Adobe Issues 12 Security Advisories Addressing 89 Vulnerabilities Across Multiple Products
Adobe has published 12 security advisories addressing a combined total of 89 vulnerabilities across multiple products and SDKs. The release occurred on July 14, 2026, coinciding with the regular monthly Patch Tuesday cycle.
The advisories cover Adobe ColdFusion, Adobe Commerce, Adobe Experience Manager, Adobe Illustrator, and additional applications such as Audition, Premiere Pro, After Effects, Animate, Media Encoder, Bridge, and the Creative Cloud Desktop Application, along with the Content Credentials SDK.
All vulnerabilities are rated at the highest severity level of Critical. Several flaws in Adobe ColdFusion, Adobe Commerce, Adobe Experience Manager, and Adobe Illustrator carry CVSS v3.1 base scores of 9.0 or above.
Adobe ColdFusion received the highest remediation priority rating of 1, with a recommended response window of 72 hours. Adobe Commerce was assigned priority 2, indicating a 30-day update target. All other products were given priority 3, allowing updates at any convenient time.
No exploitation of the disclosed vulnerabilities had been confirmed at the time of publication.
Affected Products and CVE Identifiers
Adobe ColdFusion (13 CVEs): CVE-2026-48284, CVE-2026-48318, CVE-2026-48319, CVE-2026-48320, CVE-2026-48321, CVE-2026-48322, CVE-2026-48324, CVE-2026-48325, CVE-2026-48327, CVE-2026-48328, CVE-2026-48329, CVE-2026-48332, CVE-2026-48338.
Adobe Commerce (15 CVEs): CVE-2026-47984, CVE-2026-47988, CVE-2026-47992, CVE-2026-47994, CVE-2026-47995, CVE-2026-47996, CVE-2026-47997, CVE-2026-47998, CVE-2026-47999, CVE-2026-48000, CVE-2026-48001, CVE-2026-48356, CVE-2026-48358, CVE-2026-48371.
Adobe Experience Manager (13 CVEs) and additional CVEs for Audition, Premiere Pro, After Effects, Animate, Illustrator, Media Encoder, Bridge, Creative Cloud Desktop Application, and Content Credentials SDK complete the list of 89 vulnerabilities.
Related articles
Gitea Authentication Bypass Exposes Private Repositories Through Default Docker Reverse Proxy Setting
A critical authentication bypass vulnerability in Gitea, tracked as CVE-2026-20896 with a CVSS score of 9.8, allows attackers to gain administrative access and read private repositories by sending a single HTTP header. The root cause lies in the official Docker image defaulting the REVERSE_PROXY_TRUSTED_PROXIES setting to a wildcard, trusting the X-WEBAUTH-USER header from any source when reverse-proxy authentication is enabled. The researcher reproduced the full attack on a live vulnerable instance, demonstrating how an unauthenticated request could retrieve secret files such as .env containing database passwords and cloud keys. Multiple related access-control flaws were also disclosed in the same year, including CVE-2026-27771 affecting the container registry, CVE-2026-22874 in webhooks, and CVE-2026-28740 in LFS handling. The recommended fix involves explicitly setting trusted proxy IPs or disabling reverse-proxy authentication entirely and upgrading to version 1.26.4 or later. The issue highlights recurring problems with overly permissive defaults in self-hosted DevOps tools.
Windows Lacks Official Patch for LegacyHive Zero-Day; 0Patch Delivers Free Micro-Patch
A zero-day vulnerability named LegacyHive has been discovered in the Windows user profile service, allowing any standard user to mount another user's registry hive with full access. The flaw was reported on July 14 by researcher Nightmare Eclipse, coinciding with Microsoft's Patch Tuesday, and enables extraction of stored secrets or persistence by modifying registry settings that execute code on the next administrator login. Microsoft has acknowledged the issue and is investigating, but no official fix has been released yet. ACROS Security stepped in with a free micro-patch through its 0Patch platform that neutralizes the exploit by redirecting it to a harmless temporary hive instead of the administrator profile. The protection is available for Windows 10 version 2004 and later, as well as Windows Server 2022 and newer releases, and requires only registration and agent installation without a reboot. Researchers Will Dormann and Kevin Beaumont have independently confirmed the exploit's functionality, with Beaumont also publishing Microsoft Defender for Endpoint queries to detect related attacks.
WordPress Releases Security Update Fixing Two Vulnerabilities That Chain to Remote Code Execution
The WordPress development team has issued version 7.0.2 along with other security releases on July 17, 2026, addressing two critical vulnerabilities identified as CVE-2026-63030 and CVE-2026-60137. When combined, these flaws enable remote attackers to execute arbitrary code on affected installations. CVE-2026-60137 stems from insufficient input validation in certain functions, potentially allowing SQL injection when processing untrusted data from plugins or themes. CVE-2026-63030 involves route interpretation confusion in the REST API batch endpoint, which can be leveraged alongside the SQL injection issue to achieve code execution. The vulnerabilities impact WordPress 6.8 and later branches, although chained attacks are not possible on the 6.8 series. Administrators are urged to apply the updates immediately to mitigate the risks.
Weekly Roundup Highlights Critical Vulnerabilities in Zoom, nginx, SonicWall, and Microsoft Products
Security NEXT published its weekly ranking of the most-read articles for the period of July 12 to July 18, 2026. The top story covered a serious vulnerability in the Windows version of Zoom that has already been fixed in the latest release. Other high-ranking items included a cyber attack that disrupted operations at Nichirei and affected frozen food shipments, as well as Microsoft’s monthly security update addressing more than 500 vulnerabilities including zero-days. Additional widely read reports detailed multiple flaws in nginx, a zero-day issue affecting SonicWall SMA1000 series appliances, and a data exposure investigation involving a TV Asahi subsidiary. The list also featured advisories on GNU Wget SSRF flaws, privilege escalation bugs in Microsoft Defender, and 15 security fixes for Chrome including two rated critical.