Adobe Security Updates – 15 July 2026

Adobe has released security updates to address several vulnerabilities affecting multiple Adobe products.

The addressed vulnerabilities could allow the attacker to conduct denial-of-service (DoS) attacks, trigger memory corruption, perform server-side request forgery (SSRF), bypass security restrictions, gain elevated privileges, obtain sensitive information, or execute arbitrary commands, potentially leading to gaining access to the affected product.

Sample of the addressed vulnerabilities:

1. Adobe Experience Manager Improper Restriction of XML External Entity Reference Vulnerability (CVE-2026-48359):

  • CVSS: 9.6
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Remote Code Execution

2. Adobe ColdFusion Incorrect Authorization Vulnerability (CVE-2026-48321):

  • CVSS: 9.3
  • Attack Vector: Adjacent
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Privileges
Vulnerabilities
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Adobe Security Advisory

References