Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day

Summary

Adobe has released patches for over 170 vulnerabilities across its product suite. Notably, one zero-day vulnerability in Adobe Commerce, tracked as CVE-2026-75650, was actively exploited and allowed unauthenticated attackers to execute arbitrary code.

IFF Assessment

FOE

The patching of a zero-day vulnerability that allows for arbitrary code execution represents a significant security risk that attackers could exploit.

Severity

10.0 Critical

CISA KEV: Listed as actively exploited. Federal patch due: September 11, 2026. Known ransomware use: Unknown.

Defender Context

This extensive patching effort highlights the ongoing need for prompt vulnerability management and patching, especially for critical products like Adobe Commerce. Defenders should prioritize patching these vulnerabilities to mitigate the risk of exploitation.

Read Full Story →