APSB26-151
Priority 2 Security update
9/22/2026- Content Credentials SDK
APSB26-147
Priority 3 Security update
9/22/2026 APSB26-155
Priority 3 Security update
9/22/2026Bridge
APSB26-148
Priority 3 Security update
9/22/2026Connect
APSB26-150
Priority 2 Security update
9/22/2026APSB26-157
Priority 3 Security update
9/22/2026InDesign
APSB26-145
Priority 3 Security update
9/22/2026- Magento Commerce
APSB26-138
Priority 2 Security update
9/8/2026 Adobe Experience Manager
APSB26-98
Priority 2 Security update
9/8/2026Photoshop
APSB26-130
Priority 3 Security update
9/8/2026Illustrator
APSB26-131
Priority 3 Security update
9/8/2026Animate
APSB26-132
Priority 3 Security update
9/8/2026Photoshop
APSB26-136
Priority 3 Security update
9/8/2026Adobe Campaign
APSB26-142
Priority 1 Security update
9/8/2026ColdFusion
APSB26-119
Priority 1 Security update
9/8/2026Acrobat
APSB26-141
Priority 2 Security update
9/8/2026- Magento Commerce
APSB26-146
Priority 1 Security update
9/7/2026 APSB26-115
Priority 3 Security update
8/25/2026APSB26-121
Priority 3 Security update
8/25/2026Adobe Campaign
APSB26-134
Priority 1 Security update
8/25/2026Illustrator
APSB26-124
Priority 3 Security update
8/25/2026APSB26-129
Priority 3 Security update
8/25/2026XD
APSB26-125
Priority 3 Security update
8/25/2026- Content Credentials SDK
APSB26-110
Priority 3 Security update
8/25/2026 Adobe Campaign
APSB26-123
Priority 1 Security update
8/11/2026ColdFusion
APSB26-90
Priority 1 Security update
8/11/2026- Content Credentials SDK
APSB26-111
Priority 3 Security update
8/11/2026
Last Updated: September 22, 2026
Stay up to date by subscribing to receive notifications.
Bulletins and advisories
Priority ratings
The Adobe Priority Rating System helps customers in managed environments prioritize the deployment of Adobe security updates based on Adobe's assessment of exploitability. Each priority rating signals how likely a vulnerability is to be exploited and how quickly customers should apply the update, taking into account historical attack patterns for the relevant product, the nature of the vulnerability, the platform(s) affected, and any mitigations already in place.
Priority 1
Act as soon as possible (within 72 hours).
This update resolves vulnerabilities that are being actively exploited or are at higher risk of exploitation for the given product and platform.
Priority 2
Act within 30 days.
This update addresses vulnerabilities with a high likelihood of exploitation based on the nature of the vulnerability, the product's history, and the platform affected. There are currently no known active exploits.
Priority 3
Act at your admin’s discretion.
This update addresses vulnerabilities where active exploitation is unlikely based on the product’s history and nature of the vulnerability. There are currently no known active exploits.
Severity ratings
Adobe rates the severity of CVE's using the Common Vulnerability Scoring System version 3.1 (CVSS v3.1). Each CVE is assigned a CVSS score from 0.1 to 10.0, a corresponding severity rating, and a CVSS vector string. The CVSS scores and ratings are as follows:
Critical
CVSS Score: 9.0 – 10.0
High
CVSS Score: 7.0 – 8.9
Medium
CVSS Score: 4.0 – 6.9
Low
CVSS Score: 0.1 – 3.9
Legacy severity ratings
The following severity ratings applied to bulletins published before October 2026. Bulletins from October 2026 onward use the CVSS severity ratings above.
Critical
A vulnerability, which, if exploited would allow malicious native-code to execute, potentially without a user being aware.
Important
A vulnerability, which, if exploited would compromise data security, potentially allowing access to confidential data, or could compromise processing resources.
Moderate
A vulnerability that is limited to a significant degree by factors such as default configuration, auditing, or is difficult to exploit.
How to report a security issue to Adobe.
If you need to report a security issue, please use the appropriate contact points outlined below.
Our team of security experts strives to quickly address security issues involving our products and services.
*This email should only be used to report security vulnerabilities in Adobe products.
*This email should only be used to report security vulnerabilities in Adobe products.