Skip to content
Rush Commerce
Software & Dev3 min read

Adobe twice-monthly patches: your window just halved

Adobe now ships security bulletins on the second and fourth Tuesday, blaming AI-accelerated vulnerability discovery. Your patch cadence has to move with it.

Adobe now publishes security bulletins twice a month instead of once. The second of those lands tomorrow. If your patch process was built around one predictable Tuesday, it just stopped matching reality — and Adobe's stated reason for the change is worth reading closely, because it applies to every vendor you run.

What actually happened

Effective July 14, 2026, Adobe moved its security bulletins and advisories from monthly to twice-monthly publication, landing on the second and fourth Tuesday of each month. It covers every bulletin and advisory carrying a formally published CVE that requires customer action. Out-of-band releases for actively exploited or externally reported zero-days still happen on their own schedule.

The reasoning is the interesting part. Adobe says frontier AI models and agentic analysis tooling "now uncover flaws across large codebases far faster than traditional methods could," and that those tools are already surfacing critical-risk vulnerabilities that point-in-time review would have missed. The company also notes the same capability is available to attackers, and that the gap between public disclosure and active exploitation is "compressing from days to hours."

Adobe isn't alone in re-cutting its calendar. Oracle began shipping monthly Critical Security Patch Updates on May 28, 2026, aligned to the third Tuesday, layered on top of — not replacing — its quarterly Critical Patch Updates. Two large vendors independently decided the old rhythm was too slow.

Why a faster patch cadence matters for your business

Small teams patch on a human schedule: someone gets to it. That worked when the exploit window was measured in weeks. It does not work when the vendor itself is telling you the window is hours, and it definitely doesn't work when the number of bulletins per year doubles.

Three concrete moves. Put the dates on a calendar with an owner. Second Tuesday, fourth Tuesday, Oracle's third Tuesday, Microsoft's second Tuesday — those are known in advance, so the scheduling problem is already solved for you. Know what you actually run. Most operators can't answer "do we have ColdFusion anywhere" in under an hour, which means the first step of every patch cycle is discovery instead of remediation. A one-page inventory of internet-facing software and versions fixes that permanently. And separate patch from deploy. If applying an update requires a person to log into a box, you'll skip it. If it's a pipeline step, you won't.

The vendor cadence is not the constraint anymore. Yours is.

Key takeaways

  • Adobe moved to twice-monthly security bulletins effective July 14, 2026 — second and fourth Tuesday, for any advisory with a CVE requiring customer action
  • Adobe attributes the change to AI and agentic tooling finding flaws faster, and to the disclosure-to-exploitation window "compressing from days to hours"
  • Oracle layered monthly Critical Security Patch Updates on top of its quarterly CPUs starting May 28, 2026 — the same pressure, a different vendor
  • Fix the two things you control: a current inventory of what you run and internet-facing, and a patch path that doesn't require a human on a console

If nobody owns "what version are we on," the patch cadence doesn't matter. We build the boring layer — inventory, update pipelines, and alerting that names the system instead of the CVE. See what we automate, or tell us what you're running and we'll map the exposure.

Sources: Adobe Security Blog, Oracle Security Blog, CSO Online.

  • #patch-management
  • #adobe
  • #vulnerabilities
  • #security
  • #ai-security
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.