Note: The vulnerability initially analyzed as CVE-2023-26359 has been identified to be CVE-2023-26360. This change occurred after Adobe updated their advisory to re-classify CVE-2023-26360 from an Improper Access Control vulnerability to a Deserialization of Untrusted Data vulnerability. This change, in conjunction with privately reported information regarding CVE-2023-26359, let us reliably identify CVE-2023-26360. The AttackerKB Analysis for CVE-2023-26360 is now available here.
Explore more from Rapid7
Vulnerability & Exploit Database
Rapid7s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.
Search the database
Rapid7 Labs
The threat research behind the alerts: adversary tracking, curated intelligence, and flagship threat reports.
Explore the research
Rapid7 MDR
Gain 24x7 XDR monitoring, remediation, and DFIR from experts that extend your team to help secure your extended ecosystem.
Explore MDR
Exposure management
Get continuous assessment of your attack surface with the critical context to validate and extinguish vulnerabilities and policy gaps.
See how it works
.png?width=3840&quality=75)


