Skip to main content

Adobe Monthly Security Update (September 2025)

Last Update Date: 23 Oct 2025 Release Date: 10 Sep 2025 16225 Views

RISK: High Risk

TYPE: Clients - Productivity Products

TYPE: Productivity Products

Adobe has released monthly security update for their products:

 

Vulnerable ProductRisk LevelImpactsNotesDetails (including CVE)
Adobe Acrobat and ReaderMedium Risk Medium RiskRemote Code Execution
Security Restriction Bypass
 APSB25-85
Adobe After EffectsMedium Risk Medium RiskInformation Disclosure APSB25-86
Adobe Premiere ProMedium Risk Medium RiskRemote Code Execution APSB25-87
Adobe CommerceHigh Risk High RiskSecurity Restriction BypassCVE-2025-54236 is being exploited in the wild. Due to insufficient validation of user-supplied input. A remote non-authenticated attacker can pass specially crafted input to the application and execute arbitrary code on the system.APSB25-88
Substance 3D ViewerMedium Risk Medium RiskRemote Code Execution APSB25-89
Adobe Experience ManagerMedium Risk Medium RiskSecurity Restriction Bypass
Cross-site Scripting
 APSB25-90
Adobe DreamweaverMedium Risk Medium RiskRemote Code Execution APSB25-91
Substance 3D ModelerMedium Risk Medium RiskRemote Code Execution APSB25-92
Adobe ColdFusionMedium Risk Medium RiskData Manipulation APSB25-93

 

Number of 'Extremely High Risk' product(s): 0

Number of 'High Risk' product(s): 1

Number of 'Medium Risk' product(s): 8

Number of 'Low Risk' product(s): 0

Evaluation of overall 'Risk Level': High Risk

 

 

[Updated on 2025-10-23]

Updated Description, Risk Level, Solutions and Related Links.


Impact

  • Remote Code Execution
  • Cross-Site Scripting
  • Security Restriction Bypass
  • Information Disclosure
  • Data Manipulation

System / Technologies affected

  • Acrobat DC Win - 25.001.20672 and earlier versions
  • Acrobat DC Mac - 25.001.20668 and earlier versions
  • Acrobat Reader DC Win - 25.001.20672 and earlier versions
  • Acrobat Reader DC Mac - 25.001.20668 and earlier versions
  • Acrobat 2024 Win & Mac - 24.001.30254 and earlier versions
  • Acrobat 2020 Win & Mac - 20.005.30774 and earlier versions
  • Acrobat Reader 2020 Win & Mac - 20.005.30774 and earlier versions
  • Adobe After Effects 24.6.7 and earlier versions
  • Adobe After Effects 25.3 and earlier versions
  • Adobe Premiere Pro 25.3 and earlier versions
  • Adobe Premiere Pro 24.6.5 and earlier versions
  • Adobe Commerce 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier versions
  • Adobe Commerce B2B 1.5.3-alpha2, 1.5.2-p2, 1.4.2-p7, 1.3.4-p14, 1.3.3-p15 and earlier versions
  • Magento Open Source 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14 and earlier versions
  • Adobe Substance 3D Viewer 0.25.1 and earlier versions
  • Adobe Experience Manager (AEM) AEM Cloud Service (CS)
  • Adobe Experience Manager (AEM) 6.5 LTS SP1, 6.5.23 and earlier versions
  • Adobe Dreamweaver  21.5 and earlier versions
  • Adobe Substance 3D Modeler 1.22.2 and earlier versions
  • ColdFusion 2025 Update 3 and earlier versions
  • ColdFusion 2023 Update 15 and earlier versions
  • ColdFusion 2021 Update 21 and earlier versions

Solutions

Before installation of the software, please visit the vendor web-site for more details.

  • Apply fixes issued by the vendor. Please refer to 'Details' column in the above table for details of individual product update or run software update.

Vulnerability Identifier


Source


Related Link