Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Adobe Patches Over 60 Vulnerabilities Across 13 Products

Adobe’s security updates fix vulnerabilities in Commerce, Substance, InDesign, FrameMaker, Dimension and other products.

Adobe vulnerabilities

Adobe’s August 2025 Patch Tuesday updates address more than 60 vulnerabilities across 3D design, content creation, publishing and other types of products.

The software giant has published 13 new advisories, including five that cover vulnerabilities in Substance 3D products such as Viewer, Modeler, Painter, Sampler, and Stager.

In each of them Adobe patched one or more critical (high severity based on CVSS score) code execution vulnerabilities, and in some of them multiple important (medium severity) memory leaks. 

In Commerce and the Magento open source solution Adobe fixed four critical vulnerabilities that can be exploited for privilege escalation, denial of service (DoS), and arbitrary file system read, along with two security feature bypass issues. 

In Animate, the company patched one critical arbitrary code execution vulnerability and a memory leak, while in Illustrator it addressed three code execution flaws and one DoS issue.

Adobe also fixed a critical code execution bug in Photoshop and one memory leak in Dimension. Several critical code execution flaws were also patched in FrameMaker.

Advertisement. Scroll to continue reading.

InCopy and InDesign updates resolve a total of nearly 20 critical vulnerabilities that can be exploited for arbitrary code execution.

Adobe says it’s not aware of malicious attacks exploiting any of these vulnerabilities. In addition, while some of the flaws have been rated critical, they all have a priority rating of 2 or 3, which indicates that Adobe does not expect to see in-the-wild exploitation.

Microsoft’s Patch Tuesday updates for August 2025 address over 100 vulnerabilities, including several critical issues that can be exploited for remote code execution. 

Related: Adobe Issues Out-of-Band Patches for AEM Forms Vulnerabilities With Public PoC

Related: Aanchal Gupta Joins Adobe as Chief Security Officer

Related: Adobe Patches Critical Code Execution Bugs

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

In cyber-physical systems (CPS), just one hour of downtime can outweigh an entire annual security budget. Learn how to master the Return on Security Investment (ROSI) to align security goals with the bottom-line priorities.

Register

Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization.

Register

People on the Move

Malwarebytes has named Chung Ip as Chief Financial Officer.

Semperis has appointed John Podboy as Chief Information Security Officer.

Randy Menon has become Chief Product and Marketing Officer at One Identity.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.