Security updates available for Adobe Experience Manager | APSB26-74
摘要
Adobe has released updates for Adobe Experience Manager (AEM). This update resolves vulnerabilities rated important . Successful exploitation of these vulnerabilities could result in arbitrary code execution, security feature bypass, arbitrary file system read, and privilege escalation.
正文
Adobe has released updates for Adobe Experience Manager (AEM). This update resolves vulnerabilities rated important . Successful exploitation of these vulnerabilities could result in arbitrary code execution, security feature bypass, arbitrary file system read, and privilege escalation. Adobe is not aware of any exploits in the wild for any of the issues addressed in these updates. Adobe categorizes these updates with the following priority ratings and recommends users update their installation to the newest version: CVE-2026-48252, CVE-2026-48259, CVE-2026-48263, CVE-2026-48310, CVE-2026-48355 only affect indicated AEMaaCS releases. Affected products: - Adobe Experience Manager (AEM) | AEM Cloud Service (CS) Release 2026.5.0 and earlier | All - Adobe Experience Manager (AEM) | 6.5 LTS Service Pack 2 and earlier | All - Adobe Experience Manager (AEM) | 6.5 Service Pack 25 and earlier | All Solutions: - Adobe Experience Manager (AEM) | AEM Cloud Service (CS) Release 2026.6.0 | All (Priority 3; Release Notes) - Adobe Experience Manager (AEM) | 6.5 LTS Service Pack 2 - Hotfix for NPR-43972 | All (Priority 3; Release Notes) - Adobe Experience Manager (AEM) | 6.5 Service Pack 25 - Hotfix for NPR-43971 | All (Priority 3; Release Notes) If a customer is using Apache httpd in a proxy with a non-default configuration, they may be impacted by CVE-2023-25690 - please read more here: https://httpd.apache.org/security/vulnerabilities_24.html Vulnerabilities: - - - - - - - - - - - - - Acknowledgment: Adobe would like to thank the following for reporting these issues and for working with Adobe to help protect our customers: Acknowledgment: green-jam - CVE-2026-48253, CVE-2026-48254, CVE-2026-48255, CVE-2026-48257, CVE-2026-48260, CVE-2026-48261, CVE-2026-48262 Acknowledgment: Dylan Pindur, Adam Kues, and Patrik Grobshäuser of Assetnote - CVE-2026-48252, CVE-2026-48259, CVE-2026-48263, CVE-2026-48310, CVE-2026-48355, CVE-2026-48359 Acknowledgment: NOTE: Adobe has a public bug bounty program with HackerOne. If you are interested in working with Adobe as an external security researcher, please check out https://hackerone.com/adobe
标签
- contains:cve
- has:last-updated
- priority:3
- product:adobe-experience-manager-aem
- vendor:adobe
扩展字段
{
"acknowledgments": [
"Adobe would like to thank the following for reporting these issues and for working with Adobe to help protect our customers:",
"green-jam - CVE-2026-48253, CVE-2026-48254, CVE-2026-48255, CVE-2026-48257, CVE-2026-48260, CVE-2026-48261, CVE-2026-48262",
"Dylan Pindur, Adam Kues, and Patrik Grobshäuser of Assetnote - CVE-2026-48252, CVE-2026-48259, CVE-2026-48263, CVE-2026-48310, CVE-2026-48355, CVE-2026-48359",
"NOTE: Adobe has a public bug bounty program with HackerOne. If you are interested in working with Adobe as an external security researcher, please check out https://hackerone.com/adobe"
],
"affected_products": [
{
"platform": "All",
"product": "Adobe Experience Manager (AEM)",
"version": "AEM Cloud Service (CS) Release 2026.5.0 and earlier"
},
{
"platform": "All",
"product": "Adobe Experience Manager (AEM)",
"version": "6.5 LTS Service Pack 2 and earlier"
},
{
"platform": "All",
"product": "Adobe Experience Manager (AEM)",
"version": "6.5 Service Pack 25 and earlier"
}
],
"bulletin_id": "APSB26-74",
"detail_url": "https://helpx.adobe.com/security/products/experience-manager/apsb26-74.html",
"last_updated": "07/15/2026",
"originally_posted": "07/14/2026",
"priority": "3",
"solution_paragraphs": [
"Adobe categorizes these updates with the following priority ratings and recommends users update their installation to the newest version:",
"CVE-2026-48252, CVE-2026-48259, CVE-2026-48263, CVE-2026-48310, CVE-2026-48355 only affect indicated AEMaaCS releases."
],
"solutions": [
{
"availability": "Release Notes",
"availability_url": "https://experienceleague.adobe.com/en/docs/experience-manager-cloud-service/content/release-notes/release-notes/release-notes-current",
"platform": "All",
"priority": "3",
"product": "Adobe Experience Manager (AEM)",
"version": "AEM Cloud Service (CS) Release 2026.6.0"
},
{
"availability": "Release Notes",
"availability_url": "https://experienceleague.adobe.com/en/docs/experience-manager-65-lts/content/release-notes/release-notes",
"platform": "All",
"priority": "3",
"product": "Adobe Experience Manager (AEM)",
"version": "6.5 LTS Service Pack 2 - Hotfix for NPR-43972"
},
{
"availability": "Release Notes",
"availability_url": "https://experienceleague.adobe.com/en/docs/experience-manager-65/content/release-notes/release-notes",
"platform": "All",
"priority": "3",
"product": "Adobe Experience Manager (AEM)",
"version": "6.5 Service Pack 25 - Hotfix for NPR-43971"
}
],
"summary_paragraphs": [
"Adobe has released updates for Adobe Experience Manager (AEM). This update resolves vulnerabilities rated important . Successful exploitation of these vulnerabilities could result in arbitrary code execution, security feature bypass, arbitrary file system read, and privilege escalation.",
"Adobe is not aware of any exploits in the wild for any of the issues addressed in these updates."
],
"vulnerabilities": [
{},
{},
{},
{},
{},
{},
{},
{},
{},
{},
{},
{},
{}
],
"vulnerability_paragraphs": [
"If a customer is using Apache httpd in a proxy with a non-default configuration, they may be impacted by CVE-2023-25690 - please read more here: https://httpd.apache.org/security/vulnerabilities_24.html"
]
}