Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1325 CNY

100%

Adobe — Vulnerabilities & Security Advisories 4469

Browse all 4469 CVE security advisories affecting Adobe. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Adobe Systems Incorporated primarily develops multimedia and creativity software, most notably the PDF format and the Creative Cloud suite. With a vast attack surface encompassing 4,289 recorded CVEs, the company has historically faced significant security challenges. Common vulnerability classes include remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws, often stemming from complex legacy codebases and third-party integrations. Notable incidents include critical RCE vulnerabilities in Acrobat Reader and Flash Player, which were frequently exploited by state-sponsored actors and criminal syndicates. The discontinuation of Flash Player marked a pivotal shift, yet the persistence of high-severity bugs in PDF parsing and document processing engines continues to pose risks. Adobe’s extensive market share makes it a high-value target, necessitating rigorous patch management and secure coding practices to mitigate the ongoing threat landscape associated with its widely deployed enterprise and consumer applications.

CVE IDTitleCVSSSeverityPublished
CVE-2026-48294 Adobe acrobat 跨站脚本漏洞 — Adobe Acrobat PDF Extension (Chrome)CWE-79 7.4 High2026-06-16
CVE-2026-47963 DNG SDK | Out-of-bounds Read (CWE-125) — DNG SDKCWE-125 5.5 Medium2026-06-16
CVE-2026-47934 DNG SDK | Out-of-bounds Read (CWE-125) — DNG SDKCWE-125 5.5 Medium2026-06-16
CVE-2026-47927 DNG SDK | Out-of-bounds Read (CWE-125) — DNG SDKCWE-125 5.5 Medium2026-06-16
CVE-2026-47964 DNG SDK | Heap-based Buffer Overflow (CWE-122) — DNG SDKCWE-122 7.8 High2026-06-16
CVE-2026-47965 Acrobat Reader | Out-of-bounds Write (CWE-787) — Acrobat ReaderCWE-787 7.8 High2026-06-12
CVE-2026-34711 CAI Content Credentials | Integer Overflow or Wraparound (CWE-190) — CAI Content CredentialsCWE-190 7.5 High2026-06-09
CVE-2026-34712 CAI Content Credentials | Improper Input Validation (CWE-20) — CAI Content CredentialsCWE-20 7.5 High2026-06-09
CVE-2026-47904 CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400) — CAI Content CredentialsCWE-400 6.2 Medium2026-06-09
CVE-2026-47903 CAI Content Credentials | Improper Input Validation (CWE-20) — CAI Content CredentialsCWE-20 6.2 Medium2026-06-09
CVE-2026-47902 CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400) — CAI Content CredentialsCWE-400 6.2 Medium2026-06-09
CVE-2026-47905 CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400) — CAI Content CredentialsCWE-400 6.2 Medium2026-06-09
CVE-2026-34657 CAI Content Credentials | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) — CAI Content CredentialsCWE-22 5.5 Medium2026-06-09
CVE-2026-34713 CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400) — CAI Content CredentialsCWE-400 7.5 High2026-06-09
CVE-2026-47938 Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918) — Adobe Campaign Classic (ACC)CWE-918 10.0 Critical2026-06-09
CVE-2026-48303 Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) — Adobe Campaign Classic (ACC)CWE-863 10.0 Critical2026-06-09
CVE-2026-48291 Format Plugins | Heap-based Buffer Overflow (CWE-122) — Format PluginsCWE-122 7.8 High2026-06-09
CVE-2026-48292 Format Plugins | Heap-based Buffer Overflow (CWE-122) — Format PluginsCWE-122 7.8 High2026-06-09
CVE-2026-47929 ColdFusion | Incorrect Authorization (CWE-863) — ColdFusionCWE-863 8.4 High2026-06-09
CVE-2026-47932 ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) — ColdFusionCWE-22 8.8 High2026-06-09
CVE-2026-47960 ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611) — ColdFusionCWE-611 7.4 High2026-06-09
CVE-2026-47931 ColdFusion | Improper Input Validation (CWE-20) — ColdFusionCWE-20 8.4 High2026-06-09
CVE-2026-47928 ColdFusion | Improper Input Validation (CWE-20) — ColdFusionCWE-20 9.6 Critical2026-06-09
CVE-2026-47930 ColdFusion | Improper Input Validation (CWE-20) — ColdFusionCWE-20 8.1 High2026-06-09
CVE-2026-47933 ColdFusion | Cross-site Scripting (Stored XSS) (CWE-79) — ColdFusionCWE-79 4.8 Medium2026-06-09
CVE-2026-47937 Acrobat Reader | Uncontrolled Search Path Element (CWE-427) — Acrobat ReaderCWE-427 7.4 High2026-06-09
CVE-2026-47916 Acrobat Reader | Use After Free (CWE-416) — Acrobat ReaderCWE-416 7.8 High2026-06-09
CVE-2026-47918 Acrobat Reader | Use After Free (CWE-416) — Acrobat ReaderCWE-416 7.8 High2026-06-09
CVE-2026-47915 Acrobat Reader | Use After Free (CWE-416) — Acrobat ReaderCWE-416 7.8 High2026-06-09
CVE-2026-47923 Acrobat Reader | Out-of-bounds Read (CWE-125) — Acrobat ReaderCWE-125 5.5 Medium2026-06-09

This page lists every published CVE security advisory associated with Adobe. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.