Vendor

Adobe

As of , 82 Adobe vulnerabilities are on CISA's list of exploited vulnerabilities, 11 of them used in ransomware campaigns; 6 were added in 2026. Patch first: CVE-2026-71362.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2026-71362Incorrect AuthorizationAdobe Commerce and MagentoPatch nowForensic triage required by CISA; listed in the last 14 days0.88
2CVE-2026-48282Path TraversalAdobe ColdFusionPatch nowForensic triage required by CISA0.42
3CVE-2026-75650Improper Neutralization of Special Elements Used in a Template EngineAdobe Commerce and MagentoPatch nowForensic triage required by CISA0.04
4CVE-2009-3459Heap-Based Buffer OverflowAdobe Acrobat and ReaderPatch this weekMetasploit module; EPSS 0.87; verified Exploit-DB entry0.87
5CVE-2014-0497Integer Underflow VulnerablityAdobe Flash PlayerPatch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry0.99
6CVE-2007-5659Buffer OverflowAdobe Acrobat and ReaderPatch this weekMetasploit module; EPSS 0.87; verified Exploit-DB entry0.87
7CVE-2009-3953Universal 3D Remote Code ExecutionAdobe Acrobat and ReaderPatch this weekMetasploit module; EPSS 0.83; verified Exploit-DB entry0.83
8CVE-2009-4324Use-After-FreeAdobe Acrobat and ReaderPatch this weekMetasploit module; EPSS 0.82; verified Exploit-DB entry0.82
9CVE-2010-1297Memory CorruptionAdobe Flash PlayerPatch this weekMetasploit module; EPSS 0.83; verified Exploit-DB entry0.83
10CVE-2010-2883Stack-Based Buffer OverflowAdobe Acrobat and ReaderPatch this weekMetasploit module; EPSS 0.81; verified Exploit-DB entry0.81
11CVE-2011-0609UnspecifiedAdobe Flash PlayerPatch this weekMetasploit module; EPSS 0.64; verified Exploit-DB entry0.64
12CVE-2011-2462Universal 3D Memory CorruptionAdobe Reader and AcrobatPatch this weekMetasploit module; EPSS 0.89; verified Exploit-DB entry0.89
13CVE-2012-0754Memory CorruptionAdobe Flash PlayerPatch this weekMetasploit module; EPSS 0.91; verified Exploit-DB entry0.91
14CVE-2015-0311Remote Code ExecutionAdobe Flash PlayerPatch this weekMetasploit module; EPSS 0.86; verified Exploit-DB entry0.86
15CVE-2015-0313Use-After-FreeAdobe Flash PlayerPatch this weekMetasploit module; EPSS 0.95; verified Exploit-DB entry0.95
16CVE-2015-3113Heap-Based Buffer OverflowAdobe Flash PlayerPatch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry0.99
17CVE-2015-5122Use-After-FreeAdobe Flash PlayerPatch this weekMetasploit module; EPSS 0.94; verified Exploit-DB entry0.94
18CVE-2009-0927Reader and Adobe Acrobat Stack-Based Buffer OverflowAdobe Reader and AcrobatPatch this weekMetasploit module; EPSS 0.97; verified Exploit-DB entry0.97
19CVE-2010-2861Directory TraversalAdobe ColdFusionPatch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry0.99
20CVE-2009-3960Information DisclosureAdobe BlazeDSPatch this weekRansomware use; Metasploit module; EPSS 0.90; verified Exploit-DB entry0.90
21CVE-2008-2992Reader and Acrobat Input ValidationAdobe Acrobat and ReaderPatch this weekRansomware use; Metasploit module; EPSS 0.98; verified Exploit-DB entry0.98
22CVE-2010-0188Arbitrary Code ExecutionAdobe Reader and AcrobatPatch this weekRansomware use; Metasploit module; EPSS 0.88; verified Exploit-DB entry0.88
23CVE-2011-0611Remote Code ExecutionAdobe Flash PlayerPatch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry0.99
24CVE-2012-1535Arbitrary Code ExecutionAdobe Flash PlayerPatch this weekMetasploit module; EPSS 0.70; verified Exploit-DB entry0.70
25CVE-2013-0632Authentication BypassAdobe ColdFusionPatch this weekMetasploit module; EPSS 0.94; verified Exploit-DB entry0.94

The next 57, from number 26

Products

Added each year

2040602021: 5520212022: 545420222023: 6620232024: 8820242025: 3320252026: 662026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20215
202254
20236
20248
20253
20266

Used in ransomware

Changes CISA made to these entries

  1. CVE-2016-4117 Adobe Flash PlayerRansomware use: Unknown to Known.
  2. CVE-2014-0546 Adobe Reader and AcrobatRenamed from Acrobat and Reader to Reader and Acrobat. Edited: description and name.
  3. CVE-2011-2462 Adobe Reader and AcrobatRenamed from Acrobat and Reader to Reader and Acrobat. Edited: description and name.
  4. CVE-2025-54253 Adobe Experience Manager (AEM) FormsDeadline moved from 6 November 2025 to 5 November 2025. Listing date changed from 16 October 2025 to 15 October 2025.
  5. CVE-2015-7645 Adobe Flash PlayerRansomware use: Unknown to Known.
  6. CVE-2008-2992 Adobe Acrobat and ReaderRansomware use: Unknown to Known.

Every change we recorded