Note: The vulnerability initially analyzed as CVE-2023-26359 has been identified to be CVE-2023-26360. This change occurred after Adobe updated their advisory to re-classify CVE-2023-26360 from an Improper Access Control vulnerability to a Deserialization of Untrusted Data vulnerability. This change, in conjunction with privately reported information regarding CVE-2023-26359, let us reliably identify CVE-2023-26360. The AttackerKB Analysis for CVE-2023-26360 is now available here.
Threat Research
Rapid7 Analysis: CVE-2023-26359
|Last updated on Jun 16, 2026|1 min read



