网安资讯详情 - SecLens 情报雷达

网安资讯,一网打尽。汇集权威漏洞通告与行业要闻,结合分组浏览、智能过滤、RSS订阅 和 Webhook 推送,多通道拓展您的安全情报视野。

Security updates available for Adobe Experience Manager | APSB26-74

来源: adobe_security · 发布时间 2026-07-14 08:00 (UTC+08:00) · 抓取时间 2026-07-27 10:35 (UTC+08:00)

原文链接

摘要

Adobe has released updates for Adobe Experience Manager (AEM). This update resolves vulnerabilities rated important . Successful exploitation of these vulnerabilities could result in arbitrary code execution, security feature bypass, arbitrary file system read, and privilege escalation.

正文

Adobe has released updates for Adobe Experience Manager (AEM). This update resolves vulnerabilities rated important . Successful exploitation of these vulnerabilities could result in arbitrary code execution, security feature bypass, arbitrary file system read, and privilege escalation. Adobe is not aware of any exploits in the wild for any of the issues addressed in these updates. Adobe categorizes these updates with the following priority ratings and recommends users update their installation to the newest version: CVE-2026-48252, CVE-2026-48259, CVE-2026-48263, CVE-2026-48310, CVE-2026-48355 only affect indicated AEMaaCS releases. Affected products: - Adobe Experience Manager (AEM) | AEM Cloud Service (CS) Release 2026.5.0 and earlier | All - Adobe Experience Manager (AEM) | 6.5 LTS Service Pack 2 and earlier | All - Adobe Experience Manager (AEM) | 6.5 Service Pack 25 and earlier | All Solutions: - Adobe Experience Manager (AEM) | AEM Cloud Service (CS) Release 2026.6.0 | All (Priority 3; Release Notes) - Adobe Experience Manager (AEM) | 6.5 LTS Service Pack 2 - Hotfix for NPR-43972 | All (Priority 3; Release Notes) - Adobe Experience Manager (AEM) | 6.5 Service Pack 25 - Hotfix for NPR-43971 | All (Priority 3; Release Notes) If a customer is using Apache httpd in a proxy with a non-default configuration, they may be impacted by CVE-2023-25690 - please read more here: https://httpd.apache.org/security/vulnerabilities_24.html Vulnerabilities: - - - - - - - - - - - - - Acknowledgment: Adobe would like to thank the following for reporting these issues and for working with Adobe to help protect our customers: Acknowledgment: green-jam - CVE-2026-48253, CVE-2026-48254, CVE-2026-48255, CVE-2026-48257, CVE-2026-48260, CVE-2026-48261, CVE-2026-48262 Acknowledgment: Dylan Pindur, Adam Kues, and Patrik Grobshäuser of Assetnote - CVE-2026-48252, CVE-2026-48259, CVE-2026-48263, CVE-2026-48310, CVE-2026-48355, CVE-2026-48359 Acknowledgment: NOTE: Adobe has a public bug bounty program with HackerOne. If you are interested in working with Adobe as an external security researcher, please check out https://hackerone.com/adobe

标签

扩展字段

{
  "acknowledgments": [
    "Adobe would like to thank the following for reporting these issues and for working with Adobe to help protect our customers:",
    "green-jam - CVE-2026-48253, CVE-2026-48254, CVE-2026-48255, CVE-2026-48257, CVE-2026-48260, CVE-2026-48261, CVE-2026-48262",
    "Dylan Pindur, Adam Kues, and Patrik Grobshäuser of Assetnote - CVE-2026-48252, CVE-2026-48259, CVE-2026-48263, CVE-2026-48310, CVE-2026-48355, CVE-2026-48359",
    "NOTE: Adobe has a public bug bounty program with HackerOne. If you are interested in working with Adobe as an external security researcher, please check out https://hackerone.com/adobe"
  ],
  "affected_products": [
    {
      "platform": "All",
      "product": "Adobe Experience Manager (AEM)",
      "version": "AEM Cloud Service (CS) Release 2026.5.0 and earlier"
    },
    {
      "platform": "All",
      "product": "Adobe Experience Manager (AEM)",
      "version": "6.5 LTS Service Pack 2 and earlier"
    },
    {
      "platform": "All",
      "product": "Adobe Experience Manager (AEM)",
      "version": "6.5 Service Pack 25 and earlier"
    }
  ],
  "bulletin_id": "APSB26-74",
  "detail_url": "https://helpx.adobe.com/security/products/experience-manager/apsb26-74.html",
  "last_updated": "07/15/2026",
  "originally_posted": "07/14/2026",
  "priority": "3",
  "solution_paragraphs": [
    "Adobe categorizes these updates with the following priority ratings and recommends users update their installation to the newest version:",
    "CVE-2026-48252, CVE-2026-48259, CVE-2026-48263, CVE-2026-48310, CVE-2026-48355 only affect indicated AEMaaCS releases."
  ],
  "solutions": [
    {
      "availability": "Release Notes",
      "availability_url": "https://experienceleague.adobe.com/en/docs/experience-manager-cloud-service/content/release-notes/release-notes/release-notes-current",
      "platform": "All",
      "priority": "3",
      "product": "Adobe Experience Manager (AEM)",
      "version": "AEM Cloud Service (CS) Release 2026.6.0"
    },
    {
      "availability": "Release Notes",
      "availability_url": "https://experienceleague.adobe.com/en/docs/experience-manager-65-lts/content/release-notes/release-notes",
      "platform": "All",
      "priority": "3",
      "product": "Adobe Experience Manager (AEM)",
      "version": "6.5 LTS Service Pack 2 - Hotfix for NPR-43972"
    },
    {
      "availability": "Release Notes",
      "availability_url": "https://experienceleague.adobe.com/en/docs/experience-manager-65/content/release-notes/release-notes",
      "platform": "All",
      "priority": "3",
      "product": "Adobe Experience Manager (AEM)",
      "version": "6.5 Service Pack 25 - Hotfix for NPR-43971"
    }
  ],
  "summary_paragraphs": [
    "Adobe has released updates for Adobe Experience Manager (AEM). This update resolves vulnerabilities rated important . Successful exploitation of these vulnerabilities could result in arbitrary code execution, security feature bypass, arbitrary file system read, and privilege escalation.",
    "Adobe is not aware of any exploits in the wild for any of the issues addressed in these updates."
  ],
  "vulnerabilities": [
    {},
    {},
    {},
    {},
    {},
    {},
    {},
    {},
    {},
    {},
    {},
    {},
    {}
  ],
  "vulnerability_paragraphs": [
    "If a customer is using Apache httpd in a proxy with a non-default configuration, they may be impacted by CVE-2023-25690 - please read more here: https://httpd.apache.org/security/vulnerabilities_24.html"
  ]
}