Software maker Adobe has shipped security patches for flaws in its Adobe Magento and Connect product lines, warning that exploitation could lead to remote code execution attacks.
As part of its scheduled Patch Tuesday release, Adobe released fixes for 29 documented security vulnerabilities, some serious enough to expose users to code execution, security feature bypass, and privilege escalation attacks.
The Adobe Magento patch lists 26 CVEs with severity ratings ranging from critical to important, according to an advisory from the San Jose, Calif. software vendor.
Adobe said patches for these flaws are now available for the Magento Commerce and Magento Open Source editions. Adobe Magento is an open-source e-commerce platform.
The company also shipped an “important” update to its Adobe Connect platform to address a security feature bypass flaw and a pair of cross-site scripting issues that could lead to arbitrary code execution.
Adobe Connect is a suite of software for remote training, web conferencing, presentation, and desktop sharing.
Related: Microsoft Patch Tuesday: Windows Flaw Under Active Attack
Related: Adobe Confirms Windows PDF Reader Zero-Day Attacks
Related: Microsoft Takes Another Stab at PrintNightmare Security Fix

Ryan Naraine is Editor-at-Large at SecurityWeek and host of the popular Security Conversations podcast series. He is a security community engagement expert who has built programs at major global brands, including Intel Corp., Bishop Fox and GReAT. Ryan is a founding-director of the Security Tinkerers non-profit, an advisor to early-stage entrepreneurs, and a regular speaker at security conferences around the world.
More from Ryan Naraine
- Tenable Launches $25 Million Early-Stage Venture Fund
- VMware Plugs Critical Code Execution Flaws
- GoTo Says Hackers Stole Encrypted Backups, MFA Settings
- Apple Patches WebKit Code Execution in iPhones, MacBooks
- Thoma Bravo to Buy Magnet Forensics in $1.3B Transaction
- T-Mobile Says Hackers Used API to Steal Data on 37 Million Accounts
- Chainguard Trains Spotlight on SBOM Quality Problem
- Exploited Control Web Panel Flaw Added to CISA ‘Must-Patch’ List
Latest News
- Critical Vulnerability Impacts Over 120 Lexmark Printers
- BIND Updates Patch High-Severity, Remotely Exploitable DoS Flaws
- Industry Reactions to Hive Ransomware Takedown: Feedback Friday
- Microsoft Urges Customers to Patch Exchange Servers
- Iranian APT Leaks Data From Saudi Arabia Government Under New Persona
- US Reiterates $10 Million Reward Offer After Disruption of Hive Ransomware
- Cyberattacks Target Websites of German Airports, Admin
- US Infiltrates Big Ransomware Gang: ‘We Hacked the Hackers’
