Adobe Vulnerabilities
Adobe's products include Acrobat and Acrobat Reader for PDF documents, the ColdFusion application platform and Adobe Commerce (Magento), and it formerly shipped Flash Player, which reached end of life on December 31, 2020. The database tracks 82 Adobe CVE records. CISA lists 82 of them as exploited in the wild, most recently on 2026-09-24. The most affected products are Flash Player, ColdFusion, Acrobat and Reader.
Recently Exploited Adobe CVEs
Adobe Commerce | Incorrect Authorization (CWE-863)
Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability
Adobe Acrobat Use-After-Free Vulnerability
Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)
Affected Products
14 products| Product | CVEs | KEV | Latest |
|---|---|---|---|
| Flash Player | 33 | 33 | 2024-09-17 |
| ColdFusion | 16 | 16 | 2026-07-07 |
| Acrobat and Reader | 13 | 13 | 2026-05-20 |
| Reader and Acrobat | 8 | 8 | 2022-06-08 |
| Commerce and Magento Open Source | 2 | 2 | 2024-07-17 |
| Flash Player and AIR | 2 | 2 | 2022-05-25 |
| Acrobat | 1 | 1 | 2026-04-13 |
| Acrobat and Reader, Flash Player | 1 | 1 | 2022-06-08 |
| BlazeDS | 1 | 1 | 2022-03-07 |
| Commerce and Magento | 1 | 1 | 2026-09-08 |
| Commerce and Magento | 1 | 1 | 2025-10-24 |
| Commerce and Magento | 1 | 1 | 2026-09-24 |
| Experience Manager (AEM) Forms | 1 | 1 | 2025-10-15 |
| Reader | 1 | 1 | 2022-03-03 |
All Adobe CVEs
82 records| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2026-71362 | Adobe Commerce | Incorrect Authorization (CWE-863) | Adobe | 9.1 | 87.5% | KEV | 2026-08-11 |
| CVE-2026-75650 | Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) | Adobe | 10.0 | 3.9% | KEV | 2026-09-07 |
| CVE-2026-48282 | ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) | Adobe | 10.0 | 42.4% | KEV | 2026-06-30 |
| CVE-2009-3459 | Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability | - | 8.8 | 86.6% | KEV | 2009-10-13 |
| CVE-2020-9715 | Adobe Acrobat Use-After-Free Vulnerability | Adobe | 7.8 | 48.6% | KEV | 2020-08-19 |
| CVE-2026-34621 | Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321) | Adobe | 8.6 | 2.2% | KEV | 2026-04-11 |
| CVE-2025-54236 | Adobe Commerce | Improper Input Validation (CWE-20) | Adobe | 9.1 | 94.5% | KEV | 2025-09-09 |
| CVE-2025-54253 | Adobe Experience Manager | Incorrect Authorization (CWE-863) | Adobe | 10.0 | 88.3% | KEV | 2025-08-05 |
| CVE-2017-3066 | Adobe ColdFusion Deserialization Vulnerability | - | 9.8 | 90.6% | KEV | 2017-04-27 |
| CVE-2024-20767 | ColdFusion | Improper Access Control (CWE-284) | Adobe | 7.4 | 98.5% | KEV | 2024-03-18 |
| CVE-2014-0497 | Adobe Flash Player Integer Underflow Vulnerablity | - | 8.8 | 99.9% | KEV | 2014-02-05 |
| CVE-2014-0502 | Adobe Flash Player Double Free Vulnerablity | - | 8.8 | 24.8% | KEV | 2014-02-21 |
| CVE-2013-0648 | Adobe Flash Player Code Execution Vulnerability | - | 8.8 | 11.1% | KEV | 2013-02-27 |
| CVE-2013-0643 | Adobe Flash Player Incorrect Default Permissions Vulnerability | - | 8.8 | 10.5% | KEV | 2013-02-27 |
| CVE-2024-34102 | XXE can expose crypt key and other secrets granting full admin access | Adobe | 9.8 | 100.0% | KEV | 2024-06-13 |
| CVE-2023-29300 | Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code execution | Adobe | 9.8 | 100.0% | KEV | 2023-07-12 |
| CVE-2023-38203 | Analysis CVE-2023-29300 Bypass: Adobe ColdFusion Pre-Auth RCE | Adobe | 9.8 | 97.1% | KEV | 2023-07-20 |
| CVE-2023-21608 | Adobe Acrobat Reader DC resetForm Use-After-Free Remote Code Execution Vulnerability | Adobe | 7.8 | 61.5% | KEV | 2023-01-18 |
| CVE-2023-26369 | [Google Project Zero] Adobe Acrobat DC OOBW 0-day actively exploited in the wild | Adobe | 7.8 | 6.7% | KEV | 2023-09-13 |
| CVE-2023-26359 | Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code execution | Adobe | 9.8 | 17.0% | KEV | 2023-03-23 |
| CVE-2023-29298 | Adobe ColdFusion Improper Access Control Security feature bypass | Adobe | 7.5 | 99.8% | KEV | 2023-07-12 |
| CVE-2023-38205 | ColdFusion Bypass - Vulnerability disclosure in ColdFusion | BYPASS CVE-2023-29298 | Adobe | 7.5 | 99.8% | KEV | 2023-09-14 |
| CVE-2023-26360 | Adobe ColdFusion Improper Access Control Arbitrary code execution | Adobe | 8.6 | 97.3% | KEV | 2023-03-23 |
| CVE-2012-0754 | Adobe Flash Player Memory Corruption Vulnerability | - | 7.8 | 91.1% | KEV | 2012-02-16 |
| CVE-2011-2462 | Adobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability | - | 8.8 | 88.9% | KEV | 2011-12-07 |
| CVE-2007-5659 | Adobe Acrobat and Reader Buffer Overflow Vulnerability | - | 7.8 | 87.4% | KEV | 2008-02-12 |
| CVE-2009-3953 | Adobe Acrobat and Reader Universal 3D Remote Code Execution Vulnerability | - | 8.8 | 83.2% | KEV | 2010-01-13 |
| CVE-2010-1297 | Adobe Flash Player Memory Corruption Vulnerability | - | 7.8 | 82.5% | KEV | 2010-06-08 |
| CVE-2009-4324 | Adobe Acrobat and Reader Use-After-Free Vulnerability | - | 7.8 | 81.9% | KEV | 2009-12-15 |
| CVE-2010-2883 | Adobe Acrobat and Reader Stack-Based Buffer Overflow Vulnerability | - | 7.3 | 81.4% | KEV | 2010-09-09 |
| CVE-2011-0609 | Adobe Flash Player Unspecified Vulnerability | - | 7.8 | 63.5% | KEV | 2011-03-15 |
| CVE-2008-0655 | Adobe Acrobat and Reader Unspecified Vulnerability | - | 8.8 | 37.9% | KEV | 2008-02-07 |
| CVE-2018-4990 | Adobe Acrobat and Reader Double Free Vulnerability | - | 8.8 | 36.2% | KEV | 2018-07-09 |
| CVE-2009-1862 | Adobe Acrobat and Reader, Flash Player Unspecified Vulnerability | - | 7.8 | 21.2% | KEV | 2009-07-23 |
| CVE-2012-5054 | Adobe Flash Player Integer Overflow Vulnerability | - | 8.8 | 21.2% | KEV | 2012-09-24 |
| CVE-2012-0767 | Adobe Flash Player Cross-Site Scripting (XSS) Vulnerability | - | 6.1 | 6.2% | KEV | 2012-02-16 |
| CVE-2015-8651 | Adobe Flash Player Integer Overflow Vulnerability | - | 8.8 | 67.7% | KEV | 2015-12-28 |
| CVE-2016-0984 | Adobe Flash Player and AIR Use-After-Free Vulnerability | - | 8.8 | 54.5% | KEV | 2016-02-10 |
| CVE-2014-0546 | Adobe Reader and Acrobat Sandbox Bypass Vulnerability | - | 8.8 | 22.3% | KEV | 2014-08-12 |
| CVE-2014-8439 | Adobe Flash Player Dereferenced Pointer Vulnerability | - | 8.8 | 20.4% | KEV | 2014-11-25 |
| CVE-2016-1010 | Adobe Flash Player and AIR Integer Overflow Vulnerability | - | 8.8 | 19.3% | KEV | 2016-03-12 |
| CVE-2015-0310 | Adobe Flash Player ASLR Bypass Vulnerability | - | 7.8 | 15.1% | KEV | 2015-01-23 |
| CVE-2018-5002 | Adobe Flash Player Stack-based Buffer Overflow Vulnerability | - | 7.8 | 25.1% | KEV | 2018-07-09 |
| CVE-2015-3113 | Adobe Flash Player Heap-Based Buffer Overflow Vulnerability | - | 7.8 | 99.8% | KEV | 2015-06-23 |
| CVE-2015-0313 | Adobe Flash Player Use-After-Free Vulnerability | - | 7.8 | 95.3% | KEV | 2015-02-02 |
| CVE-2015-5122 | Adobe Flash Player Use-After-Free Vulnerability | - | 7.8 | 94.0% | KEV | 2015-07-14 |
| CVE-2015-0311 | Adobe Flash Player Remote Code Execution Vulnerability | - | 7.8 | 85.6% | KEV | 2015-01-23 |
| CVE-2014-9163 | Adobe Flash Player Stack-Based Buffer Overflow Vulnerability | - | 7.8 | 20.7% | KEV | 2014-12-10 |
| CVE-2015-5123 | Adobe Flash Player Use-After-Free Vulnerability | - | 7.8 | 18.8% | KEV | 2015-07-14 |
| CVE-2013-2729 | Adobe Reader and Acrobat Arbitrary Integer Overflow Vulnerability | - | 8.8 | 66.6% | KEV | 2013-05-16 |
| CVE-2012-2034 | Adobe Flash Player Memory Corruption Vulnerability | - | 7.5 | 7.8% | KEV | 2012-06-09 |
| CVE-2010-2861 | Adobe ColdFusion Directory Traversal Vulnerability | - | 7.5 | 99.7% | KEV | 2010-08-11 |
| CVE-2009-0927 | Adobe Reader and Adobe Acrobat Stack-Based Buffer Overflow Vulnerability | - | 8.8 | 96.6% | KEV | 2009-03-19 |
| CVE-2016-4171 | Adobe Flash Player Remote Code Execution Vulnerability | - | 7.8 | 20.1% | KEV | 2016-06-16 |
| CVE-2016-7892 | Adobe Flash Player Use-After-Free Vulnerability | - | 8.8 | 18.8% | KEV | 2016-12-15 |
| CVE-2013-0625 | Adobe ColdFusion Authentication Bypass Vulnerability | - | 9.8 | 93.8% | KEV | 2013-01-09 |
| CVE-2009-3960 | Adobe BlazeDS Information Disclosure Vulnerability | - | 6.5 | 90.1% | KEV | 2010-02-15 |
| CVE-2013-0631 | Adobe ColdFusion Information Disclosure Vulnerability | - | 7.5 | 66.4% | KEV | 2013-01-09 |
| CVE-2013-0629 | Adobe ColdFusion Directory Traversal Vulnerability | - | 7.5 | 65.8% | KEV | 2013-01-09 |
| CVE-2011-0611 | Adobe Flash Player Remote Code Execution Vulnerability | - | 8.8 | 99.4% | KEV | 2011-04-13 |
| CVE-2015-5119 | Adobe Flash Player Use-After-Free Vulnerability | - | 7.8 | 99.3% | KEV | 2015-07-08 |
| CVE-2008-2992 | Adobe Reader and Acrobat Input Validation Vulnerability | - | 7.8 | 98.5% | KEV | 2008-11-04 |
| CVE-2016-4117 | Adobe Flash Player Arbitrary Code Execution Vulnerability | - | 7.8 | 94.4% | KEV | 2016-05-11 |
| CVE-2013-0632 | Adobe ColdFusion Authentication Bypass Vulnerability | - | 9.8 | 93.6% | KEV | 2013-01-17 |
| CVE-2010-0188 | Adobe Reader and Acrobat Arbitrary Code Execution Vulnerability | - | 7.8 | 88.2% | KEV | 2010-02-21 |
| CVE-2013-0640 | Adobe Reader and Acrobat Memory Corruption Vulnerability | - | 7.8 | 86.9% | KEV | 2013-02-14 |
| CVE-2013-3346 | Adobe Reader and Acrobat Memory Corruption Vulnerability | - | 8.8 | 78.9% | KEV | 2013-08-30 |
| CVE-2015-3043 | Adobe Flash Player Memory Corruption Vulnerability | - | 7.8 | 73.9% | KEV | 2015-04-14 |
| CVE-2012-1535 | Adobe Flash Player Arbitrary Code Execution Vulnerability | - | 7.8 | 70.4% | KEV | 2012-08-15 |
| CVE-2015-7645 | Adobe Flash Player Arbitrary Code Execution Vulnerability | - | 7.8 | 65.3% | KEV | 2015-10-15 |
| CVE-2014-0496 | Adobe Reader and Acrobat Use-After-Free Vulnerability | - | 8.8 | 40.0% | KEV | 2014-01-15 |
| CVE-2013-0641 | Adobe Reader Buffer Overflow Vulnerability | - | 7.8 | 32.3% | KEV | 2013-02-14 |
| CVE-2016-7855 | Adobe Flash Player Use-After-Free Vulnerability | - | 8.8 | 25.2% | KEV | 2016-11-01 |
| CVE-2016-1019 | Adobe Flash Player Arbitrary Code Execution Vulnerability | - | 7.8 | 22.3% | KEV | 2016-04-07 |
| CVE-2017-11292 | Adobe Flash Player Type Confusion Vulnerability | - | 8.8 | 11.9% | KEV | 2017-10-21 |
| CVE-2022-24086 | Adobe Commerce checkout improper input validation leads to remote code execution | Adobe | 9.8 | 99.2% | KEV | 2022-02-16 |
| CVE-2018-15982 | Adobe Flash Player Use-After-Free Vulnerability | - | 7.8 | 89.6% | KEV | 2019-01-18 |
| CVE-2018-15961 | Adobe ColdFusion Unrestricted File Upload Vulnerability | Adobe | 9.8 | 100.0% | KEV | 2018-09-25 |
| CVE-2018-4878 | Adobe Flash Player Use-After-Free Vulnerability | - | 7.8 | 89.5% | KEV | 2018-02-06 |
| CVE-2021-21017 | Acrobat Reader DC Heap-based Buffer Overflow Vulnerability Could Lead To Arbitrary Code Execution | Adobe | 8.8 | 86.3% | KEV | 2021-02-11 |
| CVE-2018-4939 | Adobe ColdFusion Deserialization of Untrusted Data Vulnerability | - | 9.8 | 62.0% | KEV | 2018-05-19 |
| CVE-2021-28550 | Adobe Acrobat Reader use after free vulnerability could lead to arbitrary code execution | Adobe | 9.6 | 51.9% | KEV | 2021-09-02 |
Frequently Asked Questions
How many Adobe vulnerabilities are actively exploited?→
82 Adobe CVEs are in the CISA Known Exploited Vulnerabilities catalog as of 2026-10-09. The latest was added on 2026-09-24.
Which Adobe vulnerabilities are used in ransomware attacks?→
CISA marks 11 Adobe KEV entries as known to be used in ransomware campaigns, including CVE-2023-29300, CVE-2023-38203, CVE-2010-2861, CVE-2009-3960, CVE-2008-2992.
Which Adobe products have the most exploited vulnerabilities?→
- +Flash Player: 33 CVEs (33 in KEV)
- +ColdFusion: 16 CVEs (16 in KEV)
- +Acrobat and Reader: 13 CVEs (13 in KEV)
- +Reader and Acrobat: 8 CVEs (8 in KEV)
- +Commerce and Magento Open Source: 2 CVEs (2 in KEV)
Where does Adobe publish security advisories?→
Adobe publishes security advisories at https://www.adobe.com/trust/security/bulletins-and-advisories.html. Check the vendor advisory for fixed versions and workarounds before applying updates.
Sources
CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Vendor and product names for exploited CVEs follow the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not affiliated with or endorsed by Adobe, MITRE, CISA, or FIRST.