Adobe joins Patch Tuesday
Adobe will start a quarterly patching cycle after PDF flaw trouble earlier this year.


Adobe is to start a regular patching cycle alongside Microsoft's, after a PDF flaw earlier this year highlighted problems in the firm's security response process.
A vulnerability in PDFs was discovered in February, and only partially patched in March. The full fix wasn't offered until this month, despite the flaw being actively exploited by attackers.
Brad Arkin, director of product security and privacy, wrote in Adobe's security blog that the incident led the firm to examine its security and patching process.
"Everything from our security team's communications during an incident to our security update process to the code itself has been carefully reviewed," he wrote.
One major change is Adobe will now offer a quarterly patching cycle. Previously, it fixed flaws whenever they showed up, but from this summer will start to offer regular updates timed to coincide with Microsoft's monthly patching exercise, dubbed Patch Tuesday.
"Based on feedback from our customers, who have processes and resources geared toward Microsoft's Patch Tuesday security updates, we will make Adobe's quarterly patches available on the same days," Arkin wrote, noting previous patches released on the same day as Microsoft's were just a coincidence.
Adobe said it would also look to "harden" existing base code, to make sure legacy sections are as secure as more recent code, which is subject to more stringent testing than code written years ago.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
The firm is also looking to improve how it manages major security problems. "We've targeted several specific areas where we are improving our incident response process," Arkin wrote.
"We expect folks outside Adobe will see more timely communications regarding incidents, quicker turn-around times on patch releases, and simultaneous patches for more affected versions as we move forward."
Freelance journalist Nicole Kobie first started writing for ITPro in 2007, with bylines in New Scientist, Wired, PC Pro and many more.
Nicole the author of a book about the history of technology, The Long History of the Future.
-
Cleo attack victim list grows as Hertz confirms customer data stolen
News Hertz has confirmed it suffered a data breach as a result of the Cleo zero-day vulnerability in late 2024, with the car rental giant warning that customer data was stolen.
By Ross Kelly
-
Lateral moves in tech: Why leaders should support employee mobility
In-depth Encouraging staff to switch roles can have long-term benefits for skills in the tech sector
By Keri Allan
-
Ask more from your CMS
Whitepaper How to get the most value in the shortest timespan
By ITPro
-
Adobe battles fake photos with editing tags
News Photoshop will include new tagging tools later this year to help fight against misinformation and deep fakes
By Nicole Kobie
-
Avast Business Patch Management review: Don’t give up the day job just yet
Reviews Good Windows patch management services but a work in progress
By Dave Mitchell
-
Adobe Photoshop Elements 2019 review: Trapped in the photo-editing middle ground
Reviews A once peerless beginner’s photo-editing package that’s past its prime
By Barry Collins
-
How Adobe saved BT £630,000
Sponsored Adobe’s digital signature platform is saving time and money - and forging stronger connections between businesses and customers
By ITPro
-
Don't settle when it comes to creativity
Sponsored Getting the best out of your creative design team means equipping them with the best software
By ITPro
-
The benefits of a subscription service
Sponsored Why software vendors are increasingly moving to a subscription model
By ITPro
-
Brexit: Adobe Creative Cloud hikes prices up 11%
News Currency changes continue to bite British software buyers
By Nicole Kobie