Adobe Security Bulletin
Last updated on Jun 9, 2026
Security update available for Adobe Dreamweaver | APSB26-62
Summary
Adobe has released a security update for Adobe Dreamweaver. This update resolves critical and important vulnerabilities that could lead to arbitrary code execution, memory exposure, and arbitrary file system read.
Adobe is not aware of any exploits in the wild for any of the issues addressed in these updates.
Affected versions
Solution
Adobe categorizes this update with the following priority rating and recommends users to use latest builds for new installation via the Creative Cloud desktop app updater, or by navigating to the Dreamweaver Help menu and clicking "Updates." For more information, please reference this help page.
Note
Note: For managed environments, IT administrators can use the Creative Cloud Packager to create deployment packages. Refer to this help page for more information on the Creative Cloud Packager.
Vulnerability Details
Acknowledgements
Adobe would like to thank the following researcher for reporting these issues and for working with Adobe to help protect our customers:
- Sudhanshu Rajbhar (sudi) - CVE-2026-47907, CVE-2026-47910
- Kieran (kaiksi) - CVE-2026-47909
- mrhavit - CVE-2026-47906
- Francis Provencher (prl) - CVE-2026-47908
NOTE: Adobe has a public bug bounty program. If you are interested in working with Adobe as an external security researcher, please check out https://app.intigriti.com/programs/adobe/adobepublic/detail
For more information, visit https://www.adobe.com/trust/security/bug-bounty.html, or email PSIRT@adobe.com.