Adobe vendor intelligence

Adobe Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting Adobe products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Browse KEV feed
Total KEVs
100
Known exploited vulnerabilities affecting Adobe products
In CISA KEV
82
Records also listed in the official catalog
Beyond CISA KEV
18
Additional exploited vulnerabilities absent from CISA KEV
Sensor Observed
6
Adobe KEVs with sensor-observed exploitation activity

The catalog gap matters for Adobe exposure

Eighteen of the 100 exploited Adobe vulnerabilities tracked by Previdian are not in CISA KEV. Teams relying on the official catalog alone would miss 18% of this vendor portfolio.

82%
Covered by CISA
18%
Beyond CISA
26
Product families

Attested Adobe vulnerabilities

100 known exploited vulnerabilities in this exploited-vulnerability portfolio. Search, then narrow it to official CISA coverage or the additional records Previdian tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2013-0625

Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly execute...

ColdFusion Confirmed In CISA 07 Mar 2022
CVE-2013-0629

Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10, when a password is not configured, allows attackers to access restricted directories via unspecified...

ColdFusion Confirmed In CISA 07 Mar 2022
CVE-2013-0631

Adobe ColdFusion 9.0, 9.0.1, and 9.0.2 allows attackers to obtain sensitive information via unspecified vectors, as exploited in the wild in...

ColdFusion Confirmed In CISA 07 Mar 2022
CVE-2009-0927

Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows remote attackers to execute...

Reader and Acrobat Confirmed In CISA 25 Mar 2022
CVE-2010-2861

Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read...

ColdFusion Confirmed In CISA 25 Mar 2022
CVE-2016-4171

Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as...

Flash Player Confirmed In CISA 25 Mar 2022
CVE-2016-7892

Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the TextField...

Adobe Flash Player 23.0.0.207 and earlier, 11.2.202.644 and earlier Confirmed In CISA 25 Mar 2022
CVE-2012-2034

Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x before 11.2.202.236 on...

Flash Player Confirmed In CISA 28 Mar 2022
CVE-2013-2729

Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary...

Reader and Acrobat Confirmed In CISA 28 Mar 2022
CVE-2014-9163

Stack-based buffer overflow in Adobe Flash Player before 13.0.0.259 and 14.x and 15.x before 15.0.0.246 on Windows and OS X and before 11.2.202.425...

Flash Player Confirmed In CISA 13 Apr 2022
CVE-2015-0311

Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through...

Flash Player Confirmed In CISA 13 Apr 2022
CVE-2015-0313

Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before...

Flash Player Confirmed In CISA 13 Apr 2022
CVE-2015-3113

Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before...

Flash Player Confirmed In CISA 13 Apr 2022
CVE-2015-5122

Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on...

Flash Player Confirmed In CISA 13 Apr 2022
CVE-2015-5123

Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on...

Flash Player Confirmed In CISA 13 Apr 2022
CVE-2018-5002

Adobe Flash Player versions 29.0.0.171 and earlier have a Stack-based buffer overflow vulnerability. Successful exploitation could lead to...

Adobe Flash Player 29.0.0.171 and earlier versions Confirmed In CISA 23 May 2022
CVE-2014-0546

Adobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows allow attackers to bypass a sandbox protection mechanism, and...

Reader and Acrobat Confirmed In CISA 25 May 2022
CVE-2014-8439

Adobe Flash Player before 13.0.0.258 and 14.x and 15.x before 15.0.0.239 on Windows and OS X and before 11.2.202.424 on Linux, Adobe AIR before...

Flash Player Confirmed In CISA 25 May 2022
CVE-2015-8651

Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux,...

Flash Player Confirmed In CISA 25 May 2022
CVE-2015-0310

Adobe Flash Player before 13.0.0.262 and 14.x through 16.x before 16.0.0.287 on Windows and OS X and before 11.2.202.438 on Linux does not properly...

Flash Player Confirmed In CISA 25 May 2022
CVE-2016-0984

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before...

Flash Player Confirmed In CISA 25 May 2022
CVE-2016-1010

Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on...

Flash Player Confirmed In CISA 25 May 2022
CVE-2007-5659

Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and earlier allow remote attackers to execute arbitrary code via a PDF file with long...

Reader and Acrobat Confirmed In CISA 08 Jun 2022
CVE-2008-0655

Multiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact and attack vectors.

Reader and Acrobat Confirmed In CISA 08 Jun 2022
CVE-2009-1862

Unspecified vulnerability in Adobe Reader and Acrobat 9.x through 9.1.2, and Adobe Flash Player 9.x through 9.0.159.0 and 10.x through 10.0.22.87,...

["Reader", "Acrobat", "Flash Player"] Confirmed In CISA 08 Jun 2022
CVE-2009-3953

The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote...

Reader and Acrobat Confirmed In CISA 08 Jun 2022
CVE-2009-4324

Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on...

Reader and Acrobat Confirmed In CISA 08 Jun 2022
CVE-2010-1297

Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3, and...

Flash Player, AIR, Reader, Acrobat Confirmed In CISA 08 Jun 2022
CVE-2010-2883

Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows remote...

Reader and Acrobat Confirmed In CISA 08 Jun 2022
CVE-2011-0609

Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier on...

Flash Player Confirmed In CISA 08 Jun 2022
CVE-2011-2462

Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x through...

Reader and Acrobat Confirmed In CISA 08 Jun 2022
CVE-2012-0754

Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and...

Flash Player Confirmed In CISA 08 Jun 2022
CVE-2012-0767

Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and...

Flash Player Confirmed In CISA 08 Jun 2022
CVE-2012-5054

Integer overflow in the copyRawDataTo method in the Matrix3D class in Adobe Flash Player before 11.4.402.265 allows remote attackers to execute...

Flash Player Confirmed In CISA 08 Jun 2022
CVE-2018-4990

Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Double Free...

Adobe Acrobat and Reader 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier versions Confirmed In CISA 08 Jun 2022
CVE-2023-26360

Adobe ColdFusion Improper Access Control Arbitrary code execution

ColdFusion Confirmed In CISA 15 Mar 2023
CVE-2023-38205

ColdFusion Bypass - Vulnerability disclosure in ColdFusion | BYPASS CVE-2023-29298

ColdFusion Confirmed In CISA 20 Jul 2023
CVE-2023-29298

Adobe ColdFusion Improper Access Control Security feature bypass

ColdFusion Confirmed In CISA 20 Jul 2023
CVE-2023-26359

Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code execution

ColdFusion Confirmed In CISA 21 Aug 2023
CVE-2023-26369

[Google Project Zero] Adobe Acrobat DC OOBW 0-day actively exploited in the wild

Acrobat Reader Confirmed In CISA 14 Sep 2023
CVE-2023-21608

Adobe Acrobat Reader DC resetForm Use-After-Free Remote Code Execution Vulnerability

Acrobat Reader Confirmed In CISA 10 Oct 2023
CVE-2023-38203

Analysis CVE-2023-29300 Bypass: Adobe ColdFusion Pre-Auth RCE

ColdFusion Confirmed In CISA 08 Jan 2024
CVE-2023-29300

Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code execution

ColdFusion Confirmed In CISA 08 Jan 2024
CVE-2024-34102

XXE can expose crypt key and other secrets granting full admin access

Adobe Commerce Confirmed In CISA 13 Jun 2024
CVE-2014-0497

Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before...

Flash Player Confirmed In CISA 17 Sep 2024
CVE-2013-0643

The Firefox sandbox in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x...

Flash Player Confirmed In CISA 17 Sep 2024
CVE-2013-0648

Unspecified vulnerability in the ExternalInterface ActionScript functionality in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171...

Flash Player Confirmed In CISA 17 Sep 2024
CVE-2014-0502

Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before...

Flash Player Confirmed In CISA 17 Sep 2024
CVE-2024-20767

ColdFusion | Improper Access Control (CWE-284)

ColdFusion Confirmed In CISA 16 Dec 2024
CVE-2017-3066

Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization...

Adobe ColdFusion ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier Confirmed In CISA 24 Feb 2025

Showing 50 of 50 on this page (100 Adobe known exploited vulnerabilities).

Recurring weakness patterns

Use after free, out-of-bounds write, and restriction account for 35 mapped occurrences across this Adobe KEV portfolio.

Browse all KEVs →