<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:adobe:commerce:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aadobecommerce/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 03 Sep 2026 19:22:39 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aadobecommerce/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Adobe Security Updates - September 2026</title><link>https://feed.craftedsignal.io/briefs/2026-09-adobe-security-updates/</link><pubDate>Thu, 03 Sep 2026 19:22:39 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-adobe-security-updates/</guid><description>Roundup of Adobe security advisories published in September 2026.</description><content:encoded><![CDATA[<p>This roundup covers 7 Adobe security vulnerabilities. All have a CVSS base score of 10.0. None are reported as actively exploited at the time of release. The issues affect Adobe Commerce, Campaign Classic, ColdFusion, Commerce, Experience Manager, Substance 3D Sampler.</p>
<h2 id="summary">Summary</h2>
<table>
	<thead>
			<tr>
					<th>CVE</th>
					<th>Product</th>
					<th>Severity</th>
					<th>CVSS</th>
					<th>EPSS</th>
					<th>KEV</th>
					<th>Source</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td><a href="#cve-2026-83959">CVE-2026-83959</a></td>
					<td>Substance 3D Sampler</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-83959">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-75650">CVE-2026-75650</a></td>
					<td>Adobe Commerce</td>
					<td>Critical</td>
					<td>10.0</td>
					<td>0.68%</td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-75650">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-76200">CVE-2026-76200</a></td>
					<td>Commerce</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-76200">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-76201">CVE-2026-76201</a></td>
					<td>Commerce</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-76201">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-82004">CVE-2026-82004</a></td>
					<td>Campaign Classic</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-82004">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-19232">CVE-2026-19232</a></td>
					<td>Experience Manager</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-19232">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-48273">CVE-2026-48273</a></td>
					<td>ColdFusion</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48273">NVD</a> (authoritative)</td>
			</tr>
	</tbody>
</table>
<h2 id="cve-2026-83959">CVE-2026-83959</h2>
<p>Adobe Substance 3D Sampler contains a heap-based buffer overflow vulnerability triggered by opening a malicious file. Successful exploitation allows an attacker to achieve arbitrary code execution in the context of the current user, requiring user interaction to open the crafted file.</p>
<p>Affected products:</p>
<ul>
<li>Substance 3D Sampler</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-83959">https://nvd.nist.gov/vuln/detail/CVE-2026-83959</a></p>
<h2 id="cve-2026-75650">CVE-2026-75650</h2>
<p>Adobe Commerce contains a vulnerability involving improper neutralization of special elements used in a template engine, which allows an unauthenticated attacker to execute arbitrary code. The vulnerability is categorized as remote code execution, does not require user interaction, and impacts the integrity and availability of the system.</p>
<p>Affected products:</p>
<ul>
<li>Adobe Commerce</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-75650">https://nvd.nist.gov/vuln/detail/CVE-2026-75650</a></p>
<h2 id="cve-2026-76200">CVE-2026-76200</h2>
<p>Adobe Commerce contains a stored Cross-Site Scripting (XSS) vulnerability allowing attackers to inject malicious JavaScript into form fields. When a victim accesses the affected page, the script executes within the victim's session, potentially leading to unauthorized account access or session hijacking.</p>
<p>Affected products:</p>
<ul>
<li>Commerce</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-76200">https://nvd.nist.gov/vuln/detail/CVE-2026-76200</a></p>
<p>Related in this roundup: <a href="#cve-2026-76201">CVE-2026-76201</a>.</p>
<h2 id="cve-2026-76201">CVE-2026-76201</h2>
<p>Adobe Commerce contains a stored Cross-Site Scripting (XSS) vulnerability allowing an attacker to inject malicious scripts into form fields. When a victim accesses the affected page, the script executes in their browser, potentially leading to session hijacking or unauthorized account access.</p>
<p>Affected products:</p>
<ul>
<li>Commerce</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-76201">https://nvd.nist.gov/vuln/detail/CVE-2026-76201</a></p>
<p>Related in this roundup: <a href="#cve-2026-76200">CVE-2026-76200</a>.</p>
<h2 id="cve-2026-82004">CVE-2026-82004</h2>
<p>Adobe Campaign Classic (ACC) is vulnerable to an OS command injection flaw (CVE-2026-82004) that allows unauthenticated attackers to achieve remote code execution in the context of the current user without requiring user interaction. The vulnerability has a CVSS v3.1 base score of 10.0 and involves a changed scope, indicating potential impact beyond the affected service.</p>
<p>Affected products:</p>
<ul>
<li>Campaign Classic</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-82004">https://nvd.nist.gov/vuln/detail/CVE-2026-82004</a></p>
<h2 id="cve-2026-19232">CVE-2026-19232</h2>
<p>Adobe Experience Manager is vulnerable to an incorrect authorization flaw that allows a low-privileged attacker to achieve arbitrary code execution. The vulnerability does not require user interaction and can result in the attacker gaining elevated access or control over a victim's session, leading to a full compromise of the affected account scope.</p>
<p>Affected products:</p>
<ul>
<li>Experience Manager</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-19232">https://nvd.nist.gov/vuln/detail/CVE-2026-19232</a></p>
<h2 id="cve-2026-48273">CVE-2026-48273</h2>
<p>Adobe ColdFusion is vulnerable to an improper neutralization of directives in dynamically evaluated code (Eval Injection), which allows a low-privileged attacker to achieve remote code execution without user interaction. The vulnerability results in a change of scope, significantly increasing the impact of successful exploitation.</p>
<p>Affected products:</p>
<ul>
<li>ColdFusion</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48273">https://nvd.nist.gov/vuln/detail/CVE-2026-48273</a></p>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>roundup</category></item></channel></rss>