Risques
- Atteinte à la confidentialité des données
- Contournement de la politique de sécurité
- Déni de service à distance
- Exécution de code arbitraire à distance
- Injection de code indirecte à distance (XSS)
- Injection SQL (SQLi)
- Élévation de privilèges
Systèmes affectés
- Acrobat 2024 versions antérieures à 24.001.30429 pour Windows et macOS
- Acrobat Reader versions antérieures à 26.002.21901 pour Windows et macOS
- Adobe Acrobat versions antérieures à 26.002.21901 pour Windows et macOS
- Adobe Commerce B2B versions 1.3.4-x antérieures à 1.3.4-2026-sep
- Adobe Commerce B2B versions 1.4.x antérieures à 1.4.2-2026-sep
- Adobe Commerce B2B versions 1.5.2-x antérieures à 1.5.2-2026-sep
- Adobe Commerce B2B versions 1.5.3-x antérieures à 1.5.3-2026-sep
- Adobe Commerce B2B versions antérieures à 1.3.3-2026-sep
- Adobe Commerce versions 2.4.5-x antérieures à 2.4.5-2026-sep
- Adobe Commerce versions 2.4.6-x antérieures à 2.4.6-2026-sep
- Adobe Commerce versions 2.4.7-x antérieures à 2.4.7-2026-sep
- Adobe Commerce versions 2.4.8-x antérieures à 2.4.8-2026-sep
- Adobe Commerce versions 2.4.9-x antérieures à 2.4.9-2026-sep
- Adobe Commerce versions antérieures à 2.4.4-2026-sep
- ColdFusion 2023 versions antérieures à 2023.0.24
- ColdFusion 2025 versions antérieures à 2025.0.13
- Magento Open Source versions 2.4.8-x antérieures à 2.4.8-2026-sep
- Magento Open Source versions 2.4.9-x antérieures à 2.4.9-2026-sep
- Magento Open Source versions antérieures à 2.4.7-2026-sep
Résumé
De multiples vulnérabilités ont été découvertes dans les produits Adobe. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
Solutions
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).
Documentation
- Bulletin de sécurité Adobe APSB26-119 du 08 septembre 2026 https://helpx.adobe.com/security/products/coldfusion/apsb26-119.html
- Bulletin de sécurité Adobe APSB26-138 du 08 septembre 2026 https://helpx.adobe.com/security/products/magento/apsb26-138.html
- Bulletin de sécurité Adobe APSB26-141 du 08 septembre 2026 https://helpx.adobe.com/security/products/acrobat/apsb26-141.html
- Référence CVE CVE-2026-21269 https://www.cve.org/CVERecord?id=CVE-2026-21269
- Référence CVE CVE-2026-48273 https://www.cve.org/CVERecord?id=CVE-2026-48273
- Référence CVE CVE-2026-75746 https://www.cve.org/CVERecord?id=CVE-2026-75746
- Référence CVE CVE-2026-75993 https://www.cve.org/CVERecord?id=CVE-2026-75993
- Référence CVE CVE-2026-75998 https://www.cve.org/CVERecord?id=CVE-2026-75998
- Référence CVE CVE-2026-75999 https://www.cve.org/CVERecord?id=CVE-2026-75999
- Référence CVE CVE-2026-76000 https://www.cve.org/CVERecord?id=CVE-2026-76000
- Référence CVE CVE-2026-76002 https://www.cve.org/CVERecord?id=CVE-2026-76002
- Référence CVE CVE-2026-76190 https://www.cve.org/CVERecord?id=CVE-2026-76190
- Référence CVE CVE-2026-76200 https://www.cve.org/CVERecord?id=CVE-2026-76200
- Référence CVE CVE-2026-76201 https://www.cve.org/CVERecord?id=CVE-2026-76201
- Référence CVE CVE-2026-76202 https://www.cve.org/CVERecord?id=CVE-2026-76202
- Référence CVE CVE-2026-77108 https://www.cve.org/CVERecord?id=CVE-2026-77108
- Référence CVE CVE-2026-77109 https://www.cve.org/CVERecord?id=CVE-2026-77109
- Référence CVE CVE-2026-77110 https://www.cve.org/CVERecord?id=CVE-2026-77110
- Référence CVE CVE-2026-77111 https://www.cve.org/CVERecord?id=CVE-2026-77111
- Référence CVE CVE-2026-77774 https://www.cve.org/CVERecord?id=CVE-2026-77774
- Référence CVE CVE-2026-79907 https://www.cve.org/CVERecord?id=CVE-2026-79907
- Référence CVE CVE-2026-79908 https://www.cve.org/CVERecord?id=CVE-2026-79908
- Référence CVE CVE-2026-79909 https://www.cve.org/CVERecord?id=CVE-2026-79909
- Référence CVE CVE-2026-79910 https://www.cve.org/CVERecord?id=CVE-2026-79910
- Référence CVE CVE-2026-80159 https://www.cve.org/CVERecord?id=CVE-2026-80159
- Référence CVE CVE-2026-80160 https://www.cve.org/CVERecord?id=CVE-2026-80160
- Référence CVE CVE-2026-80161 https://www.cve.org/CVERecord?id=CVE-2026-80161
- Référence CVE CVE-2026-80162 https://www.cve.org/CVERecord?id=CVE-2026-80162
- Référence CVE CVE-2026-81973 https://www.cve.org/CVERecord?id=CVE-2026-81973
- Référence CVE CVE-2026-81975 https://www.cve.org/CVERecord?id=CVE-2026-81975
- Référence CVE CVE-2026-81976 https://www.cve.org/CVERecord?id=CVE-2026-81976
- Référence CVE CVE-2026-81977 https://www.cve.org/CVERecord?id=CVE-2026-81977
- Référence CVE CVE-2026-81978 https://www.cve.org/CVERecord?id=CVE-2026-81978
- Référence CVE CVE-2026-81979 https://www.cve.org/CVERecord?id=CVE-2026-81979
- Référence CVE CVE-2026-81980 https://www.cve.org/CVERecord?id=CVE-2026-81980
- Référence CVE CVE-2026-81981 https://www.cve.org/CVERecord?id=CVE-2026-81981
- Référence CVE CVE-2026-81982 https://www.cve.org/CVERecord?id=CVE-2026-81982
- Référence CVE CVE-2026-81983 https://www.cve.org/CVERecord?id=CVE-2026-81983
- Référence CVE CVE-2026-81984 https://www.cve.org/CVERecord?id=CVE-2026-81984
- Référence CVE CVE-2026-81985 https://www.cve.org/CVERecord?id=CVE-2026-81985
- Référence CVE CVE-2026-81986 https://www.cve.org/CVERecord?id=CVE-2026-81986
- Référence CVE CVE-2026-81987 https://www.cve.org/CVERecord?id=CVE-2026-81987
- Référence CVE CVE-2026-81988 https://www.cve.org/CVERecord?id=CVE-2026-81988
- Référence CVE CVE-2026-81989 https://www.cve.org/CVERecord?id=CVE-2026-81989
- Référence CVE CVE-2026-81990 https://www.cve.org/CVERecord?id=CVE-2026-81990
- Référence CVE CVE-2026-81991 https://www.cve.org/CVERecord?id=CVE-2026-81991
- Référence CVE CVE-2026-81992 https://www.cve.org/CVERecord?id=CVE-2026-81992
- Référence CVE CVE-2026-81993 https://www.cve.org/CVERecord?id=CVE-2026-81993
- Référence CVE CVE-2026-81994 https://www.cve.org/CVERecord?id=CVE-2026-81994
- Référence CVE CVE-2026-81996 https://www.cve.org/CVERecord?id=CVE-2026-81996
- Référence CVE CVE-2026-81997 https://www.cve.org/CVERecord?id=CVE-2026-81997
- Référence CVE CVE-2026-82001 https://www.cve.org/CVERecord?id=CVE-2026-82001