Adobe March 2026 Patch Tuesday

Malicious code smuggling possible in Reader, Illustrator and others.

In March, Adobe released security updates for eight programs on Patch Tuesday. These updates address vulnerabilities that Adobe classifies as critical. These vulnerabilities could allow attackers to inject malicious code or escalate their privileges.

Updates Close Security Vulnerabilities

Adobe's Patch Tuesday overview lists the eight security advisory for each product. In Adobe Commerce, Commerce B2B, and Magento Open Source, the developers addressed 19 security vulnerabilities. These include several cross-site scripting (XSS) vulnerabilities, one of which narrowly missed being classified as critical by CVSS and could allow for privilege escalation or bypassing security measures. Adobe classifies six of these vulnerabilities as critical threats.

The situation is similar for Illustrator. Several vulnerabilities allow the injection and execution of arbitrary code; Adobe classifies five of the seven vulnerabilities as critical. Three security vulnerabilities exist in Acrobat DC, Acrobat Reader DC, and Acrobat 2024, two of which allow code injection and have been classified as critical. Users of Substance 3D Stager should apply the updates to close the six critical vulnerabilities that could allow attackers to inject malicious code.

Software updates in the Adobe DNG Software Development Kit (SDK) also patch some critical vulnerabilities, while Adobe Premiere and Premiere Pro only had one critical vulnerability to close. Adobe is also addressing nine vulnerabilities in Substance 3D Painter that are still classified as important. In March, the developers also closed 33 cross-site scripting (XSS) vulnerabilities in Adobe Experience Manager (AEM), which, however, only achieved a CVSS score of 5.4. Adobe classifies these vulnerabilities as important, deviating from the medium risk rating according to CVSS.

IT managers and users of Adobe software should apply the updates promptly.

about author