Skip to content
feed: live
>_0dayNews
← All vendors
Vendor

Adobe

Vulnerabilities in Adobe ColdFusion, Commerce (Magento), Reader, and Acrobat — a product line whose enterprise footprint keeps it in the KEV catalog and in attacker toolkits well past its perceived relevance.

89 CVEs6 articlesRSS
CVEs
CVE-2026-71362
[ CRITICAL ]CVSS 9.1EPSS 1.3%exploited-in-wild

Incorrect Authorization in Adobe Commerce and Magento Open Source

Adobe Commerce and Magento Open Source contain an incorrect authorization flaw enabling privilege escalation to sensitive resources. CVSS 9.1 critical. Actively exploited in wild.

Adobe / Commerce, Magento Open Source
CVE-2026-48449
[ CRITICAL ]CVSS 10.0EPSS 0.5%patched

Adobe Campaign Classic Incorrect Authorization Enables RCE

Incorrect authorization flaw in Adobe Campaign Classic scores CVSS 10.0, enabling unauthenticated remote code execution without user interaction. Adobe has patched.

Adobe / Campaign Classic
CVE-2026-48294
[ HIGH ]CVSS 7.4EPSS 1.9%patched

Adobe Acrobat Chrome extension cross-context WhatsApp data access (HermeticReader)

CVE-2026-48294: cross-context flaw in the Adobe Acrobat Chrome extension let any site silently read WhatsApp Web data. CVSS 7.4; patched by Adobe.

Adobe / Adobe Acrobat Chrome Extension
CVE-2026-48284
[ CRITICAL ]CVSS 9.6EPSS 4.9%patched

Adobe ColdFusion input-validation failure — CVSS 9.6

Input-validation failure in Adobe ColdFusion enables unauthenticated remote code execution. Patched in ColdFusion 2025 Update 11 and ColdFusion 2023 Update 22.

Adobe / ColdFusion 2023, ColdFusion 2025
CVE-2026-48319
[ CRITICAL ]CVSS 9.1EPSS 32.3%patched

Adobe ColdFusion path traversal — CVSS 9.1

Path traversal in Adobe ColdFusion allows an unauthenticated remote attacker to read arbitrary files on the server. Patched in ColdFusion 2025 Update 11 and 2023 Update 22.

Adobe / ColdFusion 2023, ColdFusion 2025
CVE-2026-48321
[ CRITICAL ]CVSS 9.3EPSS 0.5%patched

Adobe ColdFusion authorization bypass — CVSS 9.3

Authorization bypass in Adobe ColdFusion allows an unauthenticated attacker to bypass access controls. Patched in ColdFusion 2025 Update 11 and 2023 Update 22.

Adobe / ColdFusion 2023, ColdFusion 2025
CVE-2026-48322
[ CRITICAL ]CVSS 9.6EPSS 0.9%patched

Adobe ColdFusion code injection — CVSS 9.6

Code injection in Adobe ColdFusion allows unauthenticated remote code execution. Patched in ColdFusion 2025 Update 11 and ColdFusion 2023 Update 22.

Adobe / ColdFusion 2023, ColdFusion 2025
CVE-2026-48325
[ CRITICAL ]CVSS 9.3EPSS 0.5%patched

Adobe ColdFusion missing authentication — CVSS 9.3

Missing authentication check in Adobe ColdFusion allows unauthenticated attackers to access protected functionality. Patched in ColdFusion 2025 Update 11 and 2023 Update 22.

Adobe / ColdFusion 2023, ColdFusion 2025
CVE-2026-48318
[ CRITICAL ]CVSS 9.9EPSS 23.5%patched

Adobe ColdFusion path traversal

Path-traversal vulnerability in Adobe ColdFusion that could result in arbitrary code execution. The highest-scored CVE in Adobe's July 2026 ColdFusion cluster. Fixed in ColdFusion 2025 Update 11 and ColdFusion 2023 Update 22.

Adobe / ColdFusion 2025 (pre-Update 11), ColdFusion 2023 (pre-Update 22)
CVE-2026-48282
[ CRITICAL ]CVSS 10.0EPSS 99.2%kev

Adobe ColdFusion path-traversal to arbitrary code execution

Unauthenticated path-traversal (CWE-22) in Adobe ColdFusion 2023 (through update 20) and 2025 (through update 9) permitting arbitrary code execution without user interaction. CVSS 10.0. Patched by Adobe on 2026-07-01 in APSB26-68 (ColdFusion 2023 update 21, 2025 update 10). Active in-the-wild exploitation confirmed by the Canadian Centre for Cyber Security on 2026-07-02; Shadowserver counts ~800 exposed instances.

Adobe / ColdFusion (2023 through update 20; 2025 through update 9)
CVE-2009-3459
[ HIGH ]CVSS 8.8EPSS 86.6%kev

Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability

Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption.

Adobe / Acrobat and Reader
CVE-2020-9715
[ HIGH ]CVSS 7.8EPSS 48.4%kev

Adobe Acrobat Use-After-Free Vulnerability

Adobe Acrobat contains a use-after-free vulnerability that allows for code execution

Adobe / Acrobat
CVE-2026-34621
[ HIGH ]CVSS 8.6EPSS 7.1%kev

Adobe Acrobat and Reader Prototype Pollution Vulnerability

Adobe Acrobat and Reader contain a prototype pollution vulnerability that allows for arbitrary code execution.

Adobe / Acrobat and Reader
CVE-2025-54236
[ CRITICAL ]CVSS 9.1EPSS 94.5%kev

Adobe Commerce and Magento Improper Input Validation Vulnerability

Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API.

Adobe / Commerce and Magento
CVE-2025-54253
[ CRITICAL ]CVSS 10.0EPSS 87.5%kev

Adobe Experience Manager Forms Code Execution Vulnerability

Adobe Experience Manager Forms in JEE contains an unspecified vulnerability that allows for arbitrary code execution.

Adobe / Experience Manager (AEM) Forms
CVE-2017-3066
[ CRITICAL ]CVSS 9.8EPSS 90.6%kev

Adobe ColdFusion Deserialization Vulnerability

Adobe ColdFusion contains a deserialization vulnerability in the Apache BlazeDS library that allows for arbitrary code execution.

Adobe / ColdFusion
CVE-2024-20767
[ HIGH ]CVSS 7.4EPSS 98.5%kev

Adobe ColdFusion Improper Access Control Vulnerability

Adobe ColdFusion contains an improper access control vulnerability that could allow an attacker to access or modify restricted files via an internet-exposed admin panel.

Adobe / ColdFusion
CVE-2013-0643
[ HIGH ]CVSS 8.8EPSS 10.5%kev

Adobe Flash Player Incorrect Default Permissions Vulnerability

Adobe Flash Player contains an incorrect default permissions vulnerability in the Firefox sandbox that allows a remote attacker to execute arbitrary code via crafted SWF content.

Adobe / Flash Player
CVE-2013-0648
[ HIGH ]CVSS 8.8EPSS 11.1%kev

Adobe Flash Player Code Execution Vulnerability

Adobe Flash Player contains an unspecified vulnerability in the ExternalInterface ActionScript functionality that allows a remote attacker to execute arbitrary code via crafted SWF content.

Adobe / Flash Player
CVE-2014-0497
[ CRITICAL ]CVSS 9.8EPSS 99.9%kev

Adobe Flash Player Integer Underflow Vulnerablity

Adobe Flash Player contains an integer underflow vulnerability that allows a remote attacker to execute arbitrary code.

Adobe / Flash Player
CVE-2014-0502
[ HIGH ]CVSS 8.8EPSS 24.2%kev

Adobe Flash Player Double Free Vulnerablity

Adobe Flash Player contains a double free vulnerability that allows a remote attacker to execute arbitrary code.

Adobe / Flash Player
CVE-2024-34102
[ CRITICAL ]CVSS 9.8EPSS 100.0%kev

Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability

Adobe Commerce and Magento Open Source contain an improper restriction of XML external entity reference (XXE) vulnerability that allows for remote code execution.

Adobe / Commerce and Magento Open Source
CVE-2023-29300
[ CRITICAL ]CVSS 9.8EPSS 100.0%kev

Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution.

Adobe / ColdFusion
CVE-2023-38203
[ CRITICAL ]CVSS 9.8EPSS 96.7%kev

Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution.

Adobe / ColdFusion
CVE-2023-21608
[ HIGH ]CVSS 7.8EPSS 61.5%kev

Adobe Acrobat and Reader Use-After-Free Vulnerability

Adobe Acrobat and Reader contains a use-after-free vulnerability that allows for code execution in the context of the current user.

Adobe / Acrobat and Reader
CVE-2023-26369
[ HIGH ]CVSS 7.8EPSS 7.0%kev

Adobe Acrobat and Reader Out-of-Bounds Write Vulnerability

Adobe Acrobat and Reader contains an out-of-bounds write vulnerability that allows for code execution.

Adobe / Acrobat and Reader
CVE-2023-26359
[ CRITICAL ]CVSS 9.8EPSS 17.0%kev

Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could result in code execution in the context of the current user.

Adobe / ColdFusion
CVE-2023-29298
[ HIGH ]CVSS 7.5EPSS 99.8%kev

Adobe ColdFusion Improper Access Control Vulnerability

Adobe ColdFusion contains an improper access control vulnerability that allows for a security feature bypass.

Adobe / ColdFusion
CVE-2023-38205
[ HIGH ]CVSS 7.5EPSS 99.7%kev

Adobe ColdFusion Improper Access Control Vulnerability

Adobe ColdFusion contains an improper access control vulnerability that allows for a security feature bypass.

Adobe / ColdFusion
CVE-2023-26360
[ HIGH ]CVSS 8.6EPSS 97.3%kev

Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for remote code execution.

Adobe / ColdFusion
CVE-2007-5659
[ HIGH ]CVSS 7.8EPSS 94.2%kev

Adobe Acrobat and Reader Buffer Overflow Vulnerability

Adobe Acrobat and Reader contain a buffer overflow vulnerability that allows remote attackers to execute code via a PDF file with long arguments to unspecified JavaScript methods.

Adobe / Acrobat and Reader
CVE-2008-0655
[ HIGH ]CVSS 8.8EPSS 36.8%kev

Adobe Acrobat and Reader Unspecified Vulnerability

Adobe Acrobat and Reader contains an unespecified vulnerability described as a design flaw which could allow a specially crafted file to be printed silently an arbitrary number of times.

Adobe / Acrobat and Reader
CVE-2009-1862
[ HIGH ]CVSS 7.8EPSS 25.0%kev

Adobe Acrobat and Reader, Flash Player Unspecified Vulnerability

Adobe Acrobat and Reader and Adobe Flash Player allows remote attackers to execute code or cause denial-of-service (DoS).

Adobe / Acrobat and Reader, Flash Player
CVE-2009-3953
[ HIGH ]CVSS 8.8EPSS 83.9%kev

Adobe Acrobat and Reader Universal 3D Remote Code Execution Vulnerability

Adobe Acrobat and Reader contains an array boundary issue in Universal 3D (U3D) support that could lead to remote code execution.

Adobe / Acrobat and Reader
CVE-2009-4324
[ HIGH ]CVSS 7.8EPSS 81.9%kev

Adobe Acrobat and Reader Use-After-Free Vulnerability

Use-after-free vulnerability in Adobe Acrobat and Reader allows remote attackers to execute code via a crafted PDF file.

Adobe / Acrobat and Reader
CVE-2010-1297
[ HIGH ]CVSS 7.8EPSS 82.4%kev

Adobe Flash Player Memory Corruption Vulnerability

Adobe Flash Player contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).

Adobe / Flash Player
CVE-2010-2883
[ HIGH ]CVSS 7.3EPSS 82.5%kev

Adobe Acrobat and Reader Stack-Based Buffer Overflow Vulnerability

Adobe Acrobat and Reader contain a stack-based buffer overflow vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).

Adobe / Acrobat and Reader
CVE-2011-0609
[ HIGH ]CVSS 7.8EPSS 66.8%kev

Adobe Flash Player Unspecified Vulnerability

Adobe Flash Player contains an unspecified vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).

Adobe / Flash Player
CVE-2011-2462
[ CRITICAL ]CVSS 9.8EPSS 86.6%kev

Adobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability

The Universal 3D (U3D) component in Adobe Reader and Acrobat contains a memory corruption vulnerability which could allow remote attackers to execute code or cause denial-of-service (DoS).

Adobe / Reader and Acrobat
CVE-2012-0754
[ HIGH ]CVSS 8.1EPSS 92.0%kev

Adobe Flash Player Memory Corruption Vulnerability

Adobe Flash Player contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).

Adobe / Flash Player
CVE-2012-0767
[ MEDIUM ]CVSS 6.1EPSS 6.7%kev

Adobe Flash Player Cross-Site Scripting (XSS) Vulnerability

Adobe Flash Player contains a XSS vulnerability that allows remote attackers to inject web script or HTML.

Adobe / Flash Player
CVE-2012-5054
[ HIGH ]CVSS 8.8EPSS 21.2%kev

Adobe Flash Player Integer Overflow Vulnerability

Adobe Flash Player contains an integer overflow vulnerability that allows remote attackers to execute code via malformed arguments.

Adobe / Flash Player
CVE-2018-4990
[ HIGH ]CVSS 8.8EPSS 36.6%kev

Adobe Acrobat and Reader Double Free Vulnerability

Adobe Acrobat and Reader have a double free vulnerability that could lead to remote code execution.

Adobe / Acrobat and Reader
CVE-2014-0546
[ CRITICAL ]CVSS 9.8EPSS 22.3%kev

Adobe Reader and Acrobat Sandbox Bypass Vulnerability

Adobe Reader and Acrobat on Windows allow attackers to bypass a sandbox protection mechanism, and consequently execute native code in a privileged context.

Adobe / Reader and Acrobat
CVE-2014-8439
[ HIGH ]CVSS 8.8EPSS 20.0%kev

Adobe Flash Player Dereferenced Pointer Vulnerability

Adobe Flash Player has a vulnerability in the way it handles a dereferenced memory pointer which could lead to code execution.

Adobe / Flash Player
CVE-2015-0310
[ HIGH ]CVSS 7.8EPSS 15.2%kev

Adobe Flash Player ASLR Bypass Vulnerability

Adobe Flash Player does not properly restrict discovery of memory addresses, which allows attackers to bypass the address space layout randomization (ASLR) protection mechanism.

Adobe / Flash Player
CVE-2015-8651
[ HIGH ]CVSS 8.8EPSS 67.9%kev

Adobe Flash Player Integer Overflow Vulnerability

Integer overflow in Adobe Flash Player allows attackers to execute code.

Adobe / Flash Player
CVE-2016-0984
[ HIGH ]CVSS 8.8EPSS 55.4%kev

Adobe Flash Player and AIR Use-After-Free Vulnerability

Use-after-free vulnerability in Adobe Flash Player and Adobe AIR allows attackers to execute code.

Adobe / Flash Player and AIR
CVE-2016-1010
[ HIGH ]CVSS 8.8EPSS 19.8%kev

Adobe Flash Player and AIR Integer Overflow Vulnerability

Integer overflow vulnerability in Adobe Flash Player and AIR allows attackers to execute code.

Adobe / Flash Player and AIR
CVE-2018-5002
[ HIGH ]CVSS 7.8EPSS 25.4%kev

Adobe Flash Player Stack-based Buffer Overflow Vulnerability

Adobe Flash Player have a stack-based buffer overflow vulnerability that could lead to remote code execution.

Adobe / Flash Player
CVE-2014-9163
[ HIGH ]CVSS 7.8EPSS 20.4%kev

Adobe Flash Player Stack-Based Buffer Overflow Vulnerability

Stack-based buffer overflow in Adobe Flash Player allows attackers to execute code remotely.

Adobe / Flash Player
CVE-2015-0311
[ CRITICAL ]CVSS 9.8EPSS 85.8%kev

Adobe Flash Player Remote Code Execution Vulnerability

Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute code.

Adobe / Flash Player
CVE-2015-0313
[ CRITICAL ]CVSS 9.8EPSS 95.7%kev

Adobe Flash Player Use-After-Free Vulnerability

Use-after-free vulnerability in Adobe Flash Player allows remote attackers to execute code.

Adobe / Flash Player
CVE-2015-3113
[ CRITICAL ]CVSS 9.8EPSS 99.9%kev

Adobe Flash Player Heap-Based Buffer Overflow Vulnerability

Heap-based buffer overflow vulnerability in Adobe Flash Player allows remote attackers to execute code.

Adobe / Flash Player
CVE-2015-5122
[ CRITICAL ]CVSS 9.8EPSS 93.7%kev

Adobe Flash Player Use-After-Free Vulnerability

Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS).

Adobe / Flash Player
CVE-2015-5123
[ CRITICAL ]CVSS 9.8EPSS 18.5%kev

Adobe Flash Player Use-After-Free Vulnerability

Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS).

Adobe / Flash Player
CVE-2012-2034
[ HIGH ]CVSS 7.5EPSS 7.8%kev

Adobe Flash Player Memory Corruption Vulnerability

Adobe Flash Player contains a memory corruption vulnerability that allows for remote code execution or denial-of-service (DoS).

Adobe / Flash Player
CVE-2013-2729
[ CRITICAL ]CVSS 9.8EPSS 66.6%kev

Adobe Reader and Acrobat Arbitrary Integer Overflow Vulnerability

Integer overflow vulnerability in Adobe Reader and Acrobat allows attackers to execute remote code.

Adobe / Reader and Acrobat
CVE-2009-0927
[ HIGH ]CVSS 8.8EPSS 96.6%kev

Adobe Reader and Adobe Acrobat Stack-Based Buffer Overflow Vulnerability

Stack-based buffer overflow in Adobe Reader and Adobe Acrobat allows remote attackers to execute arbitrary code.

Adobe / Reader and Acrobat
CVE-2010-2861
[ CRITICAL ]CVSS 9.8EPSS 99.7%kev

Adobe ColdFusion Directory Traversal Vulnerability

A directory traversal vulnerability exists in the administrator console in Adobe ColdFusion which allows remote attackers to read arbitrary files.

Adobe / ColdFusion
CVE-2016-4171
[ CRITICAL ]CVSS 9.8EPSS 20.2%kev

Adobe Flash Player Remote Code Execution Vulnerability

Unspecified vulnerability in Adobe Flash Player allows for remote code execution.

Adobe / Flash Player
CVE-2016-7892
[ HIGH ]CVSS 8.8EPSS 18.8%kev

Adobe Flash Player Use-After-Free Vulnerability

Adobe Flash Player has an exploitable use-after-free vulnerability in the TextField class.

Adobe / Flash Player
CVE-2009-3960
[ MEDIUM ]CVSS 6.5EPSS 90.0%kev

Adobe BlazeDS Information Disclosure Vulnerability

Adobe BlazeDS, which is utilized in LifeCycle and Coldfusion, contains a vulnerability that allows for information disclosure.

Adobe / BlazeDS
CVE-2013-0625
[ CRITICAL ]CVSS 9.8EPSS 93.8%kev

Adobe ColdFusion Authentication Bypass Vulnerability

Adobe Coldfusion contains an authentication bypass vulnerability, which could result in an unauthorized user gaining administrative access.

Adobe / ColdFusion
CVE-2013-0629
[ HIGH ]CVSS 7.5EPSS 65.9%kev

Adobe ColdFusion Directory Traversal Vulnerability

Adobe Coldfusion contains a directory traversal vulnerability, which could permit an unauthorized user access to restricted directories.

Adobe / ColdFusion
CVE-2013-0631
[ HIGH ]CVSS 7.5EPSS 65.9%kev

Adobe ColdFusion Information Disclosure Vulnerability

Adobe Coldfusion contains an unspecified vulnerability, which could result in information disclosure from a compromised server.

Adobe / ColdFusion
CVE-2008-2992
[ HIGH ]CVSS 7.8EPSS 98.5%kev

Adobe Reader and Acrobat Input Validation Vulnerability

Adobe Acrobat and Reader contain an input validation issue in a JavaScript method that could potentially lead to remote code execution.

Adobe / Acrobat and Reader
CVE-2010-0188
[ HIGH ]CVSS 7.8EPSS 88.2%kev

Adobe Reader and Acrobat Arbitrary Code Execution Vulnerability

Unspecified vulnerability in Adobe Reader and Acrobat allows attackers to cause a denial of service or possibly execute arbitrary code.

Adobe / Reader and Acrobat
CVE-2011-0611
[ HIGH ]CVSS 8.8EPSS 94.2%kev

Adobe Flash Player Remote Code Execution Vulnerability

Adobe Flash Player contains a vulnerability that allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content.

Adobe / Flash Player
CVE-2012-1535
[ HIGH ]CVSS 7.8EPSS 70.4%kev

Adobe Flash Player Arbitrary Code Execution Vulnerability

Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute arbitrary code or cause a denial of service via crafted SWF content.

Adobe / Flash Player
CVE-2013-0632
[ CRITICAL ]CVSS 9.8EPSS 93.7%kev

Adobe ColdFusion Authentication Bypass Vulnerability

An authentication bypass vulnerability exists in Adobe ColdFusion which could result in an unauthorized user gaining administrative access.

Adobe / ColdFusion
CVE-2013-0640
[ HIGH ]CVSS 7.8EPSS 87.0%kev

Adobe Reader and Acrobat Memory Corruption Vulnerability

An memory corruption vulnerability exists in the acroform.dll in Adobe Reader that allows an attacker to perform remote code execution.

Adobe / Reader and Acrobat
CVE-2013-0641
[ HIGH ]CVSS 7.8EPSS 32.4%kev

Adobe Reader Buffer Overflow Vulnerability

A buffer overflow vulnerability exists in Adobe Reader which allows an attacker to perform remote code execution.

Adobe / Reader
CVE-2013-3346
[ CRITICAL ]CVSS 9.8EPSS 78.6%kev

Adobe Reader and Acrobat Memory Corruption Vulnerability

Adobe Reader and Acrobat contain a memory corruption vulnerability which can allow attackers to execute arbitrary code or cause a denial of service.

Adobe / Reader and Acrobat
CVE-2014-0496
[ HIGH ]CVSS 8.8EPSS 40.2%kev

Adobe Reader and Acrobat Use-After-Free Vulnerability

Adobe Reader and Acrobat contain a use-after-free vulnerability which can allow for code execution.

Adobe / Reader and Acrobat
CVE-2015-3043
[ CRITICAL ]CVSS 9.8EPSS 74.4%kev

Adobe Flash Player Memory Corruption Vulnerability

A memory corruption vulnerability exists in Adobe Flash Player that allows an attacker to perform remote code execution.

Adobe / Flash Player
CVE-2015-5119
[ CRITICAL ]CVSS 9.8EPSS 99.3%kev

Adobe Flash Player Use-After-Free Vulnerability

A use-after-free vulnerability exists within the ActionScript 3 ByteArray class in Adobe Flash Player that allows an attacker to perform remote code execution.

Adobe / Flash Player
CVE-2015-7645
[ HIGH ]CVSS 7.8EPSS 68.4%kev

Adobe Flash Player Arbitrary Code Execution Vulnerability

Adobe Flash Player allows remote attackers to execute arbitrary code via a crafted SWF file.

Adobe / Flash Player
CVE-2016-1019
[ CRITICAL ]CVSS 9.8EPSS 22.5%kev

Adobe Flash Player Arbitrary Code Execution Vulnerability

Adobe Flash Player allows remote attackers to cause a denial of service or possibly execute arbitrary code.

Adobe / Flash Player
CVE-2016-4117
[ CRITICAL ]CVSS 9.8EPSS 94.4%kev

Adobe Flash Player Arbitrary Code Execution Vulnerability

An access of resource using incompatible type vulnerability exists within Adobe Flash Player that allows an attacker to perform remote code execution.

Adobe / Flash Player
CVE-2016-7855
[ HIGH ]CVSS 8.8EPSS 25.2%kev

Adobe Flash Player Use-After-Free Vulnerability

Use-after-free vulnerability in Adobe Flash Player Windows and OS and Linux allows remote attackers to execute arbitrary code.

Adobe / Flash Player
CVE-2017-11292
[ HIGH ]CVSS 8.8EPSS 11.9%kev

Adobe Flash Player Type Confusion Vulnerability

Adobe Flash Player contains a type confusion vulnerability which can allow for remote code execution.

Adobe / Flash Player
CVE-2018-15982
[ HIGH ]CVSS 7.8EPSS 82.5%kev

Adobe Flash Player Use-After-Free Vulnerability

Adobe Flash Player com.adobe.tvsdk.mediacore.metadata Use After Free Vulnerability

Adobe / Flash Player
CVE-2022-24086
[ CRITICAL ]CVSS 9.8EPSS 99.1%kev

Adobe Commerce and Magento Open Source Improper Input Validation Vulnerability

Adobe Commerce and Magento Open Source contain an improper input validation vulnerability which can allow for arbitrary code execution.

Adobe / Commerce and Magento Open Source
CVE-2018-15961
[ CRITICAL ]CVSS 9.8EPSS 100.0%kev

Adobe ColdFusion Unrestricted File Upload Vulnerability

Adobe ColdFusion contains an unrestricted file upload vulnerability that could allow for code execution.

Adobe / ColdFusion
CVE-2018-4878
[ HIGH ]CVSS 7.8EPSS 89.5%kev

Adobe Flash Player Use-After-Free Vulnerability

Adobe Flash Player contains a use-after-free vulnerability that could allow for code execution.

Adobe / Flash Player
CVE-2018-4939
[ CRITICAL ]CVSS 9.8EPSS 62.9%kev

Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could allow for code execution.

Adobe / ColdFusion
CVE-2021-21017
[ HIGH ]CVSS 8.8EPSS 86.3%kev

Adobe Acrobat and Reader Heap-based Buffer Overflow Vulnerability

Acrobat Acrobat and Reader contain a heap-based buffer overflow vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user.

Adobe / Acrobat and Reader
CVE-2021-28550
[ HIGH ]CVSS 8.8EPSS 52.0%kev

Adobe Acrobat and Reader Use-After-Free Vulnerability

Adobe Acrobat and Reader contains a use-after-free vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user.

Adobe / Acrobat and Reader
Articles
~/articles/2026-08-12-adobe-commerce-cve-2026-71362-active-exploit
Attackers Exploiting Critical Adobe Commerce Flaw
adobe

Attackers Exploiting Critical Adobe Commerce Flaw

Active exploitation of CVE-2026-71362 targets Adobe Commerce and Magento storefronts. CVSS 9.1 critical flaw enables account hijacking without user interaction.

read →
~/articles/2026-08-11-adobe-coldfusion-campaign-classic-aug-patches
Adobe Patches Critical Flaws in ColdFusion, Campaign Classic
adobe

Adobe Patches Critical Flaws in ColdFusion, Campaign Classic

Adobe patches critical RCE and DoS flaws in ColdFusion and Campaign Classic. Arbitrary code execution risk confirmed. Adobe explicitly urges immediate patching — act now.

read →
~/articles/2026-08-01-adobe-campaign-classic-cvss-10-rce
Adobe Patches Max-Severity RCE in Campaign Classic
adobe

Adobe Patches Max-Severity RCE in Campaign Classic

Adobe patched CVE-2026-48449, a CVSS 10.0 incorrect authorization flaw in Campaign Classic that enables remote code execution without user interaction.

read →
~/articles/2026-07-22-adobe-acrobat-chrome-extension-whatsapp-web-data-access
Adobe Acrobat Extension Let Sites Read WhatsApp Chats
adobe

Adobe Acrobat Extension Let Sites Read WhatsApp Chats

CVE-2026-48294 in the Adobe Acrobat Chrome extension let any site access WhatsApp Web data without authentication. Adobe has patched it — update now.

read →
~/articles/2026-07-08-cisa-coldfusion-cve-2026-48282-kev-friday-deadline
CISA: Patch ColdFusion CVE-2026-48282 by Friday
adobe

CISA: Patch ColdFusion CVE-2026-48282 by Friday

CISA added Adobe ColdFusion CVE-2026-48282 to KEV on July 7 and set a July 10 federal patch deadline under BOD 26-04. CVSS 10.0. Actively exploited.

read →
~/articles/2026-07-06-adobe-coldfusion-cve-2026-48282-active-exploitation
Adobe ColdFusion CVE-2026-48282: CVSS 10, Exploited
adobe

Adobe ColdFusion CVE-2026-48282: CVSS 10, Exploited

A max-severity unauthenticated path-traversal-to-RCE in ColdFusion 2023 and 2025 is under active attack. Adobe's 72-hour patch window has already passed. Shadowserver counts ~800 exposed instances.

read →