Incident Response

Patch Tuesday: Code Execution Flaws in Adobe Commerce, Photoshop

Adobe Commerce customers exposed to code execution, privilege escalation, arbitrary file system read, and security feature bypass attacks.

Adobe vulnerabilities

Software maker Adobe on Tuesday released fixes for at least 13 security vulnerabilities in multiple product lines, warning that critical flaws in Adobe Commerce and Photoshop will require immediate attention.

As part of its scheduled batch of Patch Tuesday updates, Adobe documented at least 10 serious flaws in Adobe Commerce and Magento Open Source, a product line often targeted by malicious hackers.

“Successful exploitation could lead to arbitrary code execution, privilege escalation, arbitrary file system read, security feature bypass and application denial-of-service,” Adobe said in a critical-severity advisory.

The company identified the affected software versions as Adobe Commerce (multiple versions including 2.4.7-beta1 and earlier) and Magento Open Source (Multiple versions including 2.4.7-beta1 and earlier.)

Adobe said it was not aware of exploits for any of the documented vulnerabilities.

The San Jose, Calif. firm also released updates to fix a critical-severity flaw in the popular Adobe Photoshop software.  The flaw, tagged as CVE-2023-26370, could be exploited to launch code execution attacks on both Windows and macOS systems.

Advertisement. Scroll to continue reading.

Adobe said the patches apply to Photoshop 2022 (23.5.5 and earlier versions) and Photoshop 2023 (24.7 and earlier versions). 

Adobe’s security response team also released fixes for a pair of vulnerabilities in Adobe Bridge that could lead to memory corruption exploitation.

Related: Adobe Says Critical PDF Reader Zero-Day Being Exploited 

Related: Critical Flaws in Adobe Commerce Software

Related: Patch for Exploited Flaw in Adobe Commerce and Magento Bypassed

Related: Adobe Plugs Critical Security Holes in Illustrator, After Effects Software

Related Content

Vulnerabilities

A use-after-free in the afd.sys Windows kernel-mode driver has been exploited to gain SYSTEM privileges.

Vulnerabilities

The security defects could be exploited for arbitrary code execution and denial-of-service.

Vulnerabilities

SAP released 28 new and two updated security notes, including four notes dealing with critical-severity bugs.

Vulnerabilities

An attacker only needed to convince the targeted user to visit a malicious website to exfiltrate WhatsApp messages and contacts.

ICS/OT

The industrial giants fixed dozens of vulnerabilities across their ICS products, with advisories also released by CISA and VDE CERT.

Vulnerabilities

Two flaws in Active Directory and SharePoint Server have been exploited as zero-days, and a BitLocker bug was publicly disclosed.

Vulnerabilities

The ColdFusion security defects could allow attackers to execute arbitrary code or elevate their privileges.

Vulnerabilities

Seven of the security defects have a maximum severity rating of 10/10 and could lead to arbitrary code execution.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version