Adobe InDesign, Adobe Framemaker , and Adobe Experience Manager received updates to fix critical vulnerabilities.

Adobe has released security updates to fix critical vulnerabilities that could allow attackers to execute malicious code on devices running vulnerable versions of Adobe InDesign, Adobe Framemaker, and Adobe Experience Manager .
In total, Adobe patched 18 vulnerabilities. All of them are rated from serious to critical. Some of these vulnerabilities could lead to JavaScript code execution in the browser and the disclosure of sensitive information.
Adobe advises customers to update vulnerable applications to the latest versions as soon as possible to stay safe.

Security Update APSB20-52 for Adobe InDesign
Adobe has released security for Adobe InDesign for macOS. The updates fix memory-related vulnerabilities that could lead to code execution.
macOS users should install the Adobe InDesign 15.1.2 update to fix the following five critical vulnerabilities.
| Vulnerability Category | Vulnerability Impact | Severity | CVE Number |
|---|---|---|---|
| Memory Corruption | Arbitrary Code Execution | Critical | CVE-2020-9727 CVE-2020-9728 CVE-2020-9729 CVE-2020-9730 CVE-2020-9731 |
Security Update APSB20-54 for Adobe Framemaker
Adobe has released security for Adobe Framemaker for Windowsto fix “stack-based buffer overflow issues,” which could also allow code execution.
Users should immediately install Adobe Framemaker version 2019.0.7 to fix these critical bugs.
| Vulnerability Category | Vulnerability Impact | Severity | CVE Numbers |
| Out-of-Bounds Read | Arbitrary code execution | Critical | CVE-2020-9726 |
| Stack-based Buffer Overflow | Arbitrary code execution | Critical | CVE-2020-9725 |

Security Update APSB20-56 for Adobe Experience Manager
Finally, Adobe released updates for Adobe Experience Manager and the AEM Forms add-on, which fix “cross-site scripting” vulnerabilities. The bugs could lead to JavaScript code execution, HTML injection in the browser, and information disclosure.
Users must install Adobe Experience Manager version 6.5.6.0 or 6.4.8.2 and AEM Forms add-on Service Pack 6 to fix these security vulnerabilities.
| Vulnerability Category | Vulnerability Impact | Severity | CVE Number | Affected Versions |
| Cross-site scripting (stored) | Arbitrary JavaScript execution in the browser | Critical | CVE-2020-9732 | AEM Forms SP5 and earlier |
| Execution with Unnecessary Privileges | Sensitive Information Disclosure | Important | CVE-2020-9733 | AEM 6.5.5.0 and earlierAEM 6.4.8.1 and earlier |
| Cross-site scripting (stored) | Arbitrary JavaScript execution in the browser | Critical | CVE-2020-9734 | AEM Forms SP5 and earlier |
| Cross-site scripting (stored) | Arbitrary JavaScript execution in the browser | Important | CVE-2020-9735 | AAEM 6.5.5.0 and earlierAEM 6.4.8.1 and earlierAEM 6.3.3.8 and earlierAEM 6.2 SP1-CFP20 and earlier |
| Cross-site scripting (stored) | Arbitrary JavaScript execution in the browser | Important | CVE-2020-9736 | AEM 6.5.5.0 and earlierAEM 6.4.8.1 and earlierAEM 6.3.3.8 and earlierAEM 6.2 SP1-CFP20 and earlier |
| Cross-site scripting (stored) | Arbitrary JavaScript execution in the browser | Important | CVE-2020-9737 | AEM 6.5.5.0 and earlierAEM 6.4.8.1 and earlierAEM 6.3.3.8 and earlierAEM 6.2 SP1-CFP20 and earlier |
| Cross-site scripting (stored) | Arbitrary JavaScript execution in the browser | Important | CVE-2020-9738 | AEM 6.5.5.0 and earlierAEM 6.4.8.1 and earlierAEM 6.3.3.8 and earlierAEM 6.2 SP1-CFP20 and earlier |
| Cross-site scripting (stored) | Arbitrary JavaScript execution in the browser | Critical | CVE-2020-9740 | AEM 6.5.5.0 and earlierAEM 6.4.8.1 and earlierAEM 6.3.3.8 and earlierAEM 6.2 SP1-CFP20 and earlier |
| Cross-site scripting (stored) | Arbitrary JavaScript execution in the browser | Critical | CVE-2020-9741 | AEM Forms SP5 and earlier |
| Cross-site scripting (reflected) | Arbitrary JavaScript execution in the browser | Critical | CVE-2020-9742 | AEM 6.5.5.0 and earlierAEM 6.4.8.1 and earlierAEM 6.3.3.8 and earlier |
| HTML injection | Arbitrary HTML injection in the browser | Important | CVE-2020-9743 | AEM 6.5.5.0 and earlierAEM 6.4.8.1 and earlierAEM 6.3.3.8 and earlierAEM 6.2 SP1-CFP20 and earlier |
