Adobe Security Bulletin

Security updates available for Content Credentials SDK | APSB26-147

Bulletin ID

Date Published

Priority

APSB26-147

September 22, 2026

3

Summary

Adobe has released a security update for Content Credentials SDK. This update addresses critical and important vulnerabilities  that could result in security feature bypass and application denial-of-service.

Adobe is not aware of any exploits in the wild for any of the issues addressed in this update.  

Affected versions

Product Affected version Platform
Content Credentials Rust SDK c2pa-v0.89.2 and earlier All
C2PA Tool c2patool-v0.26.70 and earlier All

Solution

Adobe categorizes these updates with the following priority rating and recommends users update their installation to the newest version:

Product Updated version Platform Priority rating Availability
Content Credentials Rust SDK
c2pa-v0.90.17 All 3 Release Notes
C2PA Tool
c2patool-v0.27.17 All 3 Release Notes

Vulnerability Details

Vulnerability Category Vulnerability Impact Severity CVSS base score CVSS vector CVE Number

Improper Input Validation (CWE-20)

Security feature bypass

Critical

7.5

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CVE-2026-19480

Uncontrolled Resource Consumption (CWE-400)

Application denial-of-service

Critical

7.5

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVE-2026-75632

Improper Input Validation (CWE-20)

Security feature bypass

Important

6.5

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

CVE-2026-75638

Improper Input Validation (CWE-20)

Application denial-of-service

Important

5.5

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

CVE-2026-75633

Integer Overflow or Wraparound (CWE-190)

Application denial-of-service

Important

5.5

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVE-2026-89277

Improper Input Validation (CWE-20)

Security feature bypass

Important

4.3

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

CVE-2026-75634

Improper Input Validation (CWE-20)

Security feature bypass

Important

4.3

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

CVE-2026-76194
Note
Effective August 11, 2026, Adobe may assign a single CVE identifier to internally discovered vulnerabilities with the same severity rating and CWE category when a release includes systemic fixes.

Acknowledgments

Adobe would like to thank the following researchers for reporting this issue and for working with Adobe to help protect our customers.        

  • Geo-VIE (gvfx) — CVE-2026-19480
  • rootdaddy (r00tdaddy) — CVE-2026-75632
  • mars (marsduk) — CVE-2026-75638
  • bau1u — CVE-2026-75633, CVE-2026-89277
  • susdrip — CVE-2026-75634
  • 0x0.eth (0x0doteth) — CVE-2026-76194

For more information, visit https://helpx.adobe.com/security.html, or email PSIRT@adobe.com

Adobe, Inc.

Get help faster and easier

New user?