Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2724+ Articles
166+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Adobe's September 2026 Patch Tuesday Fixes 170+ Flaws Across Experience Manager, ColdFusion & More
Adobe's September 2026 Patch Tuesday Fixes 170+ Flaws Across Experience Manager, ColdFusion & More
NEWS

Adobe's September 2026 Patch Tuesday Fixes 170+ Flaws Across Experience Manager, ColdFusion & More

Adobe patched over 170 vulnerabilities this cycle, led by 107 in Experience Manager and critical RCEs in ColdFusion and Campaign Classic.

Dylan H.

News Desk

September 9, 2026
3 min read

A Big Rollup, Led by Experience Manager

Adobe's September 2026 security update round shipped fixes for more than 170 vulnerabilities spread across its product line — one of the larger Patch Tuesday batches this year. The lion's share sits in Adobe Experience Manager, which alone accounts for 107 vulnerabilities patched this cycle, followed by 32 flaws in Acrobat/Acrobat Reader, plus smaller counts in Photoshop (8), Illustrator (3), Animate (1), and Photoshop Mobile.

While the batch already includes the actively-exploited Adobe Commerce/Magento "StyleSmuggler" zero-day (CVE-2026-75650) covered separately on Labs, this cycle's real breadth is in the products that don't usually make headlines.

Two Critical RCEs in ColdFusion

Adobe ColdFusion picked up two critical remote-code-execution fixes:

CVECVSSType
CVE-2026-482739.9Code execution
CVE-2026-757469.1Code execution

Adobe also patched seven additional high/medium-severity ColdFusion issues in the same update.

Campaign Classic: A Perfect 10

Adobe Campaign Classic received a fix for CVE-2026-82004, an OS command injection vulnerability rated a maximum CVSS 10.0 — the top score on the scale. A flaw at that severity, paired with command injection, typically means unauthenticated network-based code execution with no meaningful mitigating factors in the vector string.

Commerce: Nine More Fixes Beyond the Zero-Day

Beyond the already-exploited StyleSmuggler bug, Adobe Commerce/Magento picked up eight additional vulnerabilities in this cycle: two critical privilege-escalation flaws and six high-severity security-bypass issues. Commerce administrators patching this cycle should treat it as a full update, not a single-CVE fix.

Remediation Guidance

Adobe's own release notes classify most of this batch as Priority 1, meaning administrators are expected to apply updates within three days of release. For Commerce specifically, Adobe is also recommending a credential rotation pass — encryption keys, database passwords, integration tokens, OAuth secrets, and API keys — at the source systems, not just inside the Commerce admin panel, given how many separate Commerce-adjacent flaws have surfaced this quarter.

Priority checklist:

  1. Patch Experience Manager instances first given the sheer volume of fixes (107) — prioritize any AEM instance exposed to the internet.
  2. Apply the ColdFusion critical RCE fixes (CVE-2026-48273, CVE-2026-75746) on any server running ColdFusion-based applications.
  3. Patch Campaign Classic immediately given the CVSS 10.0 OS command injection (CVE-2026-82004).
  4. Confirm Commerce/Magento stores are current on both the StyleSmuggler zero-day fix and this cycle's additional nine vulnerabilities, then rotate credentials.
  5. Roll out Acrobat/Acrobat Reader updates fleet-wide — 32 fixes is a large batch for client-side software with broad deployment.

References

  • SecurityWeek — Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day

Related Reading

  • CVE-2026-75650: StyleSmuggler Zero-Day Grants Unauthenticated RCE in Adobe Commerce & Magento
#Adobe#Patch Tuesday#Experience Manager#ColdFusion#Campaign Classic#Acrobat

Related Articles

Adobe Patches Three CVSS 10.0 Flaws in ColdFusion and Campaign Classic

Adobe's August 2026 patch cycle fixes 3 maximum-severity RCE vulnerabilities across ColdFusion and Campaign Classic. Priority 1 — patch within 72 hours.

4 min read

CVE-2026-47928: Adobe ColdFusion Critical RCE — CVSS 9.6

Adobe ColdFusion 2023.19 and 2025.8 are affected by a critical improper input validation flaw enabling unauthenticated remote code execution with scope change.

2 min read

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Adobe has patched a maximum-severity vulnerability in Campaign Classic (ACC), its enterprise marketing automation platform. The flaw carries a perfect CVSS score of 10.0 and allows unauthenticated remote code execution with no user interaction required.

4 min read
Back to all News