Adobe's September 2026 Patch Tuesday Fixes 170+ Flaws Across Experience Manager, ColdFusion & More
Adobe patched over 170 vulnerabilities this cycle, led by 107 in Experience Manager and critical RCEs in ColdFusion and Campaign Classic.
Latest updates from the world of IT and cybersecurity
Search all news articles
Adobe patched over 170 vulnerabilities this cycle, led by 107 in Experience Manager and critical RCEs in ColdFusion and Campaign Classic.
Chainguard doubled its build volume to over 1 billion manifests in six months, powered by an automated factory rebuilding images at scale.
A stealthy Linux rootkit dubbed PoisonedRefresh hooks PHP on F5 BIG-IP APM webtop servers to run in-memory web shells that leave disk files untouched.
September's Patch Tuesday breaks records with 974 CVEs fixed, including two actively exploited Windows zero-days now on CISA's KEV catalog.
An exposed Advance Passenger Information System database held 220 million passport and flight records spanning 2017-2026, researchers say.
A max-severity Magento/Adobe Commerce zero-day, StyleSmuggler, has been exploited since September 4 to plant Linux backdoors on live stores.
Chainguard's container image factory doubled its rebuild output from 500 million to over 1 billion manifests, driven by a new agentic pipeline.
Grindr will pay £26M to settle a UK High Court claim by 12,000 users alleging HIV status and PrEP data was shared with advertisers pre-2020.
Sophos found a stealthy Linux rootkit hooking PHP on F5 BIG-IP APM servers to inject memory-only web shells, leaving disk files untouched.