Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
12 / 12 results
criticalbug_reportVulnerabilityAdobe Commerce critical vulnerability under active exploitation
Adobe Commerce (formerly Magento). Specific affected versions not disclosed in advisory. All unpatched instances should be considered at risk.
criticalbug_reportVulnerabilityAdobe Commerce/Magento flaw CVE-2026-71362 exploited to hijack accounts
Adobe Commerce and Magento Open Source e-commerce platforms, all currently supported release lines. The vulnerability affects customer account session handling and requires no authentication to exploit.
criticalbug_reportVulnerabilityAdobe patches three CVSS 10.0 flaws in ColdFusion and Campaign Classic
Adobe ColdFusion 2025.0.x (prior to 2025.0.12) and 2023.0.x (prior to 2023.0.23); Adobe Campaign Classic v7 (prior to 7.4.4 build 9400) on-premise and hybrid deployments; Adobe Commerce (version not specified).
highperson_alertThreat ActorSMOKE#SCREEN Campaign Deploys ScreenConnect via Fake Software Updates
SMOKE#SCREEN is an unattributed multi-wave campaign active as of August 2026 that leverages social engineering to deploy ConnectWise ScreenConnect RMM software for persistent remote access.
criticalbug_reportVulnerabilityAdobe Campaign Classic CVSS 10.0 flaw allows code execution without interaction
Adobe Campaign Classic (ACC) v7 versions prior to 7.4.3 build 9398 on Windows and Linux. The vulnerability affects the enterprise marketing automation platform used for customer campaign management.
criticalbug_reportVulnerabilityAdobe Campaign Classic critical RCE and file read flaws require patching
Adobe Campaign Classic (specific versions not disclosed in advisory). Two vulnerabilities: one critical severity enabling arbitrary code execution, one high severity allowing file system read access.
highbug_reportVulnerabilityAdobe Acrobat Chrome extension flaw allows WhatsApp data theft via UXSS
Adobe Acrobat Chrome extension (ID: efaidnbmnnnibpcajpcglclefindmkaj) versions up to and including 26.5.2.2. Affects 314+ million users. Exploitation impacts any web application data accessible in victim's browser, demonstrated against WhatsApp Web.
highbug_reportVulnerabilityAdobe Acrobat Chrome extension flaw exposed WhatsApp Web chats
Adobe Acrobat extension for Chrome versions 26.5.2.1 and below. Affects approximately 329 million browser installations. Exploitation requires victim to visit attacker-controlled webpage while extension is installed and WhatsApp Web is in use.
criticalbug_reportVulnerabilityCISA orders patching of actively exploited Adobe ColdFusion flaw
Adobe ColdFusion commercial web application development platform. Specific affected versions not disclosed in summary, but CISA mandatory patching order indicates government-facing installations are priority targets.
highbug_reportVulnerabilityPhishing campaign targets marketing professionals via fake job interviews
Marketing professionals with Google accounts; campaign impersonates 30+ brands including Adobe, Netflix, Coca-Cola, OpenAI. Credential theft targeting Google accounts specifically.
criticalbug_reportVulnerabilityAdobe ColdFusion CVE-2026-48282 under active exploitation
Adobe ColdFusion (specific versions not disclosed). Maximum severity vulnerability actively exploited in the wild.
criticalbug_reportVulnerabilityAdobe patches CVSS 10.0 flaws in ColdFusion and Campaign Classic
Adobe ColdFusion and Adobe Campaign Classic (specific versions not provided). Vulnerabilities include arbitrary code execution, privilege escalation, arbitrary file system read, and security feature bypass.