SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Adobe Critical Security Updates Sept 2024

Adobe Critical Security Updates Sept 2024

In September 2024, Adobe has rolled out a series of crucial security updates for several of its major products. This release addresses multiple vulnerabilities across its software suite, including Adobe Media Encoder, Adobe Audition, Adobe After Effects, Adobe Premiere Pro, Adobe Illustrator, Adobe ...

Sep 11, 2024By Sumanth H3 min read

In September 2024, Adobe has rolled out a series of crucial security updates for several of its major products. This release addresses multiple vulnerabilities across its software suite, including Adobe Media Encoder, Adobe Audition, Adobe After Effects, Adobe Premiere Pro, Adobe Illustrator, Adobe Acrobat Reader, Adobe ColdFusion, and Adobe Photoshop. These updates are imperative for safeguarding your systems against potential security threats.

Overview of September 2024 Security Updates

Adobe’s latest security updates tackle various critical vulnerabilities that could potentially lead to significant issues, including arbitrary code execution and memory leaks. Below is a summary of the key updates: 

1.Adobe Media EncoderAdvisory/CVEs: APSB24-53Severity: CriticalAffected Version: Versions 24.5 and earlier, 23.6.8 and earlierImpact: Memory leak and Arbitrary code execution

2.Adobe AuditionAdvisory/CVEs: APSB24-54Severity: CriticalAffected Version: Versions 24.4.1 and earlier, 23.6.6 and earlierImpact: Memory leak and Arbitrary code execution

3.Adobe After EffectsAdvisory/CVEs: APSB24-55Severity: CriticalAffected Version: Versions 24.5 and earlier, 23.6.6 and earlierImpact: Memory leak, Arbitrary code execution and Arbitrary file system write

4.Adobe Premiere ProAdvisory/CVEs: APSB24-58Severity: CriticalAffected Version: Versions 24.5 and earlier, 23.6.8 and earlierImpact: Memory leak and Arbitrary code execution

5.Adobe IllustratorAdvisory/CVEs: APSB24-66Severity: CriticalAffected Version: Illustrator 2024 Versions 28.6 and earlier, Illustrator Versions 2023 27.9.5 and earlierImpact: Memory leak, Arbitrary code execution and Application denial-of-service

6.Adobe Acrobat and? ReaderAdvisory/CVEs: APSB24-70Severity: CriticalAffected Version:i. Adobe Acrobat DC (Continuous) : 24.003.20054 and earlier, 24.002.21005 and earlierii. Adobe Acrobat Reader DC (Continuous) : 24.003.20054 and earlier, 24.002.21005 and earlieriii. Adobe Acrobat 2024 (Classic 2024) : 24.001.30159 and earlieriv. Adobe Acrobat 2020 (Classic 2020) : 20.005.30655 and earlierv. Adobe Acrobat Reader 2020 (Classic 2020) : 20.005.30655 and earlierImpact: Arbitrary code execution

7.Adobe ColdFusionAdvisory/CVEs: APSB24-71Severity: CriticalAffected Version: ColdFusion 2023 Update 9 and earlier, ColdFusion 2021 Update 15 and earlierImpact: Arbitrary code execution

8.Adobe PhotoshopAdvisory/CVEs: APSB24-72Severity: CriticalAffected Version: Photoshop 2023 version 24.7.4 and earlier, Photoshop 2024 version 25.11 and earlierImpact: Arbitrary code execution and Memory leak

The Adobe Critical Security Updates of September 2024 address significant security flaws in a range of Adobe products. By updating to the latest versions, users can protect their systems from vulnerabilities that could otherwise be exploited by attackers. Ensure that your software is up-to-date to benefit from these critical patches. 

Stay informed and stay secure! 

Patch Critical Risks Before its Too Late with SanerNow

SecPod SanerNow CVEM is an integrated vulnerability and patch management solution that can detect, assess, prioritize and remediate vulnerabilities and other security risks in your network automatically. SanerNow supports all major OSs and 550+ third party applications to cover all bases.

SanerNow provides complete provisions to test patches before deployment. Further, you can roll them back if necessary and completely automate the process to ease the burden on your IT and security teams.

Experience next-generation of patching with SanerNow. Schedule a Demo

Featured Posts

Open StyleSmuggler: Inside the Unpatched Magento Zero-Day Backdooring Live Stores
StyleSmuggler: Inside the Unpatched Magento Zero-Day Backdooring Live Stores

CVE Research

StyleSmuggler: Inside the Unpatched Magento Zero-Day Backdooring Live Stores

StyleSmuggler, an unpatched Magento and Adobe Commerce flaw letting attackers execute code without authentication via log poisoning, installing a persistent Linux backdoor that has already compromised live stores with no vendor patch available.

Sep 7, 2026

Open CVE-2026-6471: 12-Year-Old PostgreSQL PostGREShell Flaw Enables Server Takeover
CVE-2026-6471: 12-Year-Old PostgreSQL PostGREShell Vulnerability

CVE Research

CVE-2026-6471: 12-Year-Old PostgreSQL PostGREShell Flaw Enables Server Takeover

Sep 7, 2026

Open Root-Level RCE Flaw in Cisco Nexus 9000 Series Switches Exposes Networks to Complete Compromise — CVE-2026-20212
Root-Level RCE Flaw in Cisco Nexus 9000 Series Switches Exposes Networks to Complete Compromise — CVE-2026-20212

CVE Research

Root-Level RCE Flaw in Cisco Nexus 9000 Series Switches Exposes Networks to Complete Compromise — CVE-2026-20212

CVE-2026-20212 is a critical vulnerability in Cisco Nexus 9000 Series Switches that use Silicon One ASICs. It allows an unauthenticated remote attacker to execute code with root privileges by sending crafted input to TCP ports 43210 and 43211, which are reachable in the default Layer 3 VRF. Exploitation can also crash the S1HAL process and force a device reload. This article covers how the vulnerability works, the affected product identifiers, its potential impact, available workarounds, and how to identify fixed software using the Cisco Software Checker.

Sep 4, 2026

Open SonicWall SMA 1000 Under Active Attack: Two Zero-Days Enable SSRF and Remote Code Execution
SonicWall SMA 1000 Under Active Attack: Two Zero-Days Enable SSRF and Remote Code Execution

CVE Research

SonicWall SMA 1000 Under Active Attack: Two Zero-Days Enable SSRF and Remote Code Execution

Sep 3, 2026