Content as a Service v3 - Security Bulletins - Thursday, August 27, 2026 at 11:19
Last Updated: September 22, 2026
Stay up to date by subscribing to receive notifications.
Bulletins and advisories
Priority ratings
The Adobe Priority Rating System helps customers in managed environments prioritize the deployment of Adobe security updates based on Adobe's assessment of exploitability. Each priority rating signals how likely a vulnerability is to be exploited and how quickly customers should apply the update, taking into account historical attack patterns for the relevant product, the nature of the vulnerability, the platform(s) affected, and any mitigations already in place.
Priority 1
Act as soon as possible (within 72 hours).
This update resolves vulnerabilities that are being actively exploited or are at higher risk of exploitation for the given product and platform.
Priority 2
Act within 30 days.
This update addresses vulnerabilities with a high likelihood of exploitation based on the nature of the vulnerability, the product's history, and the platform affected. There are currently no known active exploits.
Priority 3
Act at your admin’s discretion.
This update addresses vulnerabilities where active exploitation is unlikely based on the product’s history and nature of the vulnerability. There are currently no known active exploits.
Severity ratings
Adobe rates the severity of CVE's using the Common Vulnerability Scoring System version 3.1 (CVSS v3.1). Each CVE is assigned a CVSS score from 0.1 to 10.0, a corresponding severity rating, and a CVSS vector string. The CVSS scores and ratings are as follows:
Critical
CVSS Score: 9.0 – 10.0
High
CVSS Score: 7.0 – 8.9
Medium
CVSS Score: 4.0 – 6.9
Low
CVSS Score: 0.1 – 3.9
Legacy severity ratings
The following severity ratings applied to bulletins published before October 2026. Bulletins from October 2026 onward use the CVSS severity ratings above.
Critical
A vulnerability, which, if exploited would allow malicious native-code to execute, potentially without a user being aware.
Important
A vulnerability, which, if exploited would compromise data security, potentially allowing access to confidential data, or could compromise processing resources.
Moderate
A vulnerability that is limited to a significant degree by factors such as default configuration, auditing, or is difficult to exploit.
How to report a security issue to Adobe.
If you need to report a security issue, please use the appropriate contact points outlined below.
Our team of security experts strives to quickly address security issues involving our products and services.
*This email should only be used to report security vulnerabilities in Adobe products.
*This email should only be used to report security vulnerabilities in Adobe products.