Adobe Security Updates – 10 June 2026

Adobe has released security updates to address several vulnerabilities affecting multiple Adobe products.

The addressed vulnerabilities could allow the attacker to bypass security restrictions, manipulate data, obtain sensitive information, perform denial-ofservice and cross-site scripting attacks, execute arbitrary code, and gain access to the affected systems.

Sample of the addressed vulnerabilities:

1. Adobe Experience Manager Forms Cross-Site Scripting Vulnerability (CVE- 2026-34691):

  • CVSS: 9.3
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Consequences: Cross-Site Scripting

2. Adobe ColdFusion Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) Vulnerability (CVE-2026-47932):

  • CVSS: 8.8
  • Attack Vector: Adjacent
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Consequences: Security Bypass
Vulnerabilities
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Adobe Security Advisory

References