No known open bulletins for this release.
-
Improper input validation in the Web API's service input processor (CVE-2025-54236), publicly known as SessionReaper. An unauthenticated attacker can hijack customer sessions through the REST API and, depending on configuration, reach remote code execution. Adobe shipped the out-of-band hotfix VULN-32437 before the regular patch release; it was the first emergency patch since CosmicSting.
-
Improper access control (CVE-2025-49557) and related flaws that let an attacker bypass security features and reach functionality that should require authorization. Shipped with the regular August 2025 patch set for the 2.4.4 to 2.4.8 lines.
-
Stored cross-site scripting in the admin panel (CVE-2025-47110) that can be chained into arbitrary code execution when an administrator views the injected content. Fixed in the June 2025 patch set, including 2.4.8-p1.
-
Improper authorization (CVE-2025-27189) allowing a security feature bypass, published alongside the 2.4.8 general availability release. Older lines receive the fix through their April 2025 patch versions.
-
Improper authorization (CVE-2025-24434) that lets a low-privileged actor escalate privileges; Adobe rated it critical because exploitation does not require user interaction. Fixed in the February 2025 patch set.
-
Improper authentication (CVE-2024-45115) that allows privilege escalation without prior authentication. Part of the October 2024 patch set that followed the CosmicSting exploitation wave.
-
Unrestricted upload of a file with a dangerous type (CVE-2024-39397) allowing arbitrary code execution by an unauthenticated attacker; Adobe notes the exploit requires the Apache web server. Fixed in the August 2024 patch set.
-
XML external entity injection in the REST API (CVE-2024-34102), publicly known as CosmicSting. An unauthenticated attacker can read arbitrary files such as env.php and, chained with the glibc iconv bug CVE-2024-2961, execute code. Mass exploitation followed within weeks; Adobe also released an isolated patch for stores that could not upgrade.
-
APSB24-18
critical
CVE-2024-20758, CVE-2024-20759
inherited from 2.4.7
Improper input validation (CVE-2024-20758) enabling arbitrary code execution by an authenticated administrator, plus stored cross-site scripting (CVE-2024-20759). Published with the 2.4.7 general availability release and the April 2024 patch set.