tag: Adobe · 2 items
- Engineer — Plan: CVSS 10.0 OS command injection in ColdFusion and companion critical flaws in Commerce and Campaign Classic warrant prioritized patching this sprint. No KEV listing or public PoC yet, but severity justifies treating this ahead of routine patch cycles — apply Adobe’s August updates to all three products immediately.
- SOC/IR — Skip
- Leader — Skip
- Signals: CVE-2026-48362 — CISA KEV: not listed, EPSS n/a, no public PoC found
- Engineer — Plan: Audit enterprise Chrome extension policies to confirm the Adobe Acrobat extension is at current patched version; consider restricting extension permissions via managed browser policy if update cadence is slow.
- SOC/IR — Learn: No active exploitation or IOCs reported; file as a reference for understanding cross-origin data leakage via browser extension privilege abuse if hunting similar patterns later.
- Leader — Skip