厂商发布
厂商对产品安全、配置或策略的更新说明。
-
Security updates available for Adobe Animate | APSB26-83
Adobe has released an update for Adobe Animate. This update resolves critical vulnerabilities. Successful exploitation could lead to arbitrary code execution.
Adobe has released an update for Adobe Animate. This update resolves critical vulnerabilities. Successful exploitation could lead to arbitrary code execution.Adobe has released an update for Adobe Animate. This update resolves critical vulnerabilities. Successful exploitation could lead to arbitrary code execution.扩展字段
{ "acknowledgments": [ "Adobe would like to thank the following for reporting the relevant issues and for working with Adobe to help protect our customers:", "Kieran (kaiksi) - CVE-2026-48345, CVE-2026-48346, CVE-2026-48347, CVE-2026-48348, CVE-2026-48349, CVE-2026-48350", "NOTE: Adobe has a public bug bounty program with HackerOne. If you are interested in working with Adobe as an external security researcher, please check out https://hackerone.com/adobe .", "For more information, visit https://helpx.adobe.com/security.html , or email [email protected]." ], "affected_products": [ { "platform": "Windows and macOS", "product": "Adobe Animate 2023", "version": "23.0.15 and earlier versions" }, { "platform": "Windows and macOS", "product": "Adobe Animate 2024", "version": "24.0.13 and earlier versions" } ], "bulletin_id": "APSB26-83", "detail_url": "https://helpx.adobe.com/security/products/animate/apsb26-83.html", "last_updated": "07/14/2026", "originally_posted": "07/14/2026", "priority": "3", "solution_paragraphs": [ "Adobe categorizes this update with the following priority rating and recommends users update their installation to the newest version via the Creative Cloud desktop app's update mechanism. For more information, please reference this help page .", "For managed environments, IT administrators can use the Admin Console to deploy Creative Cloud applications to end users. Refer to this help page for more information." ], "solutions": [ { "availability": "Download Center", "availability_url": "https://www.adobe.com/apps/all/desktop", "platform": "Windows and macOS", "priority": "3", "product": "Adobe Animate 2023", "version": "23.0.16" }, { "availability": "Download Center", "availability_url": "https://www.adobe.com/apps/all/desktop", "platform": "Windows and macOS", "priority": "3", "product": "Adobe Animate 2024", "version": "24.0.14" } ], "summary_paragraphs": [ "Adobe has released an update for Adobe Animate. This update resolves critical vulnerabilities. Successful exploitation could lead to arbitrary code execution.", "Adobe is not aware of any exploits in the wild for any of the issues addressed in these updates." ], "vulnerabilities": [ {}, {}, {}, {}, {}, {} ] } -
Security Updates Available for Adobe Bridge | APSB26-81
Adobe has released a security update for Adobe Bridge. This update addresses critical vulnerabilities that could lead to arbitrary code execution.
Adobe has released a security update for Adobe Bridge. This update addresses critical vulnerabilities that could lead to arbitrary code execution.Adobe has released a security update for Adobe Bridge. This update addresses critical vulnerabilities that could lead to arbitrary code execution.扩展字段
{ "acknowledgments": [ "Adobe would like to thank the following researchers for reporting this issue and for working with Adobe to help protect our customers:", "yjdfy CVE-2026-48311, CVE-2026-48339, CVE-2026-48341, CVE-2026-48343", "Francis provencher (prl) CVE-2026-48340, CVE-2026-48342", "NOTE: Adobe has a public bug bounty program with HackerOne. If you are interested in working with Adobe as an external security researcher, please check out https://hackerone.com/adobe", "For more information, visit https://helpx.adobe.com/security.html , or email [email protected]" ], "affected_products": [ { "platform": "Windows and macOS", "product": "Adobe Bridge", "version": "15.1.5 (LTS) and earlier versions" }, { "platform": "Windows and macOS", "product": "Adobe Bridge", "version": "16.0.3 and earlier versions" } ], "bulletin_id": "APSB26-81", "detail_url": "https://helpx.adobe.com/security/products/bridge/apsb26-81.html", "last_updated": "07/14/2026", "originally_posted": "07/14/2026", "priority": "3", "solution_paragraphs": [ "Adobe categorizes these updates with the following priority ratings and recommends users update their installation to the newest version via the Creative Cloud desktop app's update mechanism. For more information, please reference this help page ." ], "solutions": [ { "availability": "Download Page", "availability_url": "https://www.adobe.com/products/bridge.html", "platform": "Windows and macOS", "priority": "3", "product": "Adobe Bridge", "version": "15.1.6 (LTS)" }, { "availability": "Download Page", "availability_url": "https://www.adobe.com/products/bridge.html", "platform": "Windows and macOS", "priority": "3", "product": "Adobe Bridge", "version": "16.0.4" } ], "summary_paragraphs": [ "Adobe has released a security update for Adobe Bridge. This update addresses critical vulnerabilities that could lead to arbitrary code execution.", "Adobe is not aware of any exploits in the wild for any of the issues addressed in these updates." ], "vulnerabilities": [ {}, {}, {}, {}, {}, {} ] } -
Security Updates Available for Adobe Illustrator | APSB26-79
Adobe has released an update for Adobe Illustrator. This update resolves critical vulnerabilities that could lead to arbitrary code execution and privilege escalation.
Adobe has released an update for Adobe Illustrator. This update resolves critical vulnerabilities that could lead to arbitrary code execution and privilege escalation.Adobe has released an update for Adobe Illustrator. This update resolves critical vulnerabilities that could lead to arbitrary code execution and privilege escalation.扩展字段
{ "acknowledgments": [ "Adobe would like to thank the following researcher for reporting these issues and for working with Adobe to help protect our customers:", "joney_juice - CVE-2026-48275", "Francis provencher (prl) - CVE-2026-48335, CVE-2026-48336, CVE-2026-48337", "Kieran (kaiksi) - CVE-2026-48334", "NOTE: Adobe has a public bug bounty program with HackerOne. If you are interested in working with Adobe as an external security researcher, please check out https://hackerone.com/adobe .", "For more information, visit https://helpx.adobe.com/security.html , or email [email protected]." ], "affected_products": [ { "platform": "Windows", "product": "Illustrator 2025", "version": "29.8.7 and earlier" }, { "platform": "Windows", "product": "Illustrator 2026", "version": "30.5 and earlier" } ], "bulletin_id": "APSB26-79", "detail_url": "https://helpx.adobe.com/security/products/illustrator/apsb26-79.html", "last_updated": "07/14/2026", "originally_posted": "07/14/2026", "priority": "3", "solution_paragraphs": [ "Adobe categorizes these updates with the following priority ratings and recommends users update their installation to the newest version via the Creative Cloud desktop app's update mechanism. For more information, please reference this help page ." ], "solutions": [ { "availability": "Download Page", "availability_url": "https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.adobe.com%2Fproducts%2Fcatalog.html&data=05%7C02%7Crkang%40adobe.com%7C9a0f89be2e9c477c1ec208de738da609%7Cfa7b1b5a7b34438794aed2c178decee1%7C0%7C0%7C639075249372578591%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=J83I%2FlaFq7zpPxz%2BXGAw%2BWNQ3CkHDzFhm1HYKSTW8vs%3D&reserved=0", "platform": "Windows and macOS", "priority": "3", "product": "Illustrator 2025", "version": "29.8.9" }, { "availability": "Download Page", "availability_url": "https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.adobe.com%2Fproducts%2Fcatalog.html&data=05%7C02%7Crkang%40adobe.com%7C9a0f89be2e9c477c1ec208de738da609%7Cfa7b1b5a7b34438794aed2c178decee1%7C0%7C0%7C639075249372600167%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=ywtu9syiaiZUq7gZyq641Vf5luRJwc2yZm6IbCQiOyY%3D&reserved=0", "platform": "Windows and macOS", "priority": "3", "product": "Illustrator 2026", "version": "30.6" } ], "summary_paragraphs": [ "Adobe has released an update for Adobe Illustrator. This update resolves critical vulnerabilities that could lead to arbitrary code execution and privilege escalation.", "Adobe is not aware of any exploits in the wild for any of the issues addressed in these updates." ], "vulnerabilities": [ {}, {}, {}, {}, {} ] } -
Security Updates Available for Adobe After Effects | APSB26-78
Adobe has released an update for Adobe After Effects for Windows and macOS. This update addresses critical security vulnerabilities. Successful exploitation could lead to arbitrary code execution.
Adobe has released an update for Adobe After Effects for Windows and macOS. This update addresses critical security vulnerabilities. Successful exploitation could lead to arbitrary code execution.Adobe has released an update for Adobe After Effects for Windows and macOS. This update addresses critical security vulnerabilities. Successful exploitation could lead to arbitrary code execution.扩展字段
{ "acknowledgments": [ "Adobe would like to thank the following for reporting the relevant issues and for working with Adobe to help protect our customers:", "yjdfy - CVE-2026-48274, CVE-2026-48367", "voidexploit - CVE-2026-34690", "NOTE: Adobe has a public bug bounty program with HackerOne. If you are interested in working with Adobe as an external security researcher, please check out https://hackerone.com/adobe", "For more information, visit https://helpx.adobe.com/security.html , or email [email protected]." ], "affected_products": [ { "platform": "Windows and macOS", "product": "Adobe After Effects", "version": "25.6.5 and earlier versions" }, { "platform": "Windows and macOS", "product": "Adobe After Effects", "version": "26.2.1 and earlier versions" } ], "bulletin_id": "APSB26-78", "detail_url": "https://helpx.adobe.com/security/products/after_effects/apsb26-78.html", "last_updated": "07/14/2026", "originally_posted": "07/14/2026", "priority": "3", "solution_paragraphs": [ "Adobe categorizes these updates with the following priority ratings and recommends users update their installation to the newest version via the Creative Cloud desktop app’s update mechanism. For more information, please reference this help page .", "For managed environments, IT administrators can use the Admin Console to deploy Creative Cloud applications to end users. Refer to this help page for more information." ], "solutions": [ { "availability": "Download Center", "availability_url": "https://www.adobe.com/products/catalog.html#category=creativity-design&types=desktop", "platform": "Windows and macOS", "priority": "3", "product": "Adobe After Effects", "version": "25.6.6" }, { "availability": "Download Center", "availability_url": "https://www.adobe.com/products/catalog.html#category=creativity-design&types=desktop", "platform": "Windows and macOS", "priority": "3", "product": "Adobe After Effects", "version": "26.3" } ], "summary_paragraphs": [ "Adobe has released an update for Adobe After Effects for Windows and macOS. This update addresses critical security vulnerabilities. Successful exploitation could lead to arbitrary code execution.", "Adobe is not aware of any exploits in the wild for any of the issues addressed in these updates." ], "vulnerabilities": [ { "CVE Numbers": "CVE-2026-48274", "CVSS base score": "7.8", "CVSS vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "Severity": "Critical", "Vulnerability Category": "Out-of-bounds Write ( CWE-787 )", "Vulnerability Impact": "Arbitrary code execution" }, { "CVE Numbers": "CVE-2026-48367", "CVSS base score": "7.8", "CVSS vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "Severity": "Critical", "Vulnerability Category": "Out-of-bounds Write ( CWE-787 )", "Vulnerability Impact": "Arbitrary code execution" }, { "CVE Numbers": "CVE-2026-34690", "CVSS base score": "7.8", "CVSS vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "Severity": "Critical", "Vulnerability Category": "Stack-based Buffer Overflow ( CWE-121 )", "Vulnerability Impact": "Arbitrary code execution" } ] } -
Security update available for Adobe Creative Cloud Desktop Application | APSB26-77
Adobe has released an update for the Creative Cloud Desktop for Windows. This update includes a fix for critical vulnerabilities that could lead to arbitrary code execution in the context of the current user.
Adobe has released an update for the Creative Cloud Desktop for Windows. This update includes a fix for critical vulnerabilities that could lead to arbitrary code execution in the context of the current user.Adobe has released an update for the Creative Cloud Desktop for Windows. This update includes a fix for critical vulnerabilities that could lead to arbitrary code execution in the context of the current user.扩展字段
{ "affected_products": [ { "platform": "Windows", "product": "Creative Cloud Desktop Application", "version": "6.9.1.1 and earlier versions" } ], "bulletin_id": "APSB26-77", "detail_url": "https://helpx.adobe.com/security/products/creative-cloud/apsb26-77.html", "last_updated": "07/14/2026", "originally_posted": "07/14/2026", "priority": "3", "solution_paragraphs": [ "Adobe categorizes this update with the following priority rating and recommends users update their installation to the newest version:" ], "solutions": [ { "availability": "Download Center", "availability_url": "https://helpx.adobe.com/download-install/kb/creative-cloud-desktop-app-download.html", "platform": "Windows", "priority": "3", "product": "Creative Cloud Desktop Application", "version": "6.10.0.252.3" } ], "summary_paragraphs": [ "Adobe has released an update for the Creative Cloud Desktop for Windows. This update includes a fix for critical vulnerabilities that could lead to arbitrary code execution in the context of the current user.", "Adobe is not aware of any exploits in the wild for any of the issues addressed in these updates." ], "vulnerabilities": [ {}, {} ] } -
Security Updates Available for Adobe Premiere Pro | APSB26-76
Adobe has released updates for Adobe Premiere Pro for Windows and macOS. This update addresses critical and important vulnerabilities. Successful exploitation could lead to arbitrary code execution and security feature bypass.
Adobe has released updates for Adobe Premiere Pro for Windows and macOS. This update addresses critical and important vulnerabilities. Successful exploitation could lead to arbitrary code execution and security feature bypass.Adobe has released updates for Adobe Premiere Pro for Windows and macOS. This update addresses critical and important vulnerabilities. Successful exploitation could lead to arbitrary code execution and security feature bypass.扩展字段
{ "acknowledgments": [ "Adobe would like to thank the following for reporting the relevant issues and for working with Adobe to help protect our customers:", "yjdfy -- CVE-2026-48270, CVE-2026-48369", "NOTE: Adobe has a public bug bounty program with HackerOne. If you are interested in working with Adobe as an external security researcher, please check out https://hackerone.com/adobe", "For more information, visit https://helpx.adobe.com/security.html , or email [email protected]" ], "affected_products": [ { "platform": "Windows and macOS", "product": "Adobe Premiere", "version": "26.2.2 and earlier versions" }, { "platform": "Windows and macOS", "product": "Adobe Premiere Pro", "version": "25.6.5 and earlier versions" } ], "bulletin_id": "APSB26-76", "detail_url": "https://helpx.adobe.com/security/products/premiere_pro/apsb26-76.html", "last_updated": "07/14/2026", "originally_posted": "07/14/2026", "priority": "3", "solution_paragraphs": [ "Adobe categorizes these updates with the following priority ratings and recommends users update their installation to the newest version via the Creative Cloud desktop app’s update mechanism. For more information, please reference this help page .", "For managed environments, IT administrators can use the Admin Console to deploy Creative Cloud applications to end users. Refer to this help page for more information." ], "solutions": [ { "availability": "Download Center", "availability_url": "https://www.adobe.com/products/catalog.html#category=creativity-design&types=desktop", "platform": "Windows and macOS", "priority": "3", "product": "Adobe Premiere", "version": "26.3" }, { "availability": "Download Center", "availability_url": "https://www.adobe.com/products/catalog.html#category=creativity-design&types=desktop", "platform": "Windows and macOS", "priority": "3", "product": "Adobe Premiere Pro", "version": "25.6.6" } ], "summary_paragraphs": [ "Adobe has released updates for Adobe Premiere Pro for Windows and macOS. This update addresses critical and important vulnerabilities. Successful exploitation could lead to arbitrary code execution and security feature bypass.", "Adobe is not aware of any exploits in the wild for any of the issues addressed in these updates." ], "vulnerabilities": [ {}, {}, {}, {} ] } -
Security updates available for Adobe Experience Manager | APSB26-74
Adobe has released updates for Adobe Experience Manager (AEM). This update resolves vulnerabilities rated important . Successful exploitation of these vulnerabilities could result in arbitrary code execution, security feature bypass, arbitrary file system read, and privilege escalation.
Adobe has released updates for Adobe Experience Manager (AEM). This update resolves vulnerabilities rated important . Successful exploitation of these vulnerabilities could result in arbitrary code execution, security feature bypass, arbitrary file system read, and privilege escalation.Adobe has released updates for Adobe Experience Manager (AEM). This update resolves vulnerabilities rated important . Successful exploitation of these vulnerabilities could result in arbitrary code execution, security feature bypass, arbitrary file system read, and privilege escalation.扩展字段
{ "acknowledgments": [ "Adobe would like to thank the following for reporting these issues and for working with Adobe to help protect our customers:", "green-jam - CVE-2026-48253, CVE-2026-48254, CVE-2026-48255, CVE-2026-48257, CVE-2026-48260, CVE-2026-48261, CVE-2026-48262", "Dylan Pindur, Adam Kues, and Patrik Grobshäuser of Assetnote - CVE-2026-48252, CVE-2026-48259, CVE-2026-48263, CVE-2026-48310, CVE-2026-48355, CVE-2026-48359", "NOTE: Adobe has a public bug bounty program with HackerOne. If you are interested in working with Adobe as an external security researcher, please check out https://hackerone.com/adobe" ], "affected_products": [ { "platform": "All", "product": "Adobe Experience Manager (AEM)", "version": "AEM Cloud Service (CS) Release 2026.5.0 and earlier" }, { "platform": "All", "product": "Adobe Experience Manager (AEM)", "version": "6.5 LTS Service Pack 2 and earlier" }, { "platform": "All", "product": "Adobe Experience Manager (AEM)", "version": "6.5 Service Pack 25 and earlier" } ], "bulletin_id": "APSB26-74", "detail_url": "https://helpx.adobe.com/security/products/experience-manager/apsb26-74.html", "last_updated": "07/15/2026", "originally_posted": "07/14/2026", "priority": "3", "solution_paragraphs": [ "Adobe categorizes these updates with the following priority ratings and recommends users update their installation to the newest version:", "CVE-2026-48252, CVE-2026-48259, CVE-2026-48263, CVE-2026-48310, CVE-2026-48355 only affect indicated AEMaaCS releases." ], "solutions": [ { "availability": "Release Notes", "availability_url": "https://experienceleague.adobe.com/en/docs/experience-manager-cloud-service/content/release-notes/release-notes/release-notes-current", "platform": "All", "priority": "3", "product": "Adobe Experience Manager (AEM)", "version": "AEM Cloud Service (CS) Release 2026.6.0" }, { "availability": "Release Notes", "availability_url": "https://experienceleague.adobe.com/en/docs/experience-manager-65-lts/content/release-notes/release-notes", "platform": "All", "priority": "3", "product": "Adobe Experience Manager (AEM)", "version": "6.5 LTS Service Pack 2 - Hotfix for NPR-43972" }, { "availability": "Release Notes", "availability_url": "https://experienceleague.adobe.com/en/docs/experience-manager-65/content/release-notes/release-notes", "platform": "All", "priority": "3", "product": "Adobe Experience Manager (AEM)", "version": "6.5 Service Pack 25 - Hotfix for NPR-43971" } ], "summary_paragraphs": [ "Adobe has released updates for Adobe Experience Manager (AEM). This update resolves vulnerabilities rated important . Successful exploitation of these vulnerabilities could result in arbitrary code execution, security feature bypass, arbitrary file system read, and privilege escalation.", "Adobe is not aware of any exploits in the wild for any of the issues addressed in these updates." ], "vulnerabilities": [ {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {}, {} ], "vulnerability_paragraphs": [ "If a customer is using Apache httpd in a proxy with a non-default configuration, they may be impacted by CVE-2023-25690 - please read more here: https://httpd.apache.org/security/vulnerabilities_24.html" ] } -
Security update available for Adobe Commerce | APSB26-73
Adobe has released a security update for Adobe Commerce and Magento Open Source. This update resolves critical , important and moderate vulnerabilities. Successful exploitation could lead to arbitrary code execution, privilege escalation, and security feature bypass.
Adobe has released a security update for Adobe Commerce and Magento Open Source. This update resolves critical , important and moderate vulnerabilities. Successful exploitation could lead to arbitrary code execution, privilege escalation, and security feature bypass.Adobe has released a security update for Adobe Commerce and Magento Open Source. This update resolves critical , important and moderate vulnerabilities. Successful exploitation could lead to arbitrary code execution, privilege escalation, and security feature bypass.扩展字段
{ "acknowledgments": [ "Adobe would like to thank the following researchers for reporting these issues and working with Adobe to help protect our customers:", "0x0.eth - CVE-2026-47984, CVE-2026-47996", "T.H. Lassche - CVE-2026-47988", "Sudhanshu Rajbhar (sudi) - CVE-2026-47992", "wohlie - CVE-2026-47994, CVE-2026-47995, CVE-2026-48358", "akashhamal0x01 - CVE-2026-47997, CVE-2026-47998, CVE-2026-48001", "s (howtoplay) - CVE-2026-47999", "schemonah - CVE-2026-48000", "Tseng, Ching-Yen (shaber) - CVE-2026-48371", "NOTE: Adobe has a public bug bounty program with HackerOne. If you are interested in working with Adobe as an external security researcher, please check out https://hackerone.com/adobe .", "For more information, visit https://helpx.adobe.com/security.html , or email [email protected]." ], "bulletin_id": "APSB26-73", "detail_url": "https://helpx.adobe.com/security/products/magento/apsb26-73.html", "last_updated": "07/14/2026", "originally_posted": "07/14/2026", "priority": "2", "solution_paragraphs": [ "Adobe categorizes these updates with the following priority ratings and recommends users update their installation to the newest version." ], "solutions": [ { "availability": "Release Notes", "availability_url": "https://experienceleague.adobe.com/en/docs/experience-cloud-kcs/kbarticles/ka-37421", "platform": "All", "priority": "2", "product": "Adobe Commerce", "version": "2.4.9-2026-jul 2.4.8-2026-jul 2.4.7-2026-jul 2.4.6-2026-jul 2.4.5-2026-jul 2.4.4-2026-jul" }, { "availability": "Release Notes", "availability_url": "https://experienceleague.adobe.com/en/docs/experience-cloud-kcs/kbarticles/ka-37421", "platform": "All", "priority": "2", "product": "Adobe Commerce B2B", "version": "1.5.3-2026-jul 1.5.2-2026-jul 1.4.2-2026-jul 1.3.4-2026-jul 1.3.3-2026-jul" }, { "availability": "Release Notes", "availability_url": "https://experienceleague.adobe.com/en/docs/experience-cloud-kcs/kbarticles/ka-37421", "platform": "All", "priority": "2", "product": "Magento Open Source", "version": "2.4.9-2026-jul 2.4.8-2026-jul 2.4.7-2026-jul 2.4.6-2026-jul" }, { "availability": "Upgrade Modules and Extensions", "availability_url": "https://experienceleague.adobe.com/en/docs/commerce-operations/upgrade-guide/modules/upgrade", "platform": "All", "priority": "2", "product": "Adobe Commerce Events", "version": "1.21.0" } ], "summary_paragraphs": [ "Adobe has released a security update for Adobe Commerce and Magento Open Source. This update resolves critical , important and moderate vulnerabilities. Successful exploitation could lead to arbitrary code execution, privilege escalation, and security feature bypass.", "Adobe is not aware of any exploits in the wild for any of the issues addressed in these updates." ], "vulnerabilities": [ { "Authentication required to exploit?": "No", "CVE number(s)": "CVE-2026-48356", "CVSS base score": "9.6", "CVSS vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L", "Exploit requires admin privileges?": "No", "Notes": null, "Severity": "Critical", "Vulnerability Category": "Unrestricted Upload of File with Dangerous Type ( CWE-434 )", "Vulnerability Impact": "Privilege escalation" }, { "Authentication required to exploit?": "Yes", "CVE number(s)": "CVE-2026-48358", "CVSS base score": "9.1", "CVSS vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H", "Exploit requires admin privileges?": "Yes", "Notes": "Applies to webhooks only", "Severity": "Critical", "Vulnerability Category": "Improper Encoding or Escaping of Output ( CWE-116 )", "Vulnerability Impact": "Arbitrary code execution" }, { "Authentication required to exploit?": "Yes", "CVE number(s)": "CVE-2026-47994", "CVSS base score": "8.7", "CVSS vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N", "Exploit requires admin privileges?": "Yes", "Notes": null, "Severity": "Critical", "Vulnerability Category": "Cross-site Scripting (Stored XSS) ( CWE-79 )", "Vulnerability Impact": "Privilege escalation" }, { "Authentication required to exploit?": "No", "CVE number(s)": "CVE-2026-47988", "CVSS base score": "8.6", "CVSS vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L", "Exploit requires admin privileges?": "No", "Notes": null, "Severity": "Critical", "Vulnerability Category": "Incorrect Authorization ( CWE-863 )", "Vulnerability Impact": "Security feature bypass" }, { "Authentication required to exploit?": "No", "CVE number(s)": "CVE-2026-47984", "CVSS base score": "8.2", "CVSS vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N", "Exploit requires admin privileges?": "No", "Notes": null, "Severity": "Critical", "Vulnerability Category": "Incorrect Authorization ( CWE-863 )", "Vulnerability Impact": "Security feature bypass" }, { "Authentication required to exploit?": "Yes", "CVE number(s)": "CVE-2026-47995", "CVSS base score": "8.1", "CVSS vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N", "Exploit requires admin privileges?": "Yes", "Notes": "B2B", "Severity": "Critical", "Vulnerability Category": "Cross-site Scripting (Stored XSS) ( CWE-79 )", "Vulnerability Impact": "Privilege escalation" }, { "Authentication required to exploit?": "Yes", "CVE number(s)": "CVE-2026-47996", "CVSS base score": "7.6", "CVSS vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L", "Exploit requires admin privileges?": "Yes", "Notes": null, "Severity": "Critical", "Vulnerability Category": "Incorrect Authorization ( CWE-863 )", "Vulnerability Impact": "Security feature bypass" }, { "Authentication required to exploit?": "Yes", "CVE number(s)": "CVE-2026-47992", "CVSS base score": "7.2", "CVSS vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H", "Exploit requires admin privileges?": "Yes", "Notes": null, "Severity": "Critical", "Vulnerability Category": "Improper Input Validation ( CWE-20 )", "Vulnerability Impact": "Privilege escalation" }, { "Authentication required to exploit?": "No", "CVE number(s)": "CVE-2026-47997", "CVSS base score": "5.9", "CVSS vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "Exploit requires admin privileges?": "No", "Notes": null, "Severity": "Important", "Vulnerability Category": "Incorrect Authorization ( CWE-863 )", "Vulnerability Impact": "Security feature bypass" }, { "Authentication required to exploit?": "No", "CVE number(s)": "CVE-2026-47998", "CVSS base score": "5.9", "CVSS vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "Exploit requires admin privileges?": "No", "Notes": null, "Severity": "Important", "Vulnerability Category": "Incorrect Authorization ( CWE-863 )", "Vulnerability Impact": "Security feature bypass" }, { "Authentication required to exploit?": "Yes", "CVE number(s)": "CVE-2026-48371", "CVSS base score": "5.4", "CVSS vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N", "Exploit requires admin privileges?": "Yes", "Notes": null, "Severity": "Important", "Vulnerability Category": "Cross-site Scripting (Stored XSS) ( CWE-79 )", "Vulnerability Impact": "Arbitrary code execution" }, { "Authentication required to exploit?": "Yes", "CVE number(s)": "CVE-2026-47999", "CVSS base score": "4.8", "CVSS vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N", "Exploit requires admin privileges?": "Yes", "Notes": null, "Severity": "Important", "Vulnerability Category": "Cross-site Scripting (Stored XSS) ( CWE-79 )", "Vulnerability Impact": "Arbitrary code execution" }, { "Authentication required to exploit?": "Yes", "CVE number(s)": "CVE-2026-48000", "CVSS base score": "4.3", "CVSS vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N", "Exploit requires admin privileges?": "Yes", "Notes": null, "Severity": "Moderate", "Vulnerability Category": "URL Redirection to Untrusted Site ('Open Redirect') ( CWE-601 )", "Vulnerability Impact": "Security feature bypass" }, { "Authentication required to exploit?": "No", "CVE number(s)": "CVE-2026-48001", "CVSS base score": "3.7", "CVSS vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N", "Exploit requires admin privileges?": "No", "Notes": null, "Severity": "Moderate", "Vulnerability Category": "Information Exposure ( CWE-200 )", "Vulnerability Impact": "Security feature bypass" } ], "vulnerability_paragraphs": [ "Authentication required to exploit: The vulnerability is (or is not) exploitable without credentials.", "Exploit requires admin privileges: The vulnerability is (or is not) only exploitable by an attacker with administrative privileges." ] }