Skip to main content

Alert GCSA-26208 - Adobe Security Bulletin - settembre 2026


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

******************************************************************

   alert ID: GCSA-26208
       data: 9 settembre 2026
     titolo: Adobe Security Bulletin - settembre 2026

******************************************************************

:: Descrizione del problema

   Adobe ha rilasciato i seguenti aggiornamenti di sicurezza
   con i quali risolve oltre 170 vulnerabilita'.

   APSB26-98 Security updates available for Adobe Experience Manager
   APSB26-119 Security updates available for Adobe ColdFusion
   APSB26-130 Security update available for Adobe Photoshop
   APSB26-131 Security Updates Available for Adobe Illustrator
   APSB26-132 Security updates available for Adobe Animate
   APSB26-136 Security update available for Adobe Photoshop Mobile
   APSB26-138 Security update available for Adobe Commerce
   APSB26-141 Security update available for Adobe Acrobat Reader
   APSB26-142 Security update available for Adobe Campaign Classic
   APSB26-146 Security update available for Adobe Commerce

   La vulnerabilita' CVE-2026-75650 (CVSS v3.1 score 10.0) e' attualmente oggetto di sfruttamento.
   Si tratta di una vulnerabilita' di tipo RCE presente in Adobe Commerce, Adobe Commerce B2B e Magento Open Source.

   Maggiori informazioni sono disponibili alla sezione "Riferimenti".


:: Software interessato

   Adobe Experience Manager (AEM)
   Adobe ColdFusion
   Adobe Photoshop
   Adobe Illustrator
   Adobe Animate
   Adobe Photoshop Mobile
   Adobe Commerce
   Adobe Acrobat Reader
   Adobe Campaign Classic


:: Impatto

   Esecuzione remota di codice arbitrario (RCE)
   Rivelazione di informazioni (ID)
   Denial of Service (DoS)
   Acquisizione di privilegi piu' elevati (EoP)
   Bypass delle funzionalita' di sicurezza (SFB)
   Cross-site Scripting (XSS)
   Attacco all'integrita' dei dati (Data Manipulation)


:: Soluzioni

   Aggiornare i prodotti alle versioni piu' recenti.

   Adobe Experience Manager (AEM) AEM Cloud Service (CS) Release 2026.8.0
   Adobe Experience Manager (AEM) 6.5 LTS Service Pack 3
   Adobe Experience Manager (AEM) 6.5 Service Pack 25

   ColdFusion 2025 2025.0.13
   ColdFusion 2023 2023.0.24

   Photoshop 2026 27.7
   Photoshop 2025 26.11.7

   Illustrator 2025 29.8.11
   Illustrator 2026 30.8

   Adobe Animate 2023 23.0.17
   Adobe Animate 2024 24.0.15

   Photoshop Mobile 1.7.0.2302

   Adobe Commerce
   2.4.9-2026-sep
   2.4.8-2026-sep
   2.4.7-2026-sep
   2.4.6-2026-sep
   2.4.5-2026-sep
   2.4.4-2026-sep

   Adobe Commerce B2B
   1.5.3-2026-sep
   1.5.2-2026-sep
   1.4.2-2026-sep
   1.3.4-2026-sep
   1.3.3-2026-sep

   Magento Open Source
   2.4.9-2026-sep
   2.4.8-2026-sep
   2.4.7-2026-sep

   Adobe Commerce e Magento Open Source applicare Hotfix per CVE-2026-75650

   Adobe Acrobat Continuous 26.002.21901
   Acrobat Reader Continuous 26.002.21901
   Acrobat 2024 Classic 2024 24.001.30429

   Adobe Campaign Classic ACC v7 7.4.4 build 9402


:: Riferimenti

   Adobe Security Bulletins e Advisories
   https://helpx.adobe.com/security.html/security/security-bulletin.html
   https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html
   https://helpx.adobe.com/security/products/coldfusion/apsb26-119.html
   https://helpx.adobe.com/security/products/photoshop/apsb26-130.html
   https://helpx.adobe.com/security/products/illustrator/apsb26-131.html
   https://helpx.adobe.com/security/products/animate/apsb26-132.html
   https://helpx.adobe.com/security/products/photoshop/apsb26-136.html
   https://helpx.adobe.com/security/products/magento/apsb26-138.html
   https://helpx.adobe.com/security/products/acrobat/apsb26-141.html
   https://helpx.adobe.com/security/products/campaign/apsb26-142.html
   https://helpx.adobe.com/security/products/magento/apsb26-146.html
   https://experienceleague.adobe.com/en/docs/commerce-knowledge-base/kb/announcements/commerce-apsb26-146

   SecurityWeek
   https://www.securityweek.com/adobe-patches-over-170-vulnerabilities-including-commerce-zero-day/
   https://www.securityweek.com/adobe-commerce-zero-day-exploited-to-backdoor-online-stores/

   Mitre CVE
   I riferimenti CVE sono disponibili nell'advisory originale.


GARR CERT Security Alert - subscribe/unsubscribe:
http://www.cert.garr.it/alert/ricevi-gli-alert-di-cert

-----BEGIN PGP SIGNATURE-----

iF0EAREIAB0WIQTGpdiR5MqstacBGHbBnEyTZRJgQgUCaqEfsgAKCRDBnEyTZRJg
Qn1sAKDYSsTIqXv7A2evAi5O0/TzP6IQMACfVo4Bc9SJonHutxc1boEY28N8LSs=
=Rbaw
-----END PGP SIGNATURE-----

 

Alert di GARR-CERT Usata per la segnalazione di allarmi di sicurezza e comunicazioni di interesse generale diretti agli enti GARR. L'iscrizione è aperta e consigliata a tutti, il posting è riservato ai membri di GARR-CERT