Adobe Issues 12 Security Advisories Addressing 89 Vulnerabilities Across Multiple Products
Adobe has published 12 security advisories addressing a combined total of 89 vulnerabilities across multiple products and SDKs. The release occurred on July 14, 2026, coinciding with the regular monthly Patch Tuesday cycle.
The advisories cover Adobe ColdFusion, Adobe Commerce, Adobe Experience Manager, Adobe Illustrator, and additional applications such as Audition, Premiere Pro, After Effects, Animate, Media Encoder, Bridge, and the Creative Cloud Desktop Application, along with the Content Credentials SDK.
All vulnerabilities are rated at the highest severity level of Critical. Several flaws in Adobe ColdFusion, Adobe Commerce, Adobe Experience Manager, and Adobe Illustrator carry CVSS v3.1 base scores of 9.0 or above.
Adobe ColdFusion received the highest remediation priority rating of 1, with a recommended response window of 72 hours. Adobe Commerce was assigned priority 2, indicating a 30-day update target. All other products were given priority 3, allowing updates at any convenient time.
No exploitation of the disclosed vulnerabilities had been confirmed at the time of publication.
Affected Products and CVE Identifiers
Adobe ColdFusion (13 CVEs): CVE-2026-48284, CVE-2026-48318, CVE-2026-48319, CVE-2026-48320, CVE-2026-48321, CVE-2026-48322, CVE-2026-48324, CVE-2026-48325, CVE-2026-48327, CVE-2026-48328, CVE-2026-48329, CVE-2026-48332, CVE-2026-48338.
Adobe Commerce (15 CVEs): CVE-2026-47984, CVE-2026-47988, CVE-2026-47992, CVE-2026-47994, CVE-2026-47995, CVE-2026-47996, CVE-2026-47997, CVE-2026-47998, CVE-2026-47999, CVE-2026-48000, CVE-2026-48001, CVE-2026-48356, CVE-2026-48358, CVE-2026-48371.
Adobe Experience Manager (13 CVEs) and additional CVEs for Audition, Premiere Pro, After Effects, Animate, Illustrator, Media Encoder, Bridge, Creative Cloud Desktop Application, and Content Credentials SDK complete the list of 89 vulnerabilities.
Related articles
Researchers Expose GPON Optical Network Eavesdropping via Modified ONU Devices at DEF CON
At DEF CON 34, two researchers demonstrated how inexpensive hardware modifications allow interception of downstream traffic in GPON fiber networks shared among multiple subscribers. The passive optical design means all clients connected to the same splitter receive identical data streams, with separation handled only at the ONU level through 12-bit GEM port identifiers. By acquiring Realtek RTL960x-based SFP modules and systematically bypassing built-in restrictions on GEM port reassignment, VLAN tagging, switch forwarding, and checksum validation, the team achieved access to traffic intended for up to 128 neighboring users. Exposed data includes DNS queries that can reveal occupancy patterns, unencrypted SIP voice traffic, and in some cases traffic from nearby cellular base stations. The researchers also identified exploitable vulnerabilities in the VSOL G100S OLT device that could grant root-level control and compromise provider routers. Additional coverage in the same Kaspersky report examined Head Mare's compromise of TrueConf servers, EvilFontTool font-based evasion, an OpenAI presentation on an accidental AI attack against Hugging Face, and the SCTPhantom Linux kernel flaw present for 18 years.
WordPress Patches High-Severity XSS2Shell Flaw Enabling Remote Code Execution (CVE-2026-64638)
WordPress has released a fix for a high-severity vulnerability in its core that can turn a malicious login attempt into remote PHP code execution on the server. The flaw, tracked as CVE-2026-64638 and rated 8.9 on CVSS, is named XSS2Shell and begins as a reflected cross-site scripting issue on the authentication screen. An unauthenticated attacker can submit a specially crafted username that bypasses sanitization mechanisms due to differences in how PHP and WordPress interpret certain characters, allowing controlled HTML elements to be injected into the login page. This leads to JavaScript execution in the site domain, and when an authenticated administrator visits a prepared page, the attacker can abuse the existing session to authorize application credentials and upload arbitrary PHP code. The patch is included in WordPress 7.0.3 released on August 6, with backports available for branches as old as 4.7. No public exploitation has been confirmed yet, but the technical details make immediate updating a priority for site administrators.
Google Releases Chrome 151 Fixing 41 Vulnerabilities Including Six Critical Flaws
Google has issued Chrome 151 to address 41 security vulnerabilities, six of which are rated critical and could lead to memory corruption, browser crashes, and remote code execution. The update covers Windows, macOS, and Linux platforms with versions 151.0.7922.108 and 151.0.7922.109. Two use-after-free flaws in the WebGL component, tracked as CVE-2026-19137 and CVE-2026-19170, allow continued memory access after deallocation. Additional critical issues affect the Aura, Skia, Views, and ANGLE components under CVE-2026-19149, CVE-2026-19154, CVE-2026-19172, and CVE-2026-19157. Google has withheld technical details and proof-of-concept code for several flaws to limit exploitation while the rollout completes. Users are advised to check for updates immediately through the browser's About section.
Dell Fixes 70 Vulnerabilities in VSI for VMware vSphere Including Two Critical Flaws
Dell has released an update addressing 70 vulnerabilities in Dell Virtual Storage Integrator for VMware vSphere Client, two of which are product-specific and rated critical. The advisory published on August 6, 2026, covers both native issues and flaws inherited from third-party components. CVE-2026-67261 allows unauthenticated remote attackers to execute arbitrary OS commands with root privileges via the IAPI component. CVE-2026-54489 enables session hijacking by exposing active session credentials without authentication. The product integrates Dell storage arrays with VMware vSphere environments and is widely used in enterprise virtualization deployments. Administrators are urged to apply the latest version immediately to mitigate the risks of full system compromise and unauthorized administrative access.