vulnerabilities in AEM Forms, including three critical-severity flaws leading to code execution and privilege escalation.

    Described as incorrect authorization, improper input validation, and server-side request forgery (SSRF), the critical issues are tracked as CVE-2026-75745, CVE-2026-81995, and CVE-2026-82000.

    Advertisement. Scroll to continue reading.

    The AEM Forms patches also fix three high-severity SSRF, XSS, and cross-site request forgery (CSRF) bugs leading to privilege escalation, code execution, and security feature bypass.

    Both security updates have a priority 2 rating, meaning that users should apply them within the next 30 days.

    On Tuesday, Adobe also announced fixes for multiple high- and medium-severity vulnerabilities in InDesign, Content Credentials SDK, Bridge, Substance 3D Modeler, and Premiere Pro.

    Successful exploitation of these security defects could lead to application denial-of-service (DoS), security feature bypass, arbitrary code execution, and memory exposure.

    Adobe says it is not aware of any of these security flaws being exploited in the wild. Additional information is available on the company’s security bulletins page.

    Related: Chrome 154 Patches 108 Vulnerabilities

    Related: Arista Urges Immediate Patching of Exploited VCO Zero-Day

    Related: Chrome, Firefox Updates Patch 115 Vulnerabilities

    Related: Check Point, Kaspersky, Tanium Patch Product Vulnerabilities

    Adobe AEM connect critical flaws Forms Patches
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key

    InfraTrust report warns network management systems under attack

    Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI

    Arista patches actively exploited VeloCloud Orchestrator zero-day

    Honeywell: OT Security Teams Embrace AI, but Autonomy Still Rare

    Trump-Xi Summit: What to Expect on AI, Trade, Critical Minerals

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    DeepOcean and TFKable plan JV for inter-array cable projects with dedicated vessel

    September 23, 2026

    The Guardian view on the future of the UN: more embattled, but more necessary, than ever | Editorial

    September 23, 2026

    Iran’s president says his country’s people have been ‘victims of terrorism’ by the United States – live | United Nations

    September 23, 2026

    No signs Chagos deal can be adapted to suit Trump, say UK officials | Chagos Islands

    September 23, 2026
    Latest Posts

    Ransom Cartel ransomware creator sentenced to 16 years in prison

    August 5, 2026

    Uber CEO brushes off reports of a Waymo break-up

    August 5, 2026

    Fauci Faces Contempt Vote. Here Are the Legal Issues Involved.

    August 6, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    DeepOcean and TFKable plan JV for inter-array cable projects with dedicated vessel

    September 23, 2026

    The Guardian view on the future of the UN: more embattled, but more necessary, than ever | Editorial

    September 23, 2026

    Iran’s president says his country’s people have been ‘victims of terrorism’ by the United States – live | United Nations

    September 23, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.