Adobe and Microsoft Ship Huge August Patch Loads

Adobe and Microsoft both landed oversized August security batches on August 11. Adobe issued five bulletins for 51 CVEs across ColdFusion, Campaign Classic, Commerce, Lightroom Classic, and Content Credentials SDK; Campaign Classic and ColdFusion were both marked deployment priority 1. Microsoft’s August release adds 398 CVEs across Windows, Office, Exchange, SharePoint, Teams, and other products, with one issue listed as under active attack. For Adobe, the ordering matters more than the count: Campaign Classic contains two CVSS 10 flaws and supersedes a patch Adobe issued on August 3, while ColdFusion also carries a CVSS 10 bug. Microsoft’s batch is much larger, but the vendor flags only one problem as actively attacked, which separates the urgent item from the rest of the volume. For teams with Adobe or Microsoft estates, this is a triage story about backlog density and vendor priority, not a new exploit pattern. The practical exposure sits with whichever products are already in your environment; the size of the release just determines how carefully the urgent fixes have to be picked out from the bulk.

Part of the PlainSec briefing for 2026-08-12

Every edition of this story: Adobe and Microsoft Ship Huge August Patch Loads

Sources