Adobe Is Doubling Its Patch Releases — Here's Why That Matters

Starting in July, Adobe will push security fixes twice a month instead of once. Faster vulnerability discovery, AI-assisted research, and a threat pace that monthly updates can no longer keep up with are all driving the change.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
Illustration: a calendar grid pinned to a corkboard, with two Tuesdays in a single month circled in red marker
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Adobe will begin issuing security patches on the fourth Tuesday of each month from 14 July 2025, doubling its previous once-monthly release schedule.
  • Adobe cited the pace of AI-assisted vulnerability discovery as the direct reason for the change.
  • On 30 June 2026, Adobe issued two out-of-sequence security advisories, APSB26-28 and APSB26-29, covering multiple critical flaws before the new schedule even launched.
  • Oracle made the same move earlier in 2025, shifting from quarterly patches to monthly ones.
  • Every advisory that includes a formally published CVE, a unique tracking number assigned to a known software flaw, requiring customer action will fall under the new twice-monthly schedule.

Adobe makes software that hundreds of millions of people use every day: Acrobat, Photoshop, Creative Cloud. When a security flaw turns up in one of those products, Adobe has to fix it before criminals figure out how to exploit it.

Until now, Adobe released fixes once a month, on the second Tuesday, a schedule nicknamed "Patch Tuesday" that Microsoft and SAP also follow. From 14 July 2025, Adobe adds a second window: the fourth Tuesday of each month.

The company was blunt about why. "Twice-monthly bulletins will enable us to keep pace with the era of frontier AI," Adobe wrote in a blog post. "More vulnerabilities found means more fixes to deploy and a once-a-month publication window is no longer fast enough to stay ahead of our adversaries." Frontier AI means the newest, most capable AI tools, which researchers and criminals alike now use to find software weaknesses faster than before.

Why should ordinary Adobe users care?

If you use any Adobe product and receive prompts to update, apply them promptly. Each patch closes a door that criminals are actively trying to open.

The urgency isn't theoretical. On 30 June 2026, a fifth Tuesday outside the normal schedule, Adobe had to issue two emergency advisories covering several critical vulnerabilities, meaning flaws serious enough to let an attacker take control of an affected machine. We covered the out-of-band releases in detail on [1 July](/ story/adobe-ships-emergency-fixes-for-seven-cvss-100-bugs-in-coldfusion-campaign-class) and again on [3 July](/ story/adobe-rushes-out-fixes-for-a-dozen-flaws-in-coldfusion-campaign-classic-six-), when six of the twelve patched flaws carried the highest possible severity rating. That pair of fire drills is exactly what Adobe is trying to bring under a predictable schedule.

Oracle, which makes widely used business database software, made a similar call earlier in 2025, moving from patches every three months to patches every month. Microsoft released an unscheduled fix in April 2025 to react to a specific active attack.

The pattern holds: old release rhythms were built for a slower threat environment. Adobe's announcement, first reported by CSO Online, is one of the clearer public admissions yet that AI tools are genuinely accelerating vulnerability discovery, and that vendors are scrambling to match the pace. Our June Patch Tuesday story showed Microsoft making the same argument when CVE volume hit a record that month.

For business owners running Adobe software, the practical call is simple: turn on automatic updates, and make sure whoever manages your systems knows the update window has doubled. The vendors aren't crying wolf.

© 2026 Threat Vectr