Adobe Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Adobe products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
97
In CISA KEV
80
Beyond CISA KEV
17
Sensor Observed
2
Virtual Patch Available
2
Adobe KEVs Added by Year
97 Adobe KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2026-48282
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) |
ColdFusion | Confirmed | In CISA | 02 Jul 2026 |
|
CVE-2025-49533
Adobe Experience Manager (MS) | Deserialization of Untrusted Data (CWE-502) |
Adobe Experience Manager (MS) | High | Not in CISA | 21 Oct 2025 |
|
CVE-2021-21087
ColdFusion Improper neutralization of web input during page generation could lead to arbitrary JavaScript execution in the browser |
ColdFusion | High | Not in CISA | 26 Jul 2025 |
|
CVE-2026-34621
Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321) |
Acrobat Reader | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2020-9715
Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an... |
Adobe Acrobat and Reader | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-54236
Adobe Commerce | Improper Input Validation (CWE-20) |
Adobe Commerce | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-54253
Adobe Experience Manager | Incorrect Authorization (CWE-863) |
Adobe Experience Manager | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-54254
Adobe Experience Manager | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611) |
Adobe Experience Manager | High | Not in CISA | 05 Aug 2025 |
|
CVE-2014-0515
Buffer overflow in Adobe Flash Player before 11.7.700.279 and 11.8.x through 13.0.x before 13.0.0.206 on Windows and OS X, and before 11.2.202.356... |
Flash Player | High | Not in CISA | 29 Apr 2014 |
|
CVE-2013-5331
Adobe Flash Player before 11.7.700.257 and 11.8.x and 11.9.x before 11.9.900.170 on Windows and Mac OS X and before 11.2.202.332 on Linux, Adobe... |
Flash Player | High | Not in CISA | 11 Dec 2013 |
|
CVE-2013-0634
Adobe Flash Player before 10.3.183.51 and 11.x before 11.5.502.149 on Windows and Mac OS X, before 10.3.183.51 and 11.x before 11.2.202.262 on... |
Flash Player | High | Not in CISA | 08 Feb 2013 |
|
CVE-2013-0633
Buffer overflow in Adobe Flash Player before 10.3.183.51 and 11.x before 11.5.502.149 on Windows and Mac OS X, before 10.3.183.51 and 11.x before... |
Flash Player | High | Not in CISA | 08 Feb 2013 |
|
CVE-2012-0779
Adobe Flash Player before 10.3.183.19 and 11.x before 11.2.202.235 on Windows, Mac OS X, and Linux; before 11.1.111.9 on Android 2.x and 3.x; and... |
Flash Player | High | Not in CISA | 04 May 2012 |
|
CVE-2011-4369
Unspecified vulnerability in the PRC component in Adobe Reader and Acrobat 9.x before 9.4.7 on Windows, Adobe Reader and Acrobat 9.x through 9.4.6... |
Reader and Acrobat | High | Not in CISA | 16 Dec 2011 |
|
CVE-2011-2444
Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.10 on Windows, Mac OS X, Linux, and Solaris, and before 10.3.186.7... |
Flash Player | High | Not in CISA | 22 Sep 2011 |
|
CVE-2011-2110
Adobe Flash Player before 10.3.181.26 on Windows, Mac OS X, Linux, and Solaris, and 10.3.185.23 and earlier on Android, allows remote attackers to... |
Flash Player | High | Not in CISA | 16 Jun 2011 |
|
CVE-2011-0627
Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.21 on Android allows remote attackers to execute... |
Flash Player | High | Not in CISA | 13 May 2011 |
|
CVE-2010-3654
Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris and 10.1.95.1 on Android, and authplay.dll... |
Flash Player | High | Not in CISA | 29 Oct 2010 |
|
CVE-2010-3653
The Director module (dirapi.dll) in Adobe Shockwave Player before 11.5.9.615 allows remote attackers to execute arbitrary code or cause a denial of... |
Shockwave Player | High | Not in CISA | 26 Oct 2010 |
|
CVE-2010-2884
Adobe Flash Player 10.1.82.76 and earlier on Windows, Mac OS X, Linux, and Solaris and 10.1.92.10 on Android; authplay.dll in Adobe Reader and... |
Flash Player, Reader, Acrobat | High | Not in CISA | 15 Sep 2010 |
|
CVE-2009-3459
Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute... |
Reader and Acrobat | Confirmed | In CISA | 13 Oct 2009 |
|
CVE-2009-0658
Buffer overflow in Adobe Reader 9.0 and earlier, and Acrobat 9.0 and earlier, allows remote attackers to execute arbitrary code via a crafted PDF... |
Reader | High | Not in CISA | 20 Feb 2009 |
|
CVE-2008-3873
The System.setClipboard method in ActionScript in Adobe Flash Player 9.0.124.0 and earlier allows remote attackers to populate the clipboard with a... |
Flash Player | High | Not in CISA | 29 Aug 2008 |
|
CVE-2018-4878
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the... |
Adobe Flash Player before 28.0.0.161 | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2018-15961
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file upload... |
ColdFusion | Confirmed | In CISA | 03 Nov 2021 |
Common Vulnerability Classes (CWE)
- CWE-416 — Use After Free 15
- CWE-787 — Out-of-bounds Write 11
- CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer 9
- CWE-502 — Deserialization of Untrusted Data 6
- CWE-190 — Integer Overflow or Wraparound 4
- CWE-284 — Improper Access Control 4
- CWE-20 — Improper Input Validation 4
- CWE-121 — Stack-based Buffer Overflow 3
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology