Adobe vendor intelligence

Adobe Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting Adobe products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Browse KEV feed
Total KEVs
100
Known exploited vulnerabilities affecting Adobe products
In CISA KEV
82
Records also listed in the official catalog
Beyond CISA KEV
18
Additional exploited vulnerabilities absent from CISA KEV
Sensor Observed
6
Adobe KEVs with sensor-observed exploitation activity

The catalog gap matters for Adobe exposure

Eighteen of the 100 exploited Adobe vulnerabilities tracked by Previdian are not in CISA KEV. Teams relying on the official catalog alone would miss 18% of this vendor portfolio.

82%
Covered by CISA
18%
Beyond CISA
26
Product families

Attested Adobe vulnerabilities

100 known exploited vulnerabilities in this exploited-vulnerability portfolio. Search, then narrow it to official CISA coverage or the additional records Previdian tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2026-71362

Adobe Commerce | Incorrect Authorization (CWE-863)

Adobe Commerce, Adobe Commerce B2B, Magento Open Source Confirmed In CISA 10 Sep 2026
CVE-2026-75650

Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)

Adobe Commerce, Adobe Commerce B2B, Magento Open Source Confirmed In CISA 05 Sep 2026
CVE-2026-48313

ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)

ColdFusion 2025, ColdFusion 2023 Confirmed Beyond CISA 04 Aug 2026
CVE-2026-48282

ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)

ColdFusion 2025, ColdFusion 2023 Confirmed In CISA 02 Jul 2026
CVE-2025-49533

Adobe Experience Manager (MS) | Deserialization of Untrusted Data (CWE-502)

Adobe Experience Manager (MS) High Beyond CISA 21 Oct 2025
CVE-2021-21087

ColdFusion Improper neutralization of web input during page generation could lead to arbitrary JavaScript execution in the browser

ColdFusion High Beyond CISA 26 Jul 2025
CVE-2026-34621

Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)

Acrobat DC, Acrobat Reader DC, Acrobat 2024 Confirmed In CISA 01 Jun 2026
CVE-2020-9715

Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an...

Adobe Acrobat and Reader Confirmed In CISA 01 Jun 2026
CVE-2025-54236

Adobe Commerce | Improper Input Validation (CWE-20)

Adobe Commerce Confirmed In CISA 09 Sep 2025
CVE-2025-54253

Adobe Experience Manager | Incorrect Authorization (CWE-863)

Adobe Experience Manager Confirmed In CISA 01 Jun 2026
CVE-2025-54254

Adobe Experience Manager | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)

Adobe Experience Manager High Beyond CISA 05 Aug 2025
CVE-2014-0515

Buffer overflow in Adobe Flash Player before 11.7.700.279 and 11.8.x through 13.0.x before 13.0.0.206 on Windows and OS X, and before 11.2.202.356...

Flash Player High Beyond CISA 29 Apr 2014
CVE-2013-5331

Adobe Flash Player before 11.7.700.257 and 11.8.x and 11.9.x before 11.9.900.170 on Windows and Mac OS X and before 11.2.202.332 on Linux, Adobe...

Flash Player High Beyond CISA 11 Dec 2013
CVE-2013-0634

Adobe Flash Player before 10.3.183.51 and 11.x before 11.5.502.149 on Windows and Mac OS X, before 10.3.183.51 and 11.x before 11.2.202.262 on...

Flash Player High Beyond CISA 08 Feb 2013
CVE-2013-0633

Buffer overflow in Adobe Flash Player before 10.3.183.51 and 11.x before 11.5.502.149 on Windows and Mac OS X, before 10.3.183.51 and 11.x before...

Flash Player High Beyond CISA 08 Feb 2013
CVE-2012-0779

Adobe Flash Player before 10.3.183.19 and 11.x before 11.2.202.235 on Windows, Mac OS X, and Linux; before 11.1.111.9 on Android 2.x and 3.x; and...

Flash Player High Beyond CISA 04 May 2012
CVE-2011-4369

Unspecified vulnerability in the PRC component in Adobe Reader and Acrobat 9.x before 9.4.7 on Windows, Adobe Reader and Acrobat 9.x through 9.4.6...

Reader and Acrobat High Beyond CISA 16 Dec 2011
CVE-2011-2444

Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.10 on Windows, Mac OS X, Linux, and Solaris, and before 10.3.186.7...

Flash Player High Beyond CISA 22 Sep 2011
CVE-2011-2110

Adobe Flash Player before 10.3.181.26 on Windows, Mac OS X, Linux, and Solaris, and 10.3.185.23 and earlier on Android, allows remote attackers to...

Flash Player High Beyond CISA 16 Jun 2011
CVE-2011-0627

Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.21 on Android allows remote attackers to execute...

Flash Player High Beyond CISA 13 May 2011
CVE-2010-3654

Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris and 10.1.95.1 on Android, and authplay.dll...

Flash Player High Beyond CISA 29 Oct 2010
CVE-2010-3653

The Director module (dirapi.dll) in Adobe Shockwave Player before 11.5.9.615 allows remote attackers to execute arbitrary code or cause a denial of...

Shockwave Player High Beyond CISA 26 Oct 2010
CVE-2010-2884

Adobe Flash Player 10.1.82.76 and earlier on Windows, Mac OS X, Linux, and Solaris and 10.1.92.10 on Android; authplay.dll in Adobe Reader and...

Flash Player, Reader, Acrobat High Beyond CISA 15 Sep 2010
CVE-2009-3459

Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute...

Reader and Acrobat Confirmed In CISA 13 Oct 2009
CVE-2009-0658

Buffer overflow in Adobe Reader 9.0 and earlier, and Acrobat 9.0 and earlier, allows remote attackers to execute arbitrary code via a crafted PDF...

Reader High Beyond CISA 20 Feb 2009
CVE-2008-3873

The System.setClipboard method in ActionScript in Adobe Flash Player 9.0.124.0 and earlier allows remote attackers to populate the clipboard with a...

Flash Player High Beyond CISA 29 Aug 2008
CVE-2018-4878

A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the...

Adobe Flash Player before 28.0.0.161 Confirmed In CISA 03 Nov 2021
CVE-2018-15961

Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file upload...

ColdFusion Confirmed In CISA 03 Nov 2021
CVE-2018-4939

Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Deserialization of Untrusted Data...

Adobe ColdFusion ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions Confirmed In CISA 03 Nov 2021
CVE-2021-28550

Adobe Acrobat Reader use after free vulnerability could lead to arbitrary code execution

Acrobat Reader Confirmed In CISA 03 Nov 2021
CVE-2021-21017

Acrobat Reader DC Heap-based Buffer Overflow Vulnerability Could Lead To Arbitrary Code Execution

Acrobat Reader Confirmed In CISA 03 Nov 2021
CVE-2018-15982

Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to...

Flash Player Confirmed In CISA 15 Feb 2022
CVE-2022-24086

Adobe Commerce checkout improper input validation leads to remote code execution

Magento Commerce Confirmed In CISA 15 Feb 2022
CVE-2008-2992

Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file that...

Acrobat and Reader Confirmed In CISA 03 Mar 2022
CVE-2010-0188

Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a denial of service...

Reader and Acrobat Confirmed In CISA 03 Mar 2022
CVE-2011-0611

Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140;...

Flash Player, AIR, Reader, Acrobat Confirmed In CISA 03 Mar 2022
CVE-2012-1535

Unspecified vulnerability in Adobe Flash Player before 11.3.300.271 on Windows and Mac OS X and before 11.2.202.238 on Linux allows remote...

Flash Player Confirmed In CISA 03 Mar 2022
CVE-2013-0632

administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary...

ColdFusion Confirmed In CISA 03 Mar 2022
CVE-2013-0640

Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or cause a...

Reader and Acrobat Confirmed In CISA 03 Mar 2022
CVE-2013-0641

Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allows remote attackers to execute...

Reader and Acrobat Confirmed In CISA 03 Mar 2022
CVE-2013-3346

Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial...

Reader and Acrobat Confirmed In CISA 03 Mar 2022
CVE-2014-0496

Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.9 and 11.x before 11.0.06 on Windows and Mac OS X allows attackers to...

Reader and Acrobat Confirmed In CISA 03 Mar 2022
CVE-2015-3043

Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers...

Flash Player Confirmed In CISA 03 Mar 2022
CVE-2015-5119

Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and...

Flash Player Confirmed In CISA 03 Mar 2022
CVE-2015-7645

Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote...

Flash Player Confirmed In CISA 03 Mar 2022
CVE-2016-1019

Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary...

Flash Player Confirmed In CISA 03 Mar 2022
CVE-2016-4117

Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in...

Flash Player Confirmed In CISA 03 Mar 2022
CVE-2016-7855

Use-after-free vulnerability in Adobe Flash Player before 23.0.0.205 on Windows and OS X and before 11.2.202.643 on Linux allows remote attackers...

Flash Player Confirmed In CISA 03 Mar 2022
CVE-2017-11292

Adobe Flash Player version 27.0.0.159 and earlier has a flawed bytecode verification procedure, which allows for an untrusted value to be used in...

Adobe Flash Player version 27.0.0.159 and earlier Confirmed In CISA 03 Mar 2022
CVE-2009-3960

Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0,...

BlazeDS Confirmed In CISA 07 Mar 2022

Showing 50 of 50 on this page (100 Adobe known exploited vulnerabilities).

Recurring weakness patterns

Use after free, out-of-bounds write, and restriction account for 35 mapped occurrences across this Adobe KEV portfolio.

Browse all KEVs →