Adobe has released updates that close a critical zero‑day vulnerability and 172 other security flaws across multiple products, the company says. The fixes cover ColdFusion, Acrobat Reader, Commerce, Campaign Classic, Experience Manager, Photoshop, Illustrator, Animate and Adobe Photoshop Mobile.
Adobe patches: affected products and severities
Among the most severe issues, Commerce is referenced by CVE‑2026‑75650 and Campaign Classic by CVE‑2026‑82004, the latter carrying the maximum CVSS score of 10.0. Critical issues in ColdFusion and Experience Manager reach a CVSS score of 9.9. Experience Manager accounts for the largest share by volume, with Adobe stating it has fixed 107 vulnerabilities in that product. Adobe Acrobat and Reader follow with 32 vulnerabilities. The updates also cover Photoshop, Illustrator, Animate and Adobe Photoshop Mobile.
Adobe had already issued a hot patch on September 7 in response to an active wave of attacks using Stylesmuggler against Commerce and Magento Open Source.
Exploit status and recommended action
Apart from the Commerce vulnerability, Adobe does not list any of the patched flaws as “already exploited.” Given the repeatedly demonstrated ability to develop working exploits for patches within hours using AI, Adobe advises that updates should be installed as quickly as possible. Links to the individual advisories are available on Adobe’s security page.

