Adobe security advisory (AV26-888) – Update 1
At a glance
- Severity
- Medium
- Used in attacks
- No flaws named
- Vendors and products
- Adobe
- Industries
- Retail & e-commerce
- Reported by
- 1 outlet
As of September 8, 2026, Adobe is affected by a vulnerability in the following products:
- Adobe Acrobat
- Multiple versions
- Adobe Animate 2023
- Prior to or equal to 2023.0.16
- Adobe Animate 2024
- Prior to or equal to 0.14
- Adobe Campaign Classic
- Prior to or equal to ACC v7: 7.4.4 build 9401
- Adobe ColdFusion 2023
- Prior to or equal to 2023.0.23
- Adobe ColdFusion 2025
- Prior to or equal to 0.12
- Adobe Commerce
- All except Hotfix for CVE-2026-7565
- Prior to or equal to 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug
- Adobe Commerce B2B
- All except Hotfix for CVE-2026-7565
- Prior to or equal to 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug
- Adobe Experience Manager (AEM)
- Prior to or equal to AEM Cloud Service (CS) Release 2026.7.0
- Prior to or equal to 5 LTS Service Pack 2
- Prior to or equal to 5 Service Pack 24 and earlier
- Adobe Illustrator 2025
- Prior to or equal to 8.10
- Adobe Illustrator 2026
- Prior to or equal to 7
- Adobe Photoshop 2025
- Prior to or equal to 11.6
- Adobe Photoshop 2026
- Prior to or equal to 6
- Magento Open Source
- All except Hotfix for CVE-2026-7565
- Prior to or equal to 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug
Adobe indicates that CVE-2026-75650 is exploited in the wild.
Update 1
On September 8, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-75650 to their Known Exploited Vulnerabilities (KEV) Database.
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Reproduced in full under licence from Canadian Centre for Cyber Security. © Canadian Centre for Cyber Security. Written by Canadian Centre for Cyber Security.
Coverage
One outlet has carried this so far.
2026-09-08 18:57 UTC
Related stories
- Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
The Hacker News · 2026-09-16
- Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
The Hacker News · 2026-09-16
- PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug
Infosecurity Magazine · 2026-09-16
- Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
The Hacker News · 2026-09-16
- Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix
The Hacker News · 2026-09-16