Categories: Vulnerability

Adobe Released Security Updates & Fixes for 112 Vulnerabilities that Affected Adobe Products

Adobe security updates released that cover the updates for Adobe Flash Player, Experience Manager, Connect, Adobe Acrobat, and Reader.

Adobe Flash Player

Adobe released updates for the critical Flash player that affects flash player 30.0.0.113 and it’s earlier versions. By exploiting the vulnerability an attacker can run arbitrary codes without the user’s context.

The Vulnerabilities can be tracked as CVE-2018-5008, CVE-2018-5007 and it was fixed with Adobe Flash Player version 30.0.0.134.

ProductVersionPlatformPriorityAvailability
Adobe Flash Player Desktop Runtime30.0.0.134Windows, macOS2Flash Player Download Center

 

Flash Player Distribution

Adobe Flash Player for Google Chrome30.0.0.134Windows, macOS, Linux, and Chrome OS2Google Chrome Releases
Adobe Flash Player for Microsoft Edge and Internet Explorer 1130.0.0.134Windows 10 and 8.12Microsoft Security Advisory
Adobe Flash Player Desktop Runtime30.0.0.134Linux3Flash Player Download Center

Adobe Experience Manager

Adobe Experience Manager suffers critical Server-Side Request Forgery (SSRF) vulnerabilities, it affects from version 6.0 to 6.4. Adobe categorizes the updates in priority and recommends user’s to install the newest version.

The Vulnerabilities can be tracked as CVE-2018-5004, CVE-2018-5006 and CVE-2018-12809.

Adobe security updates for Adobe Connect

Adobe Connect 9.7.5 and it’s earliest version suffered authentication bypass vulnerability that would result in sensitive information disclosure.

Both of the vulnerabilities fixed with the version 9.8.1, along with that this update also resolves the issues with the session tokens validation.

The Vulnerabilities can be tracked as CVE-2018-4994, CVE-2018-12804 and CVE-2018-12805.

ProductVersionPlatformPriorityAvailability
Adobe Connect9.8.1All2Release note

Adobe Acrobat and Reader

Adobe fixed 104 vulnerabilities with security updates for Adobe Acrobat and Reader for Windows and macOS. It covers critical and important vulnerabilities, successful exploitation of the vulnerability may lead to arbitrary code execution without user’s context.

ProductTrackUpdated VersionsPlatformPriority RatingAvailability
Acrobat DCContinuous2018.011.20055Windows and macOS2Windows
macOS
Acrobat Reader DCContinuous2018.011.20055Windows and macOS2Windows
macOS
Acrobat 2017Classic 20172017.011.30096Windows and macOS2Windows
macOS
Acrobat Reader DC 2017Classic 20172017.011.30096Windows and macOS2Windows
macOS
Acrobat DCClassic 20152015.006.30434Windows and macOS2Windows
macOS
Acrobat Reader DCClassic 20152015.006.30434Windows and macOS2Windows
macOS

Users are recommended to update their software installations to the latest versions, to update manually Help for Adobe security updates > Check for Updates.

Also Read:

Cisco Released Security Updates and Fixed Critical Vulnerabilities that Affected Cisco Products

Microsoft Released Security Updates for July and Fixed 53 Security Vulnerabilities

Debian Released Security Updates for July and Fixed Multiple Package Vulnerabilities

Apple Released Security Updates for iOS, macOS, Safari, iTunes – iOS 11.4.1 Released

Google Released Security Updates for More than 40 Android Security vulnerabilities

WordPress Update 4.9.7 – Critical Security Update to Resolve Bugs and Security Issues

VMware Released Security Updates for Critical Remote Code Execution Vulnerability

Microsoft Released Critical Security Updates with Patch for 50 Critical Vulnerabilities

Gurubaran

Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Recent Posts

Windows Kerberos Vulnerability Enables Security Feature Bypass

Microsoft has disclosed a new security vulnerability in Windows operating systems, tracked as CVE-2025-29809. This flaw,…

9 minutes ago

Ransomware Groups Target Organizations to Exfiltrate Data and Blackmail via Leak Site Posts

Ransomware attacks have continued their relentless assault on organizations worldwide, with a focus on data…

17 minutes ago

Hellcat Ransomware Upgrades Arsenal to Target Government, Education, and Energy Sectors

The cybersecurity community has raised alarms over the rapid evolution of the Hellcat ransomware group,…

22 minutes ago

Ransomware Group Actively Exploits Windows CLFS Zero-Day Vulnerability

Microsoft has uncovered a sophisticated ransomware campaign exploiting a zero-day vulnerability in the Windows Common…

53 minutes ago

CISA Issues Alert on Active Exploits of Windows CLFS Vulnerability

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert regarding active exploitation…

2 hours ago

Apache mod_auth_openidc Flaw Lets Unauthenticated Users Access Protected Data

A critical flaw in Apache mod_auth_openidc (versions ≤2.4.16.10) allows unauthenticated attackers to bypass authentication and access protected…

3 hours ago