Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Adobe — Vulnerabilities & Security Advisories 4862

Browse all 4862 CVE security advisories affecting Adobe. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Adobe Systems Incorporated primarily develops multimedia and creativity software, most notably the PDF format and the Creative Cloud suite. With a vast attack surface encompassing 4,289 recorded CVEs, the company has historically faced significant security challenges. Common vulnerability classes include remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws, often stemming from complex legacy codebases and third-party integrations. Notable incidents include critical RCE vulnerabilities in Acrobat Reader and Flash Player, which were frequently exploited by state-sponsored actors and criminal syndicates. The discontinuation of Flash Player marked a pivotal shift, yet the persistence of high-severity bugs in PDF parsing and document processing engines continues to pose risks. Adobe’s extensive market share makes it a high-value target, necessitating rigorous patch management and secure coding practices to mitigate the ongoing threat landscape associated with its widely deployed enterprise and consumer applications.

CVE ID Title CVSS Severity Published
CVE-2026-48335 Illustrator | Out-of-bounds Write (CWE-787) — Illustrator Desktop 2026 CWE-787 7.8 High 2026-07-14
CVE-2026-48337 Illustrator | Out-of-bounds Write (CWE-787) — Illustrator Desktop 2026 CWE-787 7.8 High 2026-07-14
CVE-2026-48334 Illustrator | Improper Input Validation (CWE-20) — Illustrator Desktop 2026 CWE-20 9.3 Critical 2026-07-14
CVE-2026-48275 Illustrator | Untrusted Search Path (CWE-426) — Illustrator Desktop 2026 CWE-426 8.6 High 2026-07-14
CVE-2026-48320 ColdFusion | Cross-site Scripting (Reflected XSS) (CWE-79) — ColdFusion 2025 CWE-79 8.5 High 2026-07-14
CVE-2026-48324 ColdFusion | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) — ColdFusion 2025 CWE-89 9.1 Critical 2026-07-14
CVE-2026-48332 ColdFusion | Server-Side Request Forgery (SSRF) (CWE-918) — ColdFusion 2025 CWE-918 7.7 High 2026-07-14
CVE-2026-48318 ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) — ColdFusion 2025 CWE-22 9.9 Critical 2026-07-14
CVE-2026-48338 ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) — ColdFusion 2025 CWE-22 6.8 Medium 2026-07-14
CVE-2026-48327 ColdFusion | Incorrect Authorization (CWE-863) — ColdFusion 2025 CWE-863 9.0 Critical 2026-07-14
CVE-2026-48329 ColdFusion | Insufficient Session Expiration (CWE-613) — ColdFusion 2025 CWE-613 2.7 Low 2026-07-14
CVE-2026-48321 ColdFusion | Incorrect Authorization (CWE-863) — ColdFusion 2025 CWE-863 9.3 Critical 2026-07-14
CVE-2026-48319 ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) — ColdFusion 2025 CWE-22 9.1 Critical 2026-07-14
CVE-2026-48322 ColdFusion | Improper Control of Generation of Code ('Code Injection') (CWE-94) — ColdFusion 2025 CWE-94 9.9 Critical 2026-07-14
CVE-2026-48284 ColdFusion | Improper Input Validation (CWE-20) — ColdFusion 2025 CWE-20 9.6 Critical 2026-07-14
CVE-2026-48328 ColdFusion | Improper Input Validation (CWE-20) — ColdFusion 2025 CWE-20 7.7 High 2026-07-14
CVE-2026-48325 ColdFusion | Missing Authentication for Critical Function (CWE-306) — ColdFusion 2025 CWE-306 9.3 Critical 2026-07-14
CVE-2026-48340 Bridge | Untrusted Pointer Dereference (CWE-822) — Adobe Bridge CWE-822 7.8 High 2026-07-14
CVE-2026-48343 Bridge | Out-of-bounds Write (CWE-787) — Adobe Bridge CWE-787 7.8 High 2026-07-14
CVE-2026-48339 Bridge | Heap-based Buffer Overflow (CWE-122) — Adobe Bridge CWE-122 7.8 High 2026-07-14
CVE-2026-48311 Bridge | Out-of-bounds Write (CWE-787) — Adobe Bridge CWE-787 7.8 High 2026-07-14
CVE-2026-48342 Bridge | Integer Overflow or Wraparound (CWE-190) — Adobe Bridge CWE-190 7.8 High 2026-07-14
CVE-2026-48341 Bridge | Out-of-bounds Write (CWE-787) — Adobe Bridge CWE-787 7.8 High 2026-07-14
CVE-2026-48272 Creative Cloud Desktop | Uncontrolled Search Path Element (CWE-427) — Creative Cloud Desktop CWE-427 7.8 High 2026-07-14
CVE-2026-48344 GoCart | Time-of-check Time-of-use (TOCTOU) Race Condition (CWE-367) — Creative Cloud Desktop CWE-367 7.8 High 2026-07-14
CVE-2026-48274 After Effects | Out-of-bounds Write (CWE-787) — After Effects CWE-787 7.8 High 2026-07-14
CVE-2026-48367 After Effects | Out-of-bounds Write (CWE-787) — After Effects CWE-787 7.8 High 2026-07-14
CVE-2026-48369 Premiere Pro | Out-of-bounds Write (CWE-787) — Premiere CWE-787 7.8 High 2026-07-14
CVE-2026-48269 Premiere Pro | Heap-based Buffer Overflow (CWE-122) — Premiere CWE-122 7.8 High 2026-07-14
CVE-2026-48270 Premiere Pro | Out-of-bounds Write (CWE-787) — Premiere CWE-787 7.8 High 2026-07-14

This page lists every published CVE security advisory associated with Adobe. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.