Premier Ministre S.G.D.S.N Agence nationalede la sécurité dessystèmes d'information Paris, le 09 septembre 2026 N° CERTFR-2026-AVI-1140 Affaire suivie par: CERT-FR Avis du CERT-FR Objet: Multiples vulnérabilités dans les produits Adobe Gestion du document Référence CERTFR-2026-AVI-1140 Titre Multiples vulnérabilités dans les produits Adobe Date de la première version09 septembre 2026 Date de la dernière version09 septembre 2026 Source(s) Bulletin de sécurité Adobe APSB26-119 du 08 septembre 2026Bulletin de sécurité Adobe APSB26-138 du 08 septembre 2026Bulletin de sécurité Adobe APSB26-141 du 08 septembre 2026 Une gestion de version détaillée se trouve à la fin de ce document. Risques Atteinte à la confidentialité des données Contournement de la politique de sécurité Déni de service à distance Exécution de code arbitraire à distance Injection de code indirecte à distance (XSS) Injection SQL (SQLi) Élévation de privilèges Systèmes affectés Acrobat 2024 versions antérieures à 24.001.30429 pour Windows et macOS Acrobat Reader versions antérieures à 26.002.21901 pour Windows et macOS Adobe Acrobat versions antérieures à 26.002.21901 pour Windows et macOS Adobe Commerce B2B versions 1.3.4-x antérieures à 1.3.4-2026-sep Adobe Commerce B2B versions 1.4.x antérieures à 1.4.2-2026-sep Adobe Commerce B2B versions 1.5.2-x antérieures à 1.5.2-2026-sep Adobe Commerce B2B versions 1.5.3-x antérieures à 1.5.3-2026-sep Adobe Commerce B2B versions antérieures à 1.3.3-2026-sep Adobe Commerce versions 2.4.5-x antérieures à 2.4.5-2026-sep Adobe Commerce versions 2.4.6-x antérieures à 2.4.6-2026-sep Adobe Commerce versions 2.4.7-x antérieures à 2.4.7-2026-sep Adobe Commerce versions 2.4.8-x antérieures à 2.4.8-2026-sep Adobe Commerce versions 2.4.9-x antérieures à 2.4.9-2026-sep Adobe Commerce versions antérieures à 2.4.4-2026-sep ColdFusion 2023 versions antérieures à 2023.0.24 ColdFusion 2025 versions antérieures à 2025.0.13 Magento Open Source versions 2.4.8-x antérieures à 2.4.8-2026-sep Magento Open Source versions 2.4.9-x antérieures à 2.4.9-2026-sep Magento Open Source versions antérieures à 2.4.7-2026-sep Résumé De multiples vulnérabilités ont été découvertes dans les produits Adobe. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
Solutions Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation). Documentation Bulletin de sécurité Adobe APSB26-119 du 08 septembre 2026 https://helpx.adobe.com/security/products/coldfusion/apsb26-119.html Bulletin de sécurité Adobe APSB26-138 du 08 septembre 2026 https://helpx.adobe.com/security/products/magento/apsb26-138.html Bulletin de sécurité Adobe APSB26-141 du 08 septembre 2026 https://helpx.adobe.com/security/products/acrobat/apsb26-141.html Référence CVE CVE-2026-21269 https://www.cve.org/CVERecord?id=CVE-2026-21269 Référence CVE CVE-2026-48273 https://www.cve.org/CVERecord?id=CVE-2026-48273 Référence CVE CVE-2026-75746 https://www.cve.org/CVERecord?id=CVE-2026-75746 Référence CVE CVE-2026-75993 https://www.cve.org/CVERecord?id=CVE-2026-75993 Référence CVE CVE-2026-75998 https://www.cve.org/CVERecord?id=CVE-2026-75998 Référence CVE CVE-2026-75999 https://www.cve.org/CVERecord?id=CVE-2026-75999 Référence CVE CVE-2026-76000 https://www.cve.org/CVERecord?id=CVE-2026-76000 Référence CVE CVE-2026-76002 https://www.cve.org/CVERecord?id=CVE-2026-76002 Référence CVE CVE-2026-76190 https://www.cve.org/CVERecord?id=CVE-2026-76190 Référence CVE CVE-2026-76200 https://www.cve.org/CVERecord?id=CVE-2026-76200 Référence CVE CVE-2026-76201 https://www.cve.org/CVERecord?id=CVE-2026-76201 Référence CVE CVE-2026-76202 https://www.cve.org/CVERecord?id=CVE-2026-76202 Référence CVE CVE-2026-77108 https://www.cve.org/CVERecord?id=CVE-2026-77108 Référence CVE CVE-2026-77109 https://www.cve.org/CVERecord?id=CVE-2026-77109 Référence CVE CVE-2026-77110 https://www.cve.org/CVERecord?id=CVE-2026-77110 Référence CVE CVE-2026-77111 https://www.cve.org/CVERecord?id=CVE-2026-77111 Référence CVE CVE-2026-77774 https://www.cve.org/CVERecord?id=CVE-2026-77774 Référence CVE CVE-2026-79907 https://www.cve.org/CVERecord?id=CVE-2026-79907 Référence CVE CVE-2026-79908 https://www.cve.org/CVERecord?id=CVE-2026-79908 Référence CVE CVE-2026-79909 https://www.cve.org/CVERecord?id=CVE-2026-79909 Référence CVE CVE-2026-79910 https://www.cve.org/CVERecord?id=CVE-2026-79910 Référence CVE CVE-2026-80159 https://www.cve.org/CVERecord?id=CVE-2026-80159 Référence CVE CVE-2026-80160 https://www.cve.org/CVERecord?id=CVE-2026-80160 Référence CVE CVE-2026-80161 https://www.cve.org/CVERecord?id=CVE-2026-80161 Référence CVE CVE-2026-80162 https://www.cve.org/CVERecord?id=CVE-2026-80162 Référence CVE CVE-2026-81973 https://www.cve.org/CVERecord?id=CVE-2026-81973 Référence CVE CVE-2026-81975 https://www.cve.org/CVERecord?id=CVE-2026-81975 Référence CVE CVE-2026-81976 https://www.cve.org/CVERecord?id=CVE-2026-81976 Référence CVE CVE-2026-81977 https://www.cve.org/CVERecord?id=CVE-2026-81977 Référence CVE CVE-2026-81978 https://www.cve.org/CVERecord?id=CVE-2026-81978 Référence CVE CVE-2026-81979 https://www.cve.org/CVERecord?id=CVE-2026-81979 Référence CVE CVE-2026-81980 https://www.cve.org/CVERecord?id=CVE-2026-81980 Référence CVE CVE-2026-81981 https://www.cve.org/CVERecord?id=CVE-2026-81981 Référence CVE CVE-2026-81982 https://www.cve.org/CVERecord?id=CVE-2026-81982 Référence CVE CVE-2026-81983 https://www.cve.org/CVERecord?id=CVE-2026-81983 Référence CVE CVE-2026-81984 https://www.cve.org/CVERecord?id=CVE-2026-81984 Référence CVE CVE-2026-81985 https://www.cve.org/CVERecord?id=CVE-2026-81985 Référence CVE CVE-2026-81986 https://www.cve.org/CVERecord?id=CVE-2026-81986 Référence CVE CVE-2026-81987 https://www.cve.org/CVERecord?id=CVE-2026-81987 Référence CVE CVE-2026-81988 https://www.cve.org/CVERecord?id=CVE-2026-81988 Référence CVE CVE-2026-81989 https://www.cve.org/CVERecord?id=CVE-2026-81989 Référence CVE CVE-2026-81990 https://www.cve.org/CVERecord?id=CVE-2026-81990 Référence CVE CVE-2026-81991 https://www.cve.org/CVERecord?id=CVE-2026-81991 Référence CVE CVE-2026-81992 https://www.cve.org/CVERecord?id=CVE-2026-81992 Référence CVE CVE-2026-81993 https://www.cve.org/CVERecord?id=CVE-2026-81993 Référence CVE CVE-2026-81994 https://www.cve.org/CVERecord?id=CVE-2026-81994 Référence CVE CVE-2026-81996 https://www.cve.org/CVERecord?id=CVE-2026-81996 Référence CVE CVE-2026-81997 https://www.cve.org/CVERecord?id=CVE-2026-81997 Référence CVE CVE-2026-82001 https://www.cve.org/CVERecord?id=CVE-2026-82001 Gestion détaillée du document le 09 septembre 2026 Version initiale