Shortly after its public disclosure, hackers began exploiting a serious vulnerability in Adobe Commerce known as CVE-2026-71362, which has a CVSS score of 9.1. This flaw allows attackers to hijack customer accounts without needing authentication, potentially exposing sensitive user data. Businesses using Adobe Commerce should be particularly vigilant, as this vulnerability could lead to unauthorized access to customer information and significant privacy breaches. The urgency of the situation is heightened by the rapid targeting of the flaw by cybercriminals, making it critical for affected organizations to act quickly to safeguard their systems and user data.
Researchers have identified a critical vulnerability (CVE-2026-71362) in Adobe's Commerce and Magento e-commerce platforms that could allow hackers to take control of customer accounts. This flaw impacts businesses using these platforms, raising serious concerns for online retailers and their customers. Attackers could exploit this vulnerability to gain unauthorized access to sensitive user information, potentially leading to identity theft and financial fraud. As attempts to exploit this flaw have already been detected, it's crucial for affected users to take immediate action to secure their accounts. The situation underscores the ongoing risks faced by e-commerce platforms and the need for timely software updates.
Adobe has released important security updates to address multiple critical vulnerabilities affecting its ColdFusion, Commerce, and Campaign Classic products. Among these, the most serious is a command injection flaw in ColdFusion, identified as CVE-2026-48362, which has a maximum severity score of 10.0 on the CVSS scale. If exploited, this vulnerability could allow attackers to execute arbitrary code on affected systems, leading to potential privilege escalation. This is particularly concerning for organizations that rely on these Adobe products, as successful exploitation could compromise sensitive data and system integrity. Users are strongly advised to apply the latest patches to mitigate these risks.
Adobe has issued a warning for users of its ColdFusion and Campaign Classic products to address serious security flaws that could allow attackers to execute arbitrary code or cause denial-of-service attacks. These vulnerabilities pose significant risks, as they could let malicious actors take control of systems or disrupt services. Users of these applications are urged to prioritize patching to protect their data and ensure operational continuity. The company has not specified if these vulnerabilities are currently being exploited in the wild, but the urgency of the advisory indicates a pressing need for action. Patching is essential to mitigate the risks posed by these flaws.
A new campaign known as SMOKE#SCREEN has been identified by Securonix Threat Research, where attackers are using deceptive tactics to gain unauthorized remote access to systems. The attackers are distributing fake Zoom updates and other social engineering lures to install ScreenConnect, a remote management tool, on victims' devices. This allows them to maintain persistent access while evading security measures. The campaign is ongoing and utilizes various methods, including notices about Adobe software and system maintenance prompts, making it particularly insidious. Organizations and individuals should be vigilant about such fraudulent updates and take necessary precautions to protect their systems.
Russian hackers have reportedly hijacked hotel Wi-Fi networks to steal Microsoft 365 authentication tokens from unsuspecting users. This technique allows attackers to gain access to sensitive accounts without needing the users' passwords. The incident primarily affects travelers and guests using hotel Wi-Fi, who may unknowingly expose their credentials while accessing their Microsoft accounts. This type of attack raises significant concerns about the security of public internet connections and the potential for widespread account takeovers. Users should be cautious when connecting to hotel Wi-Fi and consider using a VPN to protect their data.
Adobe has addressed a serious security vulnerability in its Campaign Classic (ACC) platform, which is used for enterprise marketing automation. The flaw, identified as CVE-2026-48449, has a maximum severity score of 10.0, indicating it could allow attackers to execute arbitrary code without any user interaction. This issue stems from incorrect authorization processes within the software. Organizations using Adobe Campaign Classic need to apply the latest security updates to protect against potential exploitation, as the implications of this vulnerability could lead to unauthorized access and control over sensitive marketing data. Prompt action is essential to ensure the security of systems relying on this platform.
Cybersecurity researchers have identified a serious vulnerability in the Adobe Acrobat Chrome extension, which has around 314 million users. This flaw, known as HermeticReader and tracked as CVE-2026-48294, could allow malicious websites to access users' WhatsApp Web data without their knowledge. The vulnerability has a CVSS score of 7.4, indicating it poses a significant risk. Adobe has patched this issue, but it raises concerns about the security of extensions and the potential for data breaches. Users of the Adobe Acrobat extension should ensure they have updated to the latest version to protect their data.
A security flaw in the Adobe Acrobat extension for Chrome has been identified, allowing unauthorized access to private WhatsApp chats when users are logged into WhatsApp Web. This issue arises because the extension does not require any authentication to access data displayed in the chat interface. As a result, malicious actors could potentially view sensitive conversations without the user's knowledge. The vulnerability raises concerns about user privacy, especially given the popularity of WhatsApp for personal and business communications. Users of the Adobe Acrobat extension should be aware of this risk and consider disabling the extension until a fix is provided.
Mozilla has rolled out updates for Firefox to fix two serious vulnerabilities that could be exploited by attackers. The flaws, identified as CVE-2026-15718 and CVE-2026-15719, involve issues with JavaScript: WebAssembly and site isolation in the DOM: Navigation component. Mozilla has warned users that exploit code for these vulnerabilities is already available publicly, increasing the urgency for users to update. It’s crucial for Firefox users to install these updates promptly to protect against potential attacks that could compromise their security and privacy. Keeping software up to date is a key defense against such risks.
Adobe has released patches to address serious vulnerabilities in ColdFusion that could allow attackers to run arbitrary code or gain elevated privileges. These flaws pose a significant risk to users and organizations that rely on ColdFusion for web applications. If exploited, they could lead to unauthorized access and potential data breaches. It’s crucial for affected users to apply these updates as soon as possible to protect their systems from potential attacks. Adobe's quick response highlights the ongoing need for vigilance in maintaining software security.
The Department of Homeland Security (DHS) has reported a significant data breach involving one of its databases, although specific details about the extent of the breach or the data compromised have not been disclosed. Meanwhile, Adobe is increasing the frequency of its security updates to better protect users from vulnerabilities, responding to the growing number of cyber threats. In another development, Canadian authorities have successfully disrupted ransomware operations, which is a crucial step in combating the rise of these attacks. Additionally, a data breach at AssuranceAmerica has put the personal information of around 7 million individuals at risk. This series of events illustrates the ongoing challenges organizations face in safeguarding sensitive data and the need for improved security measures across various sectors.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog due to evidence of active exploitation. One of the most critical is CVE-2026-48282, a path traversal vulnerability in Adobe ColdFusion that could allow attackers to execute arbitrary code. This flaw has a maximum CVSS score of 10.0, indicating its severity. Additionally, vulnerabilities in Joomla and Langflow have also been flagged, though specific details about those flaws were not provided in the article. Organizations using affected products should prioritize applying patches and updates to mitigate these risks, as exploitation in the wild can lead to significant data breaches or system compromises.
CISA has added a new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, specifically CVE-2026-48282, which affects Adobe ColdFusion. This path traversal vulnerability allows attackers to gain unauthorized access and control over affected systems, posing significant risks, particularly to federal agencies. The Binding Operational Directive (BOD) 26-04 emphasizes the need for federal agencies to address high-risk vulnerabilities quickly, while also encouraging all organizations to adopt similar risk-based vulnerability management practices. CISA will continue to update the catalog as new vulnerabilities are identified, and organizations are urged to report any exploited vulnerabilities not currently listed. Rapid remediation is essential to mitigate potential exploitation risks.
Hackers are taking advantage of a serious vulnerability in Adobe ColdFusion, which has a maximum severity score of 10.0 on the CVSS scale, indicating it poses a significant risk. This flaw allows attackers to execute arbitrary code, potentially compromising systems and accessing sensitive data. Organizations using affected versions of ColdFusion should take immediate action to protect their environments. Adobe has not specified the exact versions impacted, but users of ColdFusion should assume they are at risk if they haven't updated. The fact that this vulnerability is actively being exploited makes it crucial for companies to apply any available patches and review their security measures.