Risques
- Atteinte à la confidentialité des données
- Contournement de la politique de sécurité
- Déni de service à distance
- Exécution de code arbitraire à distance
- Injection de code indirecte à distance (XSS)
- Non spécifié par l'éditeur
- Élévation de privilèges
Systèmes affectés
- Adobe Commerce B2B sans le correctif d'août 2026
- Adobe Commerce sans le correctif d'août 2026
- ColdFusion 2023 versions antérieures à 2023.0.23
- ColdFusion 2025 versions antérieures à 2025.0.12
- Magento Open Source sans le correctif d'août 2026
Résumé
De multiples vulnérabilités ont été découvertes dans les produits Adobe. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
Solutions
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).
Documentation
- Bulletin de sécurité Adobe APSB26-90 du 11 août 2026 https://helpx.adobe.com/security/products/coldfusion/apsb26-90.html
- Bulletin de sécurité Adobe APSB26-92 du 11 août 2026 https://helpx.adobe.com/security/products/magento/apsb26-92.html
- Référence CVE CVE-2026-21273 https://www.cve.org/CVERecord?id=CVE-2026-21273
- Référence CVE CVE-2026-21279 https://www.cve.org/CVERecord?id=CVE-2026-21279
- Référence CVE CVE-2026-25652 https://www.cve.org/CVERecord?id=CVE-2026-25652
- Référence CVE CVE-2026-34635 https://www.cve.org/CVERecord?id=CVE-2026-34635
- Référence CVE CVE-2026-48273 https://www.cve.org/CVERecord?id=CVE-2026-48273
- Référence CVE CVE-2026-48362 https://www.cve.org/CVERecord?id=CVE-2026-48362
- Référence CVE CVE-2026-48375 https://www.cve.org/CVERecord?id=CVE-2026-48375
- Référence CVE CVE-2026-48376 https://www.cve.org/CVERecord?id=CVE-2026-48376
- Référence CVE CVE-2026-48384 https://www.cve.org/CVERecord?id=CVE-2026-48384
- Référence CVE CVE-2026-48386 https://www.cve.org/CVERecord?id=CVE-2026-48386
- Référence CVE CVE-2026-48411 https://www.cve.org/CVERecord?id=CVE-2026-48411
- Référence CVE CVE-2026-48412 https://www.cve.org/CVERecord?id=CVE-2026-48412
- Référence CVE CVE-2026-48413 https://www.cve.org/CVERecord?id=CVE-2026-48413
- Référence CVE CVE-2026-48414 https://www.cve.org/CVERecord?id=CVE-2026-48414
- Référence CVE CVE-2026-48415 https://www.cve.org/CVERecord?id=CVE-2026-48415
- Référence CVE CVE-2026-48416 https://www.cve.org/CVERecord?id=CVE-2026-48416
- Référence CVE CVE-2026-48440 https://www.cve.org/CVERecord?id=CVE-2026-48440
- Référence CVE CVE-2026-71362 https://www.cve.org/CVERecord?id=CVE-2026-71362
- Référence CVE CVE-2026-71383 https://www.cve.org/CVERecord?id=CVE-2026-71383
- Référence CVE CVE-2026-71384 https://www.cve.org/CVERecord?id=CVE-2026-71384
- Référence CVE CVE-2026-71385 https://www.cve.org/CVERecord?id=CVE-2026-71385
- Référence CVE CVE-2026-71386 https://www.cve.org/CVERecord?id=CVE-2026-71386
- Référence CVE CVE-2026-71387 https://www.cve.org/CVERecord?id=CVE-2026-71387