AI Security AI安全 2h ago Updated 1h ago 更新于 1小时前 43

Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day Adobe 修复超过170个漏洞,包括Commerce零日漏洞

Adobe patched over 170 vulnerabilities across its product suite, with urgent Priority 1 fixes for multiple critical-severity flaws CVE-2026-75650, a CVSS 10/10 unauthenticated remote code execution vulnerability in Adobe Commerce/Magento, is actively exploited in the wild (dubbed "StyleSmuggler") Additional critical patches address CVE-2026-82004 (OS command injection in Campaign Classic, CVSS 10/10) and two ColdFusion code execution flaws (CVSS 9.9 and 9.1) Experience Manager received the large Adobe发布超过170个漏洞补丁,涵盖Commerce/Magento、Campaign Classic、ColdFusion、Experience Manager等多个产品线 Commerce/Magento零日漏洞CVE-2026-75650(CVSS 10/10)已被实际利用,攻击者通过StyleSmuggler手法注入代码并部署后门 Campaign Classic的OS命令注入漏洞CVE-2026-82004(CVSS 10/10)和ColdFusion两个关键代码执行漏洞(CVSS 9.9/10和9.1/10)同样被紧急修复 Adobe建议所有Priority 1安全更新在发布后

68
Hot 热度
62
Quality 质量
55
Impact 影响力

Analysis 深度分析

TL;DR

  • Adobe patched over 170 vulnerabilities across its product suite, with urgent Priority 1 fixes for multiple critical-severity flaws
  • CVE-2026-75650, a CVSS 10/10 unauthenticated remote code execution vulnerability in Adobe Commerce/Magento, is actively exploited in the wild (dubbed "StyleSmuggler")
  • Additional critical patches address CVE-2026-82004 (OS command injection in Campaign Classic, CVSS 10/10) and two ColdFusion code execution flaws (CVSS 9.9 and 9.1)
  • Experience Manager received the largest share of fixes with 107 vulnerabilities patched, followed by 32 in Acrobat Reader
  • Adobe recommends applying all Priority 1 updates within three days and rotating all encryption keys and credentials at the source

Why It Matters

This represents one of the largest coordinated security patch releases from Adobe, targeting enterprise-critical platforms like Commerce, Campaign Classic, and Experience Manager that power thousands of online businesses. The active exploitation of the Magento zero-day by multiple threat actors deploying backdoors and web shells underscores the urgent need for immediate remediation by e-commerce operators. The breadth of vulnerabilities across Creative Cloud and Document products also highlights ongoing attack surface risks for individual and organizational users.

Technical Details

  • CVE-2026-75650 (CVSS 10/10): Unauthenticated code injection in Adobe Commerce/Magento Open Source enabling remote code execution; exploited via the standard "Payment Transaction Failed Reminder" feature without user interaction, dubbed "StyleSmuggler" by Sansec
  • CVE-2026-82004 (CVSS 10/10): OS command injection vulnerability in Adobe Campaign Classic leading to arbitrary code execution
  • ColdFusion critical flaws: CVE-2026-48273 (CVSS 9.9) and CVE-2026-75746 (CVSS 9.1) are critical code execution weaknesses, plus seven high- and medium-severity issues
  • Patch distribution: 107 vulnerabilities in Experience Manager, 32 in Acrobat Reader, 8 in Photoshop, 3 in Illustrator, 1 in Animate, plus Photoshop Mobile fixes
  • Eight additional Commerce vulnerabilities patched: Two critical privilege escalation flaws and six high-severity security bypass/privilege escalation bugs

Industry Insight

  • Organizations running Magento/Adobe Commerce should treat this as an emergency—apply patches immediately and rotate all credentials (encryption keys, admin passwords, API keys, OAuth secrets) at their source, not just within Magento, since attackers may have already exfiltrated data
  • The "StyleSmuggler" attack vector exploiting a built-in payment reminder feature demonstrates how attackers leverage legitimate application functionality for stealthy code injection, a pattern likely to recur across SaaS platforms
  • Adobe's Priority 1 patch cadence and three-day remediation window signal the severity expected by enterprise security teams; integrating these updates into emergency patch management workflows is essential for compliance and risk reduction

TL;DR

  • Adobe发布超过170个漏洞补丁,涵盖Commerce/Magento、Campaign Classic、ColdFusion、Experience Manager等多个产品线
  • Commerce/Magento零日漏洞CVE-2026-75650(CVSS 10/10)已被实际利用,攻击者通过StyleSmuggler手法注入代码并部署后门
  • Campaign Classic的OS命令注入漏洞CVE-2026-82004(CVSS 10/10)和ColdFusion两个关键代码执行漏洞(CVSS 9.9/10和9.1/10)同样被紧急修复
  • Adobe建议所有Priority 1安全更新在发布后三天内完成应用,并强调需从源头轮换所有加密密钥和凭证

为什么值得看

Adobe作为企业级软件巨头,此次大规模安全补丁涉及电商、营销自动化、创意工具等核心产品线,对依赖Adobe生态的企业构成直接安全影响。零日漏洞已被实际利用的案例警示企业必须建立快速响应机制。

技术解析

  • CVE-2026-75650是Commerce/Magento的代码注入漏洞,无需认证即可实现远程代码执行(RCE),攻击者通过触发Magento的"Payment Transaction Failed Reminder"功能注入恶意代码,CVSS评分10/10
  • CVE-2026-82004是Campaign Classic的OS命令注入漏洞,同样无需认证即可实现任意代码执行,CVSS评分10/10
  • ColdFusion安全更新修复了两个关键代码执行漏洞:CVE-2026-48273(CVSS 9.9/10)和CVE-2026-75746(CVSS 9.1/10),以及七个高/中严重性漏洞
  • 攻击者利用StyleSmuggler攻击在Commerce/Magento中部署后门和web shell,建议用户不仅轮换加密密钥,还要从源头轮换所有凭证(包括管理员密码、数据库凭证、OAuth密钥、SSH密钥、API密钥等)
  • 其他受影响产品包括Experience Manager(107个漏洞)、Acrobat Reader(32个)、Photoshop(8个)、Illustrator(3个)、Animate(1个)及Photoshop Mobile

行业启示

  • 企业软件安全补丁的紧迫性凸显,Adobe要求Priority 1更新在三天内完成,企业需建立自动化补丁管理和快速响应机制
  • 零日漏洞被实际利用的案例表明,依赖第三方软件的企业必须重视供应链安全,定期审计和更新所有组件
  • 大规模漏洞修复(170+)反映Adobe产品生态的复杂性,企业应建立持续的安全监控和漏洞管理流程,降低潜在风险

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全