Skip to main content

Adobe security briefs

18 published alerts for Adobe products and services.

Actively exploited (KEV)

CVE-2026-75650

Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability

Adobe Commerce and Magento is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-75650). Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code. CISA remediation due date: 2026-09-11. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-48282

Adobe ColdFusion Path Traversal Vulnerability

Adobe ColdFusion is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-48282). Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user. CISA remediation due date: 2026-07-10. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2009-3459

Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability

Adobe Acrobat and Reader is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2009-3459). Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption. CISA remediation due date: 2026-06-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-34621

Adobe Acrobat and Reader Prototype Pollution Vulnerability

Adobe Acrobat and Reader is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-34621). Adobe Acrobat and Reader contain a prototype pollution vulnerability that allows for arbitrary code execution. CISA remediation due date: 2026-04-27. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2020-9715

Adobe Acrobat Use-After-Free Vulnerability

Adobe Acrobat is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2020-9715). Adobe Acrobat contains a use-after-free vulnerability that allows for code execution CISA remediation due date: 2026-04-27. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2025-54236

Adobe Commerce and Magento Improper Input Validation Vulnerability

Adobe Commerce and Magento is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-54236). Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API. CISA remediation due date: 2025-11-14. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2025-54253

Adobe Experience Manager Forms Code Execution Vulnerability

Adobe Experience Manager (AEM) Forms is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-54253). Adobe Experience Manager Forms in JEE contains an unspecified vulnerability that allows for arbitrary code execution. CISA remediation due date: 2025-11-05. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-38203

Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

Adobe ColdFusion is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-38203). Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution. CISA remediation due date: 2024-01-29. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-29300

Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

Adobe ColdFusion is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-29300). Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution. CISA remediation due date: 2024-01-29. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2010-2861

Adobe ColdFusion Directory Traversal Vulnerability

Adobe ColdFusion is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2010-2861). A directory traversal vulnerability exists in the administrator console in Adobe ColdFusion which allows remote attackers to read arbitrary files. CISA remediation due date: 2022-04-15. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2009-3960

Adobe BlazeDS Information Disclosure Vulnerability

Adobe BlazeDS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2009-3960). Adobe BlazeDS, which is utilized in LifeCycle and Coldfusion, contains a vulnerability that allows for information disclosure. CISA remediation due date: 2022-09-07. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2016-4117

Adobe Flash Player Arbitrary Code Execution Vulnerability

Adobe Flash Player is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2016-4117). An access of resource using incompatible type vulnerability exists within Adobe Flash Player that allows an attacker to perform remote code execution. CISA remediation due date: 2022-03-24. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2016-1019

Adobe Flash Player Arbitrary Code Execution Vulnerability

Adobe Flash Player is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2016-1019). Adobe Flash Player allows remote attackers to cause a denial of service or possibly execute arbitrary code. CISA remediation due date: 2022-03-24. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2015-7645

Adobe Flash Player Arbitrary Code Execution Vulnerability

Adobe Flash Player is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2015-7645). Adobe Flash Player allows remote attackers to execute arbitrary code via a crafted SWF file. CISA remediation due date: 2022-03-24. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2010-0188

Adobe Reader and Acrobat Arbitrary Code Execution Vulnerability

Adobe Reader and Acrobat is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2010-0188). Unspecified vulnerability in Adobe Reader and Acrobat allows attackers to cause a denial of service or possibly execute arbitrary code. CISA remediation due date: 2022-03-24. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2008-2992

Adobe Reader and Acrobat Input Validation Vulnerability

Adobe Acrobat and Reader is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2008-2992). Adobe Acrobat and Reader contain an input validation issue in a JavaScript method that could potentially lead to remote code execution. CISA remediation due date: 2022-03-24. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2018-15982

Adobe Flash Player Use-After-Free Vulnerability

Adobe Flash Player is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-15982). Adobe Flash Player com.adobe.tvsdk.mediacore.metadata Use After Free Vulnerability CISA remediation due date: 2022-08-15. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2018-4878

Adobe Flash Player Use-After-Free Vulnerability

Adobe Flash Player is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-4878). Adobe Flash Player contains a use-after-free vulnerability that could allow for code execution. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.