Vendor
Adobe, page 2
As of , 82 Adobe vulnerabilities are on CISA's list of exploited vulnerabilities, 11 of them used in ransomware campaigns; 6 were added in 2026. Patch first: CVE-2026-71362.
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 26 | CVE-2013-3346Memory Corruption | Adobe Reader and Acrobat | Patch this weekMetasploit module; EPSS 0.79; verified Exploit-DB entry | 0.79 | ||
| 27 | CVE-2015-3043Memory Corruption | Adobe Flash Player | Patch this weekMetasploit module; EPSS 0.74; verified Exploit-DB entry | 0.74 | ||
| 28 | CVE-2015-5119Use-After-Free | Adobe Flash Player | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 29 | CVE-2016-4117Arbitrary Code Execution | Adobe Flash Player | Patch this weekRansomware use; Metasploit module; EPSS 0.94; verified Exploit-DB entry | 0.94 | ||
| 30 | CVE-2025-54236Improper Input Validation | Adobe Commerce and Magento | Patch this weekMetasploit module; EPSS 0.95 | 0.95 | ||
| 31 | CVE-2024-20767Improper Access Control | Adobe ColdFusion | Patch this weekMetasploit module; EPSS 0.99 | 0.99 | ||
| 32 | CVE-2024-34102Improper Restriction of XML External Entity Reference (XXE) | Adobe Commerce and Magento Open Source | Patch this weekMetasploit module; EPSS 0.99 | 0.99 | ||
| 33 | CVE-2023-26360Deserialization of Untrusted Data | Adobe ColdFusion | Patch this weekMetasploit module; EPSS 0.97 | 0.97 | ||
| 34 | CVE-2018-15961Unrestricted File Upload | Adobe ColdFusion | Patch this weekMetasploit module; EPSS 0.99 | 0.99 | ||
| 35 | CVE-2013-0625Authentication Bypass | Adobe ColdFusion | Patch this weekEPSS 0.94; verified Exploit-DB entry | 0.94 | ||
| 36 | CVE-2013-0629Directory Traversal | Adobe ColdFusion | Patch this weekEPSS 0.66; verified Exploit-DB entry | 0.66 | ||
| 37 | CVE-2013-0640Memory Corruption | Adobe Reader and Acrobat | Patch this weekEPSS 0.87; verified Exploit-DB entry | 0.87 | ||
| 38 | CVE-2015-7645Arbitrary Code Execution | Adobe Flash Player | Patch this weekRansomware use; EPSS 0.65; verified Exploit-DB entry | 0.65 | ||
| 39 | CVE-2016-0984Use-After-Free | Adobe Flash Player and AIR | Patch this weekEPSS 0.55; verified Exploit-DB entry | 0.55 | ||
| 40 | CVE-2025-54253Experience Manager Forms Code Execution | Adobe Experience Manager (AEM) Forms | Patch this weekEPSS 0.88 | 0.88 | ||
| 41 | CVE-2017-3066Deserialization | Adobe ColdFusion | Patch this weekEPSS 0.91 | 0.91 | ||
| 42 | CVE-2023-29300Deserialization of Untrusted Data | Adobe ColdFusion | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| 43 | CVE-2023-38203Deserialization of Untrusted Data | Adobe ColdFusion | Patch this weekRansomware use; EPSS 0.97 | 0.97 | ||
| 44 | CVE-2023-21608Use-After-Free | Adobe Acrobat and Reader | Patch this weekEPSS 0.61 | 0.61 | ||
| 45 | CVE-2023-29298Improper Access Control | Adobe ColdFusion | Patch this weekEPSS 0.99 | 0.99 | ||
| 46 | CVE-2023-38205Improper Access Control | Adobe ColdFusion | Patch this weekEPSS 0.99 | 0.99 | ||
| 47 | CVE-2015-8651Integer Overflow | Adobe Flash Player | Patch this weekEPSS 0.68 | 0.68 | ||
| 48 | CVE-2013-2729Arbitrary Integer Overflow | Adobe Reader and Acrobat | Patch this weekEPSS 0.67 | 0.67 | ||
| 49 | CVE-2013-0631Information Disclosure | Adobe ColdFusion | Patch this weekEPSS 0.66 | 0.66 | ||
| 50 | CVE-2018-15982Use-After-Free | Adobe Flash Player | Patch this weekRansomware use; EPSS 0.90 | 0.90 | ||
| 51 | CVE-2022-24086Improper Input Validation | Adobe Commerce and Magento Open Source | Patch this weekEPSS 0.99 | 0.99 | ||
| 52 | CVE-2018-4878Use-After-Free | Adobe Flash Player | Patch this weekRansomware use; EPSS 0.90 | 0.90 | ||
| 53 | CVE-2018-4939Deserialization of Untrusted Data | Adobe ColdFusion | Patch this weekEPSS 0.62 | 0.62 | ||
| 54 | CVE-2021-21017Heap-based Buffer Overflow | Adobe Acrobat and Reader | Patch this weekEPSS 0.86 | 0.86 | ||
| 55 | CVE-2021-28550Use-After-Free | Adobe Acrobat and Reader | Patch this weekEPSS 0.52 | 0.52 | ||
| 56 | CVE-2016-1019Arbitrary Code Execution | Adobe Flash Player | Patch this weekRansomware use | 0.22 | ||
| 57 | CVE-2020-9715Use-After-Free | Adobe Acrobat | Patch soon | 0.49 | ||
| 58 | CVE-2008-0655Unspecified | Adobe Acrobat and Reader | Patch soon | 0.38 | ||
| 59 | CVE-2018-4990Double Free | Adobe Acrobat and Reader | Patch soon | 0.36 | ||
| 60 | CVE-2013-0641Buffer Overflow | Adobe Reader | Patch soon | 0.32 | ||
| 61 | CVE-2014-0496Use-After-Free | Adobe Reader and Acrobat | Patch soon | 0.40 | ||
| 62 | CVE-2014-0502Double Free Vulnerablity | Adobe Flash Player | Patch soon | 0.25 | ||
| 63 | CVE-2009-1862Unspecified | Adobe Acrobat and Reader, Flash Player | Patch soon | 0.21 | ||
| 64 | CVE-2012-5054Integer Overflow | Adobe Flash Player | Patch soon | 0.21 | ||
| 65 | CVE-2014-0546Sandbox Bypass | Adobe Reader and Acrobat | Patch soon | 0.22 | ||
| 66 | CVE-2014-8439Dereferenced Pointer | Adobe Flash Player | Patch soon | 0.20 | ||
| 67 | CVE-2016-1010Integer Overflow | Adobe Flash Player and AIR | Patch soon | 0.19 | ||
| 68 | CVE-2018-5002Stack-based Buffer Overflow | Adobe Flash Player | Patch soon | 0.25 | ||
| 69 | CVE-2014-9163Stack-Based Buffer Overflow | Adobe Flash Player | Patch soon | 0.21 | ||
| 70 | CVE-2015-5123Use-After-Free | Adobe Flash Player | Patch soon | 0.19 | ||
| 71 | CVE-2016-4171Remote Code Execution | Adobe Flash Player | Patch soon | 0.20 | ||
| 72 | CVE-2016-7892Use-After-Free | Adobe Flash Player | Patch soon | 0.19 | ||
| 73 | CVE-2016-7855Use-After-Free | Adobe Flash Player | Patch soon | 0.25 | ||
| 74 | CVE-2023-26359Deserialization of Untrusted Data | Adobe ColdFusion | Patch soon | 0.17 | ||
| 75 | CVE-2015-0310ASLR Bypass | Adobe Flash Player | Patch soon | 0.15 | ||
| 76 | CVE-2013-0643Incorrect Default Permissions | Adobe Flash Player | Patch soon | 0.11 | ||
| 77 | CVE-2013-0648Code Execution | Adobe Flash Player | Patch soon | 0.11 | ||
| 78 | CVE-2017-11292Type Confusion | Adobe Flash Player | Patch soon | 0.12 | ||
| 79 | CVE-2012-2034Memory Corruption | Adobe Flash Player | Patch soon | 0.08 | ||
| 80 | CVE-2023-26369Out-of-Bounds Write | Adobe Acrobat and Reader | Patch soon | 0.07 | ||
| 81 | CVE-2012-0767Cross-Site Scripting (XSS) | Adobe Flash Player | Patch soon | 0.06 | ||
| 82 | CVE-2026-34621Prototype Pollution | Adobe Acrobat and Reader | Patch soon | 0.02 |