CVE-2024-20738: Adobe Framemaker Publishing Server

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

Adobe FrameMaker Publishing Server versions 2022.1 and earlier are affected by an Improper Authentication vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass authentication mechanisms and gain unauthorized access. Exploitation of this issue does not require user interaction.

Affected products

  • Adobe Framemaker Publishing Server: before 2022 (fixed in 2022); version 2022 only

Published 2024-02-15. Last modified 2026-06-17.