Adobe patches critical Connect and AEM Forms code execution bugs
Adobe shipped fixes for nine critical flaws across Connect and AEM Forms on September 23, rated priority 2. Not exploited yet — which is exactly when patching is cheap.
Adobe shipped patches for nine critical vulnerabilities across Connect and AEM Forms on September 23. Six critical bugs in Adobe Connect and three in Experience Manager Forms, all leading to arbitrary code execution or privilege escalation, per SecurityWeek's breakdown. Adobe rated both updates priority 2 — patch within 30 days — and says none are exploited in the wild. That combination is the best patching window you will ever get, and it is the one most teams sleep through.
What actually happened
Adobe Connect got nine fixes, six of them critical: CVE-2026-75682, CVE-2026-75684, CVE-2026-75686, CVE-2026-75689, CVE-2026-75697 and CVE-2026-75698. The classes are SQL injection, cross-site scripting and improper input validation, with impact described as arbitrary code execution and privilege escalation. Three high-severity issues — path traversal, certificate validation and XSS — came along with them.
AEM Forms got six fixes, three critical: CVE-2026-75745 (incorrect authorization), CVE-2026-81995 (improper input validation) and CVE-2026-82000 (server-side request forgery), detailed in Adobe's bulletin APSB26-57. Three more high-severity SSRF, XSS and CSRF bugs were fixed alongside.
Across the full September batch Adobe addressed 36 vulnerabilities, also touching InDesign, Bridge, Premiere Pro, Substance 3D Modeler and the Content Credentials SDK.
Why patch timing matters for your business
Priority 2 means Adobe does not see exploitation yet. Teams read that as "not urgent." It is the opposite — it is the only window where patching is a maintenance task instead of an incident.
The clock starts at disclosure, not at exploitation. CVE numbers and vulnerability classes are now public. "Incorrect authorization in AEM Forms JEE" tells a researcher exactly where to look, and the gap between a published advisory and a working exploit keeps shrinking. You are not racing Adobe. You are racing whoever reads the bulletin with different intentions.
What we actually do for clients on a day like this:
Answer "do we run it" in minutes, not days. You need a current inventory of internet-facing software with versions. If finding out whether you run AEM Forms takes a meeting, your patch window is already half gone.
Patch the exposed instance first. An AEM Forms server accepting public submissions and an internal Connect deployment behind SSO are not the same risk. Sort by reachability, not by CVSS.
Check your vendors, not just your servers. Plenty of small businesses touch Adobe Connect through an agency, a training provider or a marketing partner. Ask them, in writing, when they patched.
Put the 30 days on a calendar with a name on it. Priority 2 items die in backlogs because nobody owns them. A dated ticket with an assignee is the whole practice.
Nobody is being exploited today. That is the entire reason to move today.
Key takeaways
- Adobe patched nine critical flaws on September 23, 2026: six in Connect, three in AEM Forms, all enabling code execution or privilege escalation
- Connect CVEs: 2026-75682, -75684, -75686, -75689, -75697, -75698 (SQL injection, XSS, improper input validation)
- AEM Forms CVEs: 2026-75745 (incorrect authorization), -81995 (input validation), -82000 (SSRF), per bulletin APSB26-57
- Both updates are priority 2 — a 30-day window — and Adobe says none are exploited in the wild
- Patch internet-facing instances first; sort by reachability, not severity score
- Ask agencies and training vendors when they patched — their Adobe stack is your exposure too
Most small businesses cannot answer "what do we run, and what version?" in under an hour. That question is the whole difference between a patch and a breach notification. We build and maintain the systems our clients run, which means we already know the answer on days like this. See what we take off your plate, or ask us to look at what you're running.
Sources: SecurityWeek, Adobe Security Bulletin APSB26-57.
- #security
- #patching
- #adobe
- #vulnerability-management
- #cve
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Reachy Mini CVE-2026-96455: your LAN can install code on it
An unauthenticated POST /apps/install endpoint on the Reachy Mini robot lets any host on the same network run code. AI hardware is an unmanaged endpoint.
Read itGrok 4.7 lands in Copilot — enabled by default
Grok 4.7 ships at the same price as 4.6 and rolls into GitHub Copilot, where new models are on by default until an admin turns them off. Check your model policy.
Read it