Adobe Security Bulletin

Security updates available for Content Credentials SDK | APSB26-110

Bulletin ID

Date Published

Priority

APSB26-110

August 25, 2026

3

Summary

Adobe has released a security update for Content Credentials SDK. This update addresses critical and important vulnerabilities  that could result in application denial-of-service and arbitrary file system read.

Adobe is not aware of any exploits in the wild for any of the issues addressed in this update.  

Affected versions

Product Affected version Platform
Content Credentials Rust SDK c2pa-v0.89.0 and earlier All
C2PA Tool c2patool-v0.26.70 and earlier All

Solution

Adobe categorizes these updates with the following priority rating and recommends users update their installation to the newest version:

Product Updated version Platform Priority rating Availability
Content Credentials Rust SDK
c2pa-v0.90.11 All 3 Release Notes
C2PA Tool
c2patool-v0.27.11 All 3 Release Notes

Vulnerability Details

Vulnerability Category Vulnerability Impact Severity CVSS base score CVSS vector CVE Number

Uncontrolled Resource Consumption (CWE-400)

Application denial-of-service

Critical

7.5

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVE-2026-71360

Improper Input Validation (CWE-20)

Application denial-of-service

Critical

7.5

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVE-2026-71443

Integer Underflow (Wrap or Wraparound) (CWE-191)

Application denial-of-service

Critical

7.5

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVE-2026-71442

Integer Underflow (Wrap or Wraparound) (CWE-191)

Application denial-of-service

Important

6.2

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVE-2026-71444

Integer Underflow (Wrap or Wraparound) (CWE-191)

Application denial-of-service

Important

6.2

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVE-2026-76189

Improper Input Validation (CWE-20)

Arbitrary file system read

Important

5.5

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

CVE-2026-76198

Note
Effective August 11, 2026, Adobe may assign a single CVE identifier to internally discovered vulnerabilities with the same severity rating and CWE category when a release includes systemic fixes.

Acknowledgments

Adobe would like to thank the following researchers for reporting this issue and for working with Adobe to help protect our customers.        

  • bau1u — CVE-2026-71360, CVE-2026-71443, CVE-2026-71442, CVE-2026-71444, CVE-2026-76189
  • Jony (jony_juice) — CVE-2026-76198

For more information, visit https://helpx.adobe.com/security.html, or email PSIRT@adobe.com

Adobe, Inc.

Get help faster and easier

New user?