Adobe Security Updates – 10 September 2025

Adobe has released security updates to address several vulnerabilities across multiple Adobe products.

The addressed vulnerabilities could allow the attacker to bypass security restrictions, obtain sensitive information, or execute arbitrary code and gain access to the affected system.

Sample of the addressed vulnerabilities:

1. Adobe Commerce and Magento Open Source Improper Input Validation Vulnerability (CVE-2025-54236):

  • CVSS: 9.1
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Bypass Security

2. ColdFusion Incorrect Authorization Vulnerability (CVE-2025-54261):

  • CVSS: 9
  • Attack Vector: Network
  • Attack Complexity: High
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Access
Vulnerabilities
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Adobe Security Advisory

References