Skip to content
Threat Feed
high threat

Adobe Security Updates — August 2026

Roundup of Adobe security advisories published in August 2026.

CVE search metadata

CVE search record: CVE-2026-48362. Severity: critical. CVSS: 10.0. EPSS: 4.31%. KEV: no. Product: ColdFusion 2025 (<= 2025.0.11). Brief: Adobe Security Updates — August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-adobe-security-updates/

CVE search record: CVE-2026-21279. Severity: high. CVSS: 8.2. EPSS: 0.47%. KEV: no. Brief: Adobe Security Updates — August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-adobe-security-updates/

CVE search record: CVE-2026-48424. Severity: high. CVSS: 7.8. EPSS: 0.20%. KEV: no. Brief: Adobe Security Updates — August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-adobe-security-updates/

CVE search record: CVE-2026-48432. Severity: high. CVSS: 7.8. EPSS: 0.20%. KEV: no. Brief: Adobe Security Updates — August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-adobe-security-updates/

CVE search record: CVE-2026-34674. Severity: high. CVSS: 7.8. KEV: no. Brief: Adobe Security Updates — August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-adobe-security-updates/

What's new

  • 1. added CVE-2026-34674 +1 Aug 27, 19:09 via nvd
  • 2. added CVE-2026-71564 +2 Aug 25, 18:55 via nvd
  • 3. added CVE-2026-48405 +2 Aug 25, 18:55 via nvd
  • 4. added CVE-2026-48447 Aug 25, 18:55 via nvd
  • 5. added CVE-2026-75766 Aug 25, 18:54 via nvd

This roundup covers 50 Adobe security vulnerabilities. CVSS base scores range from 7.1 to 10.0. None are reported as actively exploited at the time of release. The issues affect Adobe Campaign Classic, Adobe Commerce, Adobe Substance 3D Designer, Adobe Substance 3D Painter, Adobe Substance 3D Sampler, ColdFusion, ColdFusion 2025, Content Credentials Rust SDK, Lightroom Classic, Substance 3D Painter, Substance 3D Sampler.

Summary

CVEProductSeverityCVSSEPSSKEVSource
CVE-2026-48362ColdFusion 2025 (<= 2025.0.11)Critical10.04.31%noNVD (authoritative)
CVE-2026-71384n/aCritical9.60.37%noNVD (authoritative)
CVE-2026-21273ColdFusion 2025 (<= 2025.0.11)noNVD (authoritative)
CVE-2026-21279n/aHigh8.20.47%noNVD (authoritative)
CVE-2026-25652n/aHigh7.80.14%noNVD (authoritative)
CVE-2026-34635n/aHigh8.40.18%noNVD (authoritative)
CVE-2026-48385ColdFusion (<= 2025.0.11)noNVD (authoritative)
CVE-2026-48386ColdFusion 2025 (<= 2025.0.11)noNVD (authoritative)
CVE-2026-48439Content Credentials Rust SDK (<= c2pa-v0.90.5)High7.50.51%noNVD (authoritative)
CVE-2026-48440n/aHigh8.10.55%noNVD (authoritative)
CVE-2026-48442Content Credentials Rust SDK (<= c2pa-v0.90.5)High7.10.24%noNVD (authoritative)
CVE-2026-27302Adobe Campaign Classic (<= 7.4.3 build 9399)Critical10.00.71%noNVD (authoritative)
CVE-2026-71362n/aCritical9.125.14%noNVD (authoritative)
CVE-2026-71398Adobe Campaign Classic (<= 7.4.3 build 9399)Critical10.00.79%noNVD (authoritative)
CVE-2026-47940n/anoNVD (authoritative)
CVE-2026-48397n/anoNVD (authoritative)
CVE-2026-48405n/aHigh7.80.16%noNVD (authoritative)
CVE-2026-48406n/anoNVD (authoritative)
CVE-2026-48407n/aHigh7.80.16%noNVD (authoritative)
CVE-2026-48408Lightroom Classic (<= 15.4)High7.80.16%noNVD (authoritative)
CVE-2026-48410n/aHigh7.80.16%noNVD (authoritative)
CVE-2026-48413Adobe Commerce (<= 2026-07-31)noNVD (authoritative)
CVE-2026-48415n/aHigh7.60.35%noNVD (authoritative)
CVE-2026-48416n/aHigh7.50.50%noNVD (authoritative)
CVE-2026-48447n/aHigh7.70.14%noNVD (authoritative)
CVE-2026-76193Adobe Campaign Classic (<= 7.4.4 build 9400)Critical10.0noNVD (authoritative)
CVE-2026-76195Adobe Campaign Classic (<= 7.4.4 build 9400)Critical10.0noNVD (authoritative)
CVE-2026-76197Adobe Campaign Classic (<= 7.4.4 build 9400)Critical10.0noNVD (authoritative)
CVE-2026-48417Substance 3D Sampler (<= 6.0.1)noNVD (authoritative)
CVE-2026-48418Adobe Substance 3D Sampler (<= 6.0.1)noNVD (authoritative)
CVE-2026-48419Substance 3D Sampler (<= 6.0.1)High7.8noNVD (authoritative)
CVE-2026-48420Adobe Substance 3D Sampler (<= 6.0.1)High7.8noNVD (authoritative)
CVE-2026-48421Substance 3D Sampler (<= 6.0.1)High7.8noNVD (authoritative)
CVE-2026-48424Adobe Substance 3D Sampler (<= 6.0.1)noNVD (authoritative)
CVE-2026-48426Adobe Substance 3D Designer (<= 16.0.4)noNVD (authoritative)
CVE-2026-48427Adobe Substance 3D Designer (<= 16.0.4)noNVD (authoritative)
CVE-2026-48428Adobe Substance 3D Designer (<= 16.0.4)noNVD (authoritative)
CVE-2026-48430Adobe Substance 3D Designer (<= 16.0.4)noNVD (authoritative)
CVE-2026-48432Adobe Substance 3D Designer (<= 16.0.4)High7.8noNVD (authoritative)
CVE-2026-48433Adobe Substance 3D Designer (<= 16.0.4)noNVD (authoritative)
CVE-2026-71360n/aHigh7.5noNVD (authoritative)
CVE-2026-71382Substance 3D Sampler (<= 6.0.1)noNVD (authoritative)
CVE-2026-71443n/anoNVD (authoritative)
CVE-2026-71564Adobe Substance 3D Designer (<= 16.0.4)High7.8noNVD (authoritative)
CVE-2026-75749Adobe Substance 3D Painter (<= 12.1.2)noNVD (authoritative)
CVE-2026-75750Adobe Substance 3D Painter (<= 12.1.2)High7.8noNVD (authoritative)
CVE-2026-75766Substance 3D Painter (<= 12.1.2)High7.8noNVD (authoritative)
CVE-2026-75768Substance 3D Painter (<= 12.1.2)noNVD (authoritative)
CVE-2026-75769Substance 3D Painter (<= 12.1.2)High7.8noNVD (authoritative)
CVE-2026-75770Adobe Substance 3D Painter (<= 12.1.2)noNVD (authoritative)

CVE-2026-48362

CVE-2026-48362 is a critical OS command injection vulnerability in Adobe ColdFusion 2023 and 2025 that allows unauthenticated, remote attackers to achieve arbitrary code execution. The vulnerability does not require user interaction and impacts the scope of the application, posing a significant risk to affected environments.

Affected products:

  • ColdFusion 2025 (<= 2025.0.11)
  • ColdFusion 2023 (<= 2023.0.22)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-48362

Related in this roundup: CVE-2026-21273, CVE-2026-48386.

CVE-2026-71384

CVE-2026-71384 is an incorrect authorization vulnerability in Adobe ColdFusion 2023 and 2025. The flaw allows an unauthenticated, adjacent attacker to bypass security features, resulting in unauthorized read and write access, and potentially a denial-of-service condition. Although the vulnerable component is restricted to an administrative network zone by default, successful exploitation does not require user interaction.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-71384

CVE-2026-21273

CVE-2026-21273 describes an improper input validation vulnerability in Adobe ColdFusion 2025 and 2023. A low-privileged attacker can exploit this flaw by enticing a user to open a malicious file, leading to unauthorized read and write access and privilege escalation on the affected system.

Affected products:

  • ColdFusion 2025 (<= 2025.0.11)
  • ColdFusion 2023 (<= 2023.0.22)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-21273

Related in this roundup: CVE-2026-48362, CVE-2026-48386.

CVE-2026-21279

Adobe ColdFusion versions 2025 (<= 2025.0.11) and 2023 (<= 2023.0.22) are vulnerable to an improper input validation flaw that allows for a security feature bypass. An unauthenticated remote attacker can exploit this vulnerability to gain unauthorized read and limited write access to the affected system without requiring user interaction.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-21279

CVE-2026-25652

CVE-2026-25652 is an Incorrect Authorization vulnerability in Adobe ColdFusion 2025 and 2023 versions. A low-privileged attacker can exploit this flaw to escalate privileges and gain unauthorized read and write access to the system. Exploitation is local and does not require user interaction.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-25652

CVE-2026-34635

Adobe ColdFusion versions 2025 (<= 2025.0.11) and 2023 (<= 2023.0.22) contain a Use of Hard-coded Cryptographic Key vulnerability. A low-privileged attacker can exploit this issue to bypass security features and obtain unauthorized read and write access without user interaction. The vulnerability results in a scope change, potentially allowing for cross-security-domain impact.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-34635

CVE-2026-48385

Adobe ColdFusion is vulnerable to an OS command injection flaw (CVE-2026-48385) that allows low-privileged, remote attackers to bypass security features and gain unauthorized write access to the system. The vulnerability does not require user interaction and impacts the system scope.

Affected products:

  • ColdFusion (<= 2025.0.11)
  • ColdFusion (<= 2023.0.22)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-48385

CVE-2026-48386

Adobe ColdFusion is vulnerable to a broken or risky cryptographic algorithm (CWE-327), which can be exploited by a remote, unauthenticated attacker to disclose sensitive memory contents. Successful exploitation allows for the unauthorized access to sensitive information without requiring user interaction.

Affected products:

  • ColdFusion 2025 (<= 2025.0.11)
  • ColdFusion 2023 (<= 2023.0.22)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-48386

Related in this roundup: CVE-2026-48362, CVE-2026-21273.

CVE-2026-48439

The CAI Content Credentials SDKs and command-line tool are vulnerable to an uncontrolled resource consumption issue (CWE-400). A remote, unauthenticated attacker can exploit this vulnerability to exhaust system resources, leading to a denial-of-service (DoS) condition. No user interaction is required for successful exploitation.

Affected products:

  • Content Credentials Rust SDK (<= c2pa-v0.90.5)
  • Content Credentials Command-Line Tool (<= c2patool-v0.27.5)
  • Content Credentials JS SDK (<= @contentauth/c2pa@0.14.2)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-48439

Related in this roundup: CVE-2026-48442.

CVE-2026-48440

Adobe ColdFusion versions 2025 (<= 2025.0.11) and 2023 (<= 2023.0.22) are vulnerable to a heap-based buffer overflow. This vulnerability allows an unauthenticated, remote attacker to execute arbitrary code in the context of the current user without requiring user interaction. The exploitation process is non-deterministic, relying on specific environmental conditions.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-48440

CVE-2026-48442

The Adobe Content Credentials SDK and associated tooling are vulnerable to a path traversal vulnerability (CWE-22) which allows an attacker to perform arbitrary file system reads. The vulnerability does not require user interaction and impacts multiple language-specific SDKs and the CLI tool.

Affected products:

  • Content Credentials Rust SDK (<= c2pa-v0.90.5)
  • Content Credentials Command-Line Tool (<= c2patool-v0.27.5)
  • Content Credentials JS SDK (<= @contentauth/c2pa-v0.27.5)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-48442

Related in this roundup: CVE-2026-48439.

CVE-2026-27302

Adobe Campaign Classic is vulnerable to an incorrect authorization flaw (CWE-863) that allows an unauthenticated remote attacker to execute arbitrary code. The vulnerability has a CVSS v3.1 base score of 10.0 and does not require user interaction to exploit.

Affected products:

  • Adobe Campaign Classic (<= 7.4.3 build 9399)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-27302

Related in this roundup: CVE-2026-71398, CVE-2026-76193, CVE-2026-76195, CVE-2026-76197.

CVE-2026-71362

Adobe Commerce and Magento Open Source are vulnerable to an Incorrect Authorization flaw (CWE-863) that allows an unauthenticated, remote attacker to perform privilege escalation. The vulnerability does not require user interaction and can be exploited to gain unauthorized access to sensitive resources.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-71362

CVE-2026-71398

Adobe Campaign Classic (ACC) is vulnerable to an incorrect authorization flaw (CWE-863) that allows an unauthenticated remote attacker to execute arbitrary code. The vulnerability has a CVSS base score of 10.0 and does not require user interaction for exploitation.

Affected products:

  • Adobe Campaign Classic (<= 7.4.3 build 9399)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-71398

Related in this roundup: CVE-2026-27302, CVE-2026-76193, CVE-2026-76195, CVE-2026-76197.

CVE-2026-47940

Adobe Lightroom Classic is vulnerable to an integer overflow or wraparound condition that can lead to arbitrary code execution. The vulnerability is triggered when a user is enticed to open a maliciously crafted file, allowing an attacker to execute code within the context of the current user session.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-47940

CVE-2026-48397

Adobe Lightroom Classic is vulnerable to a deserialization of untrusted data issue that allows an attacker to achieve arbitrary code execution. The vulnerability requires user interaction, specifically the opening of a malicious file by the victim, which triggers the flaw within the application context.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-48397

CVE-2026-48405

Adobe Lightroom Classic is vulnerable to an out-of-bounds write (CWE-787) flaw that allows an attacker to achieve arbitrary code execution. Successful exploitation requires a user to open a specially crafted malicious file, which triggers the memory corruption within the application context.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-48405

CVE-2026-48406

Adobe Lightroom Classic is vulnerable to an out-of-bounds write (CWE-787) that allows for arbitrary code execution. A local attacker can exploit this by convincing a user to open a specially crafted malicious file within the application.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-48406

CVE-2026-48407

Adobe Lightroom Classic is susceptible to an out-of-bounds write vulnerability that can be exploited by an attacker to achieve arbitrary code execution. Successful exploitation requires a user to open a specially crafted malicious file, which triggers the memory corruption issue within the application's process context.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-48407

CVE-2026-48408

Adobe Lightroom Classic is vulnerable to an out-of-bounds write (CWE-787) that allows for arbitrary code execution. Successful exploitation requires a user to open a specially crafted malicious file, which triggers the vulnerability in the context of the logged-in user.

Affected products:

  • Lightroom Classic (<= 15.4)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-48408

CVE-2026-48410

Adobe Lightroom Classic is vulnerable to an out-of-bounds write, which can be exploited by an attacker to achieve arbitrary code execution. Successful exploitation requires the user to open a malicious file, making it a client-side execution risk.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-48410

CVE-2026-48413

Adobe Commerce and Magento Open Source are vulnerable to a stored Cross-Site Scripting (XSS) attack via malicious input in form fields. A low-privileged attacker can inject scripts that execute in a victim's browser, potentially leading to unauthorized account or session control. This vulnerability involves a change in security scope.

Affected products:

  • Adobe Commerce (<= 2026-07-31)
  • Adobe Commerce B2B (<= 2026-07-31)
  • Magento Open Source (<= 2026-07-31)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-48413

CVE-2026-48415

Adobe Commerce and Magento Open Source are vulnerable to an Incorrect Authorization flaw (CWE-863) that allows a low-privileged, remote attacker to bypass security controls. Successful exploitation grants unauthorized read and write access without requiring user interaction, potentially impacting data integrity and availability.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-48415

CVE-2026-48416

CVE-2026-48416 is an incorrect authorization vulnerability in Adobe Commerce and Magento Open Source that allows remote, unauthenticated attackers to bypass security measures and gain unauthorized read access to sensitive data. The vulnerability does not require user interaction and is exploitable over the network.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-48416

CVE-2026-48447

Adobe Lightroom Classic is vulnerable to an incorrect authorization flaw (CWE-863) that can be exploited to achieve arbitrary code execution. The vulnerability is triggered when a user opens a maliciously crafted file. Successful exploitation requires user interaction and specific conditions beyond the attacker's control.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-48447

CVE-2026-76193

Adobe Campaign Classic (ACC) is vulnerable to a Server-Side Request Forgery (SSRF) flaw, identified as CVE-2026-76193. An unauthenticated, remote attacker can leverage this vulnerability to execute arbitrary code within the context of the service user without any interaction required. The vulnerability carries a critical CVSS v3.1 score of 10.0.

Affected products:

  • Adobe Campaign Classic (<= 7.4.4 build 9400)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-76193

Related in this roundup: CVE-2026-27302, CVE-2026-71398, CVE-2026-76195, CVE-2026-76197.

CVE-2026-76195

Adobe Campaign Classic (ACC) versions up to and including 7.4.4 build 9400 are vulnerable to an OS command injection flaw. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary code on the underlying system with the privileges of the application process. This vulnerability features a changed scope and does not require user interaction for successful exploitation.

Affected products:

  • Adobe Campaign Classic (<= 7.4.4 build 9400)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-76195

Related in this roundup: CVE-2026-27302, CVE-2026-71398, CVE-2026-76193, CVE-2026-76197.

CVE-2026-76197

Adobe Campaign Classic is vulnerable to an OS command injection flaw due to improper neutralization of special elements in user-supplied input. An unauthenticated remote attacker can exploit this vulnerability without user interaction to execute arbitrary code on the affected system with the privileges of the application process. This vulnerability is classified as a critical RCE.

Affected products:

  • Adobe Campaign Classic (<= 7.4.4 build 9400)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-76197

Related in this roundup: CVE-2026-27302, CVE-2026-71398, CVE-2026-76193, CVE-2026-76195.

CVE-2026-48417

Adobe Substance 3D Sampler is susceptible to a stack-based buffer overflow vulnerability that can be triggered when a user opens a specially crafted malicious file. Successful exploitation allows an attacker to achieve arbitrary code execution within the security context of the logged-in user, requiring user interaction to execute.

Affected products:

  • Substance 3D Sampler (<= 6.0.1)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-48417

Related in this roundup: CVE-2026-48419, CVE-2026-48421, CVE-2026-71382.

CVE-2026-48418

Adobe Substance 3D Sampler is vulnerable to an out-of-bounds write flaw, tracked as CVE-2026-48418. A remote attacker can exploit this by tricking a user into opening a specially crafted malicious file, which may result in arbitrary code execution within the context of the currently logged-in user.

Affected products:

  • Adobe Substance 3D Sampler (<= 6.0.1)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-48418

Related in this roundup: CVE-2026-48420, CVE-2026-48424.

CVE-2026-48419

Adobe Substance 3D Sampler is vulnerable to an out-of-bounds write flaw, identified as CVE-2026-48419. This vulnerability allows an attacker to execute arbitrary code in the context of the current user if the user is tricked into opening a specially crafted, malicious file. Successful exploitation requires user interaction.

Affected products:

  • Substance 3D Sampler (<= 6.0.1)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-48419

Related in this roundup: CVE-2026-48417, CVE-2026-48421, CVE-2026-71382.

CVE-2026-48420

Adobe Substance 3D Sampler versions 6.0.1 and earlier are vulnerable to an out-of-bounds write vulnerability. A remote attacker could exploit this by tricking a user into opening a maliciously crafted file, leading to arbitrary code execution in the context of the current user.

Affected products:

  • Adobe Substance 3D Sampler (<= 6.0.1)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-48420

Related in this roundup: CVE-2026-48418, CVE-2026-48424.

CVE-2026-48421

Adobe Substance 3D Sampler versions 6.0.1 and earlier are vulnerable to an out-of-bounds write flaw. An attacker can exploit this by enticing a user to open a specially crafted malicious file, leading to arbitrary code execution within the context of the user running the application.

Affected products:

  • Substance 3D Sampler (<= 6.0.1)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-48421

Related in this roundup: CVE-2026-48417, CVE-2026-48419, CVE-2026-71382.

CVE-2026-48424

Adobe Substance 3D Sampler versions 6.0.1 and earlier are vulnerable to a heap-based buffer overflow triggered by opening a specially crafted malicious file. Successful exploitation requires user interaction and can lead to arbitrary code execution within the context of the current user.

Affected products:

  • Adobe Substance 3D Sampler (<= 6.0.1)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-48424

Related in this roundup: CVE-2026-48418, CVE-2026-48420.

CVE-2026-48426

Adobe Substance 3D Designer versions 16.0.4 and earlier are vulnerable to an out-of-bounds write vulnerability that can lead to arbitrary code execution. The vulnerability is triggered when a user opens a specially crafted malicious file, necessitating user interaction. The flaw is categorized as an out-of-bounds write (CWE-787).

Affected products:

  • Adobe Substance 3D Designer (<= 16.0.4)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-48426

Related in this roundup: CVE-2026-48427, CVE-2026-48428, CVE-2026-48430, CVE-2026-48432, CVE-2026-48433, CVE-2026-71564.

CVE-2026-48427

Adobe Substance 3D Designer versions 16.0.4 and earlier are vulnerable to an out-of-bounds write flaw that allows for arbitrary code execution. Successful exploitation requires a user to open a specially crafted malicious file, which triggers the memory corruption in the context of the current user session.

Affected products:

  • Adobe Substance 3D Designer (<= 16.0.4)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-48427

Related in this roundup: CVE-2026-48426, CVE-2026-48428, CVE-2026-48430, CVE-2026-48432, CVE-2026-48433, CVE-2026-71564.

CVE-2026-48428

Adobe Substance 3D Designer versions 16.0.4 and earlier are vulnerable to a heap-based buffer overflow when processing a malicious file. Successful exploitation allows an attacker to execute arbitrary code in the context of the current user, provided the user interacts with the file.

Affected products:

  • Adobe Substance 3D Designer (<= 16.0.4)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-48428

Related in this roundup: CVE-2026-48426, CVE-2026-48427, CVE-2026-48430, CVE-2026-48432, CVE-2026-48433, CVE-2026-71564.

CVE-2026-48430

Adobe Substance 3D Designer versions 16.0.4 and earlier are vulnerable to a heap-based buffer overflow that can be triggered by enticing a user to open a specially crafted malicious file. Successful exploitation allows for arbitrary code execution within the context of the current user.

Affected products:

  • Adobe Substance 3D Designer (<= 16.0.4)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-48430

Related in this roundup: CVE-2026-48426, CVE-2026-48427, CVE-2026-48428, CVE-2026-48432, CVE-2026-48433, CVE-2026-71564.

CVE-2026-48432

Adobe Substance 3D Designer is susceptible to a heap-based buffer overflow vulnerability that can be triggered when a user opens a specially crafted malicious file. Successful exploitation of this flaw allows an attacker to execute arbitrary code within the security context of the current user.

Affected products:

  • Adobe Substance 3D Designer (<= 16.0.4)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-48432

Related in this roundup: CVE-2026-48426, CVE-2026-48427, CVE-2026-48428, CVE-2026-48430, CVE-2026-48433, CVE-2026-71564.

CVE-2026-48433

Adobe Substance 3D Designer versions up to and including 16.0.4 contain a heap-based buffer overflow vulnerability. Successful exploitation requires a user to open a specially crafted malicious file, which can lead to arbitrary code execution in the context of the current user.

Affected products:

  • Adobe Substance 3D Designer (<= 16.0.4)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-48433

Related in this roundup: CVE-2026-48426, CVE-2026-48427, CVE-2026-48428, CVE-2026-48430, CVE-2026-48432, CVE-2026-71564.

CVE-2026-71360

CAI Content Credentials, including the C2PA Tool and Content Credentials Rust SDK, is vulnerable to uncontrolled resource consumption. An unauthenticated attacker can trigger this vulnerability to exhaust system resources, resulting in a denial-of-service condition without requiring user interaction.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-71360

CVE-2026-71382

Adobe Substance 3D Sampler is vulnerable to an out-of-bounds write vulnerability (CWE-787) that allows a local attacker to achieve arbitrary code execution. The vulnerability is triggered when a user is convinced to open a maliciously crafted file, making the impact dependent on user interaction.

Affected products:

  • Substance 3D Sampler (<= 6.0.1)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-71382

Related in this roundup: CVE-2026-48417, CVE-2026-48419, CVE-2026-48421.

CVE-2026-71443

The CAI Content Credentials tools and SDK provided by Adobe contain an improper input validation vulnerability. An unauthenticated, remote attacker can exploit this flaw by sending specifically crafted input to the application, resulting in an application crash and denial-of-service condition without requiring user interaction.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-71443

CVE-2026-71564

Adobe Substance 3D Designer versions 16.0.4 and earlier are vulnerable to an out-of-bounds write vulnerability. A remote attacker can trigger this vulnerability by enticing a user to open a specially crafted malicious file, leading to arbitrary code execution in the context of the current user.

Affected products:

  • Adobe Substance 3D Designer (<= 16.0.4)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-71564

Related in this roundup: CVE-2026-48426, CVE-2026-48427, CVE-2026-48428, CVE-2026-48430, CVE-2026-48432, CVE-2026-48433.

CVE-2026-75749

Adobe Substance 3D Painter is vulnerable to an out-of-bounds write flaw (CWE-787) that can be triggered by convincing a user to open a specially crafted malicious file. Successful exploitation allows an attacker to execute arbitrary code with the privileges of the currently logged-in user.

Affected products:

  • Adobe Substance 3D Painter (<= 12.1.2)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-75749

Related in this roundup: CVE-2026-75750, CVE-2026-75770.

CVE-2026-75750

Adobe Substance 3D Painter versions 12.1.2 and earlier contain a heap-based buffer overflow vulnerability. Successful exploitation allows an attacker to achieve arbitrary code execution in the context of the current user by convincing a victim to open a specially crafted malicious file.

Affected products:

  • Adobe Substance 3D Painter (<= 12.1.2)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-75750

Related in this roundup: CVE-2026-75749, CVE-2026-75770.

CVE-2026-75766

Adobe Substance 3D Painter versions 12.1.2 and earlier are vulnerable to a heap-based buffer overflow triggered by opening a specially crafted malicious file. Successful exploitation allows an attacker to execute arbitrary code in the context of the current user. This requires user interaction to open the file.

Affected products:

  • Substance 3D Painter (<= 12.1.2)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-75766

Related in this roundup: CVE-2026-75768, CVE-2026-75769.

CVE-2026-75768

Adobe Substance 3D Painter is vulnerable to an untrusted search path flaw (CWE-426), allowing a local attacker to execute arbitrary code in the context of the current user. Exploitation requires user interaction, specifically the victim opening a maliciously crafted file.

Affected products:

  • Substance 3D Painter (<= 12.1.2)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-75768

Related in this roundup: CVE-2026-75766, CVE-2026-75769.

CVE-2026-75769

Adobe Substance 3D Painter is vulnerable to a heap-based buffer overflow due to improper validation of user-supplied input. An attacker can exploit this by enticing a user to open a specially crafted malicious file, potentially leading to arbitrary code execution within the context of the current user session.

Affected products:

  • Substance 3D Painter (<= 12.1.2)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-75769

Related in this roundup: CVE-2026-75766, CVE-2026-75768.

CVE-2026-75770

Adobe Substance 3D Painter versions 12.1.2 and earlier are vulnerable to an out-of-bounds write vulnerability. An attacker can exploit this by enticing a user to open a specially crafted malicious file, potentially leading to arbitrary code execution within the context of the current user.

Affected products:

  • Adobe Substance 3D Painter (<= 12.1.2)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-75770

Related in this roundup: CVE-2026-75749, CVE-2026-75750.