Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Adobe — Vulnerabilities & Security Advisories 4577

Browse all 4577 CVE security advisories affecting Adobe. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Adobe Systems Incorporated primarily develops multimedia and creativity software, most notably the PDF format and the Creative Cloud suite. With a vast attack surface encompassing 4,289 recorded CVEs, the company has historically faced significant security challenges. Common vulnerability classes include remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws, often stemming from complex legacy codebases and third-party integrations. Notable incidents include critical RCE vulnerabilities in Acrobat Reader and Flash Player, which were frequently exploited by state-sponsored actors and criminal syndicates. The discontinuation of Flash Player marked a pivotal shift, yet the persistence of high-severity bugs in PDF parsing and document processing engines continues to pose risks. Adobe’s extensive market share makes it a high-value target, necessitating rigorous patch management and secure coding practices to mitigate the ongoing threat landscape associated with its widely deployed enterprise and consumer applications.

CVE IDTitleCVSSSeverityPublished
CVE-2026-48389 DNG SDK | Stack-based Buffer Overflow (CWE-121) — DNG SDKCWE-121 7.8 High2026-07-20
CVE-2026-48373 Acrobat Reader | Heap-based Buffer Overflow (CWE-122) — Acrobat ReaderCWE-122 7.8 High2026-07-17
CVE-2026-48295 CAI Content Credentials | Insufficiently Protected Credentials (CWE-522) — Content Credentials Rust SDKCWE-522 7.5 High2026-07-14
CVE-2026-48290 CAI Content Credentials | Server-Side Request Forgery (SSRF) (CWE-918) — Content Credentials Rust SDKCWE-918 8.2 High2026-07-14
CVE-2026-48296 CAI Content Credentials | Integer Underflow (Wrap or Wraparound) (CWE-191) — Content Credentials Rust SDKCWE-191 6.2 Medium2026-07-14
CVE-2026-48357 CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400) — Content Credentials Rust SDKCWE-400 6.2 Medium2026-07-14
CVE-2026-48287 CAI Content Credentials | Untrusted Search Path (CWE-426) — Content Credentials Rust SDKCWE-426 7.4 High2026-07-14
CVE-2026-48312 CAI Content Credentials | Improper Input Validation (CWE-20) — Content Credentials Rust SDKCWE-20 6.8 Medium2026-07-14
CVE-2026-48302 CAI Content Credentials | Improper Input Validation (CWE-20) — Content Credentials Rust SDKCWE-20 6.2 Medium2026-07-14
CVE-2026-48351 CAI Content Credentials | Improper Input Validation (CWE-20) — Content Credentials Rust SDKCWE-20 7.5 High2026-07-14
CVE-2026-48354 CAI Content Credentials | Integer Overflow or Wraparound (CWE-190) — Content Credentials Rust SDKCWE-190 6.2 Medium2026-07-14
CVE-2026-48298 CAI Content Credentials | Integer Underflow (Wrap or Wraparound) (CWE-191) — Content Credentials Rust SDKCWE-191 6.2 Medium2026-07-14
CVE-2026-48352 CAI Content Credentials | Improper Input Validation (CWE-20) — Content Credentials Rust SDKCWE-20 7.5 High2026-07-14
CVE-2026-48353 CAI Content Credentials | Improper Input Validation (CWE-20) — Content Credentials Rust SDKCWE-20 5.5 Medium2026-07-14
CVE-2026-48335 Illustrator | Out-of-bounds Write (CWE-787) — Illustrator Desktop 2026CWE-787 7.8 High2026-07-14
CVE-2026-48336 Illustrator | Out-of-bounds Write (CWE-787) — Illustrator Desktop 2026CWE-787 7.8 High2026-07-14
CVE-2026-48337 Illustrator | Out-of-bounds Write (CWE-787) — Illustrator Desktop 2026CWE-787 7.8 High2026-07-14
CVE-2026-48275 Illustrator | Untrusted Search Path (CWE-426) — Illustrator Desktop 2026CWE-426 8.6 High2026-07-14
CVE-2026-48334 Illustrator | Improper Input Validation (CWE-20) — Illustrator Desktop 2026CWE-20 9.3 Critical2026-07-14
CVE-2026-48320 ColdFusion | Cross-site Scripting (Reflected XSS) (CWE-79) — ColdFusion 2025CWE-79 8.5 High2026-07-14
CVE-2026-48324 ColdFusion | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) — ColdFusion 2025CWE-89 9.1 Critical2026-07-14
CVE-2026-48332 ColdFusion | Server-Side Request Forgery (SSRF) (CWE-918) — ColdFusion 2025CWE-918 7.7 High2026-07-14
CVE-2026-48318 ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) — ColdFusion 2025CWE-22 9.9 Critical2026-07-14
CVE-2026-48338 ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) — ColdFusion 2025CWE-22 6.8 Medium2026-07-14
CVE-2026-48327 ColdFusion | Incorrect Authorization (CWE-863) — ColdFusion 2025CWE-863 9.0 Critical2026-07-14
CVE-2026-48329 ColdFusion | Insufficient Session Expiration (CWE-613) — ColdFusion 2025CWE-613 2.7 Low2026-07-14
CVE-2026-48321 ColdFusion | Incorrect Authorization (CWE-863) — ColdFusion 2025CWE-863 9.3 Critical2026-07-14
CVE-2026-48319 ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) — ColdFusion 2025CWE-22 9.1 Critical2026-07-14
CVE-2026-48322 ColdFusion | Improper Control of Generation of Code ('Code Injection') (CWE-94) — ColdFusion 2025CWE-94 9.6 Critical2026-07-14
CVE-2026-48284 ColdFusion | Improper Input Validation (CWE-20) — ColdFusion 2025CWE-20 9.6 Critical2026-07-14

This page lists every published CVE security advisory associated with Adobe. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.