.

Adobe Security Bulletin

Last updated on Sep 22, 2026

Security updates available for Content Credentials SDK | APSB26-147

Bulletin ID
Date published
Priority
APSB26-147
September 22, 2026
3

Summary

Adobe has released a security update for Content Credentials SDK. This update addresses critical and important vulnerabilities that could result in security feature bypass and application denial-of-service.

Adobe is not aware of any exploits in the wild for any of the issues addressed in this update.

Affected versions

Product
Affected version
Platform
Content Credentials Rust SDK
c2pa-v0.89.2 and earlier
All
C2PA Tool
c2patool-v0.26.70 and earlier
All

Solution

Adobe categorizes these updates with the following priority rating and recommends users update their installation to the newest version:

Product
Updated version
Platform
Priority rating
Availability
Content Credentials Rust SDK
c2pa-v0.90.17
All
3
C2PA Tool
c2patool-v0.27.17
All
3

Vulnerability Details

Vulnerability category
Vulnerability impact
Severity
CVSS base score
CVSS vector
CVE number
Improper Input Validation (CWE-20)
Security feature bypass
Critical
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVE-2026-19480
Uncontrolled Resource Consumption (CWE-400)
Application denial-of-service
Critical
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVE-2026-75632
Improper Input Validation (CWE-20)
Security feature bypass
Important
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
CVE-2026-75638
Improper Input Validation (CWE-20)
Application denial-of-service
Important
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVE-2026-75633
Integer Overflow or Wraparound (CWE-190)
Application denial-of-service
Important
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVE-2026-89277
Improper Input Validation (CWE-20)
Security feature bypass
Important
4.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
CVE-2026-75634
Improper Input Validation (CWE-20)
Security feature bypass
Important
4.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
CVE-2026-76194

Acknowledgments

Adobe would like to thank the following researchers for reporting this issue and for working with Adobe to help protect our customers.

  • Geo-VIE (gvfx) — CVE-2026-19480
  • rootdaddy (r00tdaddy) — CVE-2026-75632
  • mars (marsduk) — CVE-2026-75638
  • bau1u — CVE-2026-75633, CVE-2026-89277
  • susdrip — CVE-2026-75634
  • 0x0.eth (0x0doteth) — CVE-2026-76194