Vendor
Adobe
As of , 82 Adobe vulnerabilities are on CISA's list of exploited vulnerabilities, 11 of them used in ransomware campaigns; 6 were added in 2026. Patch first: CVE-2026-71362.
Patch first
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 1 | CVE-2026-71362Incorrect Authorization | Adobe Commerce and Magento | Patch nowForensic triage required by CISA; listed in the last 14 days | 0.88 | ||
| 2 | CVE-2026-48282Path Traversal | Adobe ColdFusion | Patch nowForensic triage required by CISA | 0.42 | ||
| 3 | CVE-2026-75650Improper Neutralization of Special Elements Used in a Template Engine | Adobe Commerce and Magento | Patch nowForensic triage required by CISA | 0.04 | ||
| 4 | CVE-2009-3459Heap-Based Buffer Overflow | Adobe Acrobat and Reader | Patch this weekMetasploit module; EPSS 0.87; verified Exploit-DB entry | 0.87 | ||
| 5 | CVE-2014-0497Integer Underflow Vulnerablity | Adobe Flash Player | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 6 | CVE-2007-5659Buffer Overflow | Adobe Acrobat and Reader | Patch this weekMetasploit module; EPSS 0.87; verified Exploit-DB entry | 0.87 | ||
| 7 | CVE-2009-3953Universal 3D Remote Code Execution | Adobe Acrobat and Reader | Patch this weekMetasploit module; EPSS 0.83; verified Exploit-DB entry | 0.83 | ||
| 8 | CVE-2009-4324Use-After-Free | Adobe Acrobat and Reader | Patch this weekMetasploit module; EPSS 0.82; verified Exploit-DB entry | 0.82 | ||
| 9 | CVE-2010-1297Memory Corruption | Adobe Flash Player | Patch this weekMetasploit module; EPSS 0.83; verified Exploit-DB entry | 0.83 | ||
| 10 | CVE-2010-2883Stack-Based Buffer Overflow | Adobe Acrobat and Reader | Patch this weekMetasploit module; EPSS 0.81; verified Exploit-DB entry | 0.81 | ||
| 11 | CVE-2011-0609Unspecified | Adobe Flash Player | Patch this weekMetasploit module; EPSS 0.64; verified Exploit-DB entry | 0.64 | ||
| 12 | CVE-2011-2462Universal 3D Memory Corruption | Adobe Reader and Acrobat | Patch this weekMetasploit module; EPSS 0.89; verified Exploit-DB entry | 0.89 | ||
| 13 | CVE-2012-0754Memory Corruption | Adobe Flash Player | Patch this weekMetasploit module; EPSS 0.91; verified Exploit-DB entry | 0.91 | ||
| 14 | CVE-2015-0311Remote Code Execution | Adobe Flash Player | Patch this weekMetasploit module; EPSS 0.86; verified Exploit-DB entry | 0.86 | ||
| 15 | CVE-2015-0313Use-After-Free | Adobe Flash Player | Patch this weekMetasploit module; EPSS 0.95; verified Exploit-DB entry | 0.95 | ||
| 16 | CVE-2015-3113Heap-Based Buffer Overflow | Adobe Flash Player | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 17 | CVE-2015-5122Use-After-Free | Adobe Flash Player | Patch this weekMetasploit module; EPSS 0.94; verified Exploit-DB entry | 0.94 | ||
| 18 | CVE-2009-0927Reader and Adobe Acrobat Stack-Based Buffer Overflow | Adobe Reader and Acrobat | Patch this weekMetasploit module; EPSS 0.97; verified Exploit-DB entry | 0.97 | ||
| 19 | CVE-2010-2861Directory Traversal | Adobe ColdFusion | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 20 | CVE-2009-3960Information Disclosure | Adobe BlazeDS | Patch this weekRansomware use; Metasploit module; EPSS 0.90; verified Exploit-DB entry | 0.90 | ||
| 21 | CVE-2008-2992Reader and Acrobat Input Validation | Adobe Acrobat and Reader | Patch this weekRansomware use; Metasploit module; EPSS 0.98; verified Exploit-DB entry | 0.98 | ||
| 22 | CVE-2010-0188Arbitrary Code Execution | Adobe Reader and Acrobat | Patch this weekRansomware use; Metasploit module; EPSS 0.88; verified Exploit-DB entry | 0.88 | ||
| 23 | CVE-2011-0611Remote Code Execution | Adobe Flash Player | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 24 | CVE-2012-1535Arbitrary Code Execution | Adobe Flash Player | Patch this weekMetasploit module; EPSS 0.70; verified Exploit-DB entry | 0.70 | ||
| 25 | CVE-2013-0632Authentication Bypass | Adobe ColdFusion | Patch this weekMetasploit module; EPSS 0.94; verified Exploit-DB entry | 0.94 |
Products
- Flash Player33 entries
- ColdFusion16 entries
- Acrobat and Reader13 entries
- Reader and Acrobat8 entries
- Commerce and Magento3 entries
- Commerce and Magento Open Source2 entries
- Flash Player and AIR2 entries
- Acrobat1 entry
- Acrobat and Reader, Flash Player1 entry
- BlazeDS1 entry
- Experience Manager (AEM) Forms1 entry
- Reader1 entry
Added each year
Show the numbers
| Period | entries added |
|---|---|
| 2021 | 5 |
| 2022 | 54 |
| 2023 | 6 |
| 2024 | 8 |
| 2025 | 3 |
| 2026 | 6 |
Used in ransomware
Changes CISA made to these entries
- CVE-2014-0546 Adobe Reader and AcrobatRenamed from Acrobat and Reader to Reader and Acrobat. Edited: description and name.
- CVE-2011-2462 Adobe Reader and AcrobatRenamed from Acrobat and Reader to Reader and Acrobat. Edited: description and name.
- CVE-2025-54253 Adobe Experience Manager (AEM) FormsDeadline moved from 6 November 2025 to 5 November 2025. Listing date changed from 16 October 2025 to 15 October 2025.