Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Adobe — Vulnerabilities & Security Advisories 4862

Browse all 4862 CVE security advisories affecting Adobe. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Adobe Systems Incorporated primarily develops multimedia and creativity software, most notably the PDF format and the Creative Cloud suite. With a vast attack surface encompassing 4,289 recorded CVEs, the company has historically faced significant security challenges. Common vulnerability classes include remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws, often stemming from complex legacy codebases and third-party integrations. Notable incidents include critical RCE vulnerabilities in Acrobat Reader and Flash Player, which were frequently exploited by state-sponsored actors and criminal syndicates. The discontinuation of Flash Player marked a pivotal shift, yet the persistence of high-severity bugs in PDF parsing and document processing engines continues to pose risks. Adobe’s extensive market share makes it a high-value target, necessitating rigorous patch management and secure coding practices to mitigate the ongoing threat landscape associated with its widely deployed enterprise and consumer applications.

CVE ID Title CVSS Severity Published
CVE-2026-48308 Premiere Pro | Improper Input Validation (CWE-20) — Premiere CWE-20 5.9 Medium 2026-07-14
CVE-2026-47971 Media Encoder | Stack-based Buffer Overflow (CWE-121) — Adobe Media Encoder CWE-121 7.8 High 2026-07-14
CVE-2026-48366 Media Encoder | Out-of-bounds Write (CWE-787) — Adobe Media Encoder CWE-787 7.8 High 2026-07-14
CVE-2026-47976 Media Encoder | Out-of-bounds Write (CWE-787) — Adobe Media Encoder CWE-787 7.8 High 2026-07-14
CVE-2026-47979 Media Encoder | Out-of-bounds Read (CWE-125) — Adobe Media Encoder CWE-125 5.5 Medium 2026-07-14
CVE-2026-48370 Media Encoder | Out-of-bounds Write (CWE-787) — Adobe Media Encoder CWE-787 7.8 High 2026-07-14
CVE-2026-48345 Animate | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) — Adobe Animate 2023 CWE-78 8.2 High 2026-07-14
CVE-2026-48346 Animate | Untrusted Search Path (CWE-426) — Adobe Animate 2023 CWE-426 7.9 High 2026-07-14
CVE-2026-48347 Animate | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) — Adobe Animate 2023 CWE-78 7.7 High 2026-07-14
CVE-2026-48349 Animate | Incorrect Authorization (CWE-863) — Adobe Animate 2023 CWE-863 8.1 High 2026-07-14
CVE-2026-48350 Animate | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) — Adobe Animate 2023 CWE-22 8.6 High 2026-07-14
CVE-2026-48348 Animate | Incorrect Authorization (CWE-863) — Adobe Animate 2023 CWE-863 7.7 High 2026-07-14
CVE-2026-47984 Adobe Commerce | Incorrect Authorization (CWE-863) — Adobe Commerce CWE-863 8.2 High 2026-07-14
CVE-2026-47997 Adobe Commerce | Incorrect Authorization (CWE-863) — Adobe Commerce CWE-863 5.9 Medium 2026-07-14
CVE-2026-47988 Adobe Commerce | Incorrect Authorization (CWE-863) — Adobe Commerce CWE-863 8.6 High 2026-07-14
CVE-2026-48358 Adobe Commerce | Improper Encoding or Escaping of Output (CWE-116) — Adobe Commerce CWE-116 9.1 Critical 2026-07-14
CVE-2026-47999 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Commerce CWE-79 4.8 Medium 2026-07-14
CVE-2026-48356 Adobe Commerce | Unrestricted Upload of File with Dangerous Type (CWE-434) — Adobe Commerce CWE-434 9.3 Critical 2026-07-14
CVE-2026-48000 Adobe Commerce | URL Redirection to Untrusted Site ('Open Redirect') (CWE-601) — Adobe Commerce CWE-601 6.1 Medium 2026-07-14
CVE-2026-47998 Adobe Commerce | Incorrect Authorization (CWE-863) — Adobe Commerce CWE-863 5.9 Medium 2026-07-14
CVE-2026-47995 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Commerce CWE-79 8.1 High 2026-07-14
CVE-2026-48001 Adobe Commerce | Information Exposure (CWE-200) — Adobe Commerce CWE-200 3.7 Low 2026-07-14
CVE-2026-47996 Adobe Commerce | Incorrect Authorization (CWE-863) — Adobe Commerce CWE-863 6.8 Medium 2026-07-14
CVE-2026-48371 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Commerce CWE-79 5.4 Medium 2026-07-14
CVE-2026-47994 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Commerce CWE-79 8.7 High 2026-07-14
CVE-2026-47992 Adobe Commerce | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) — Adobe Commerce CWE-89 7.2 High 2026-07-14
CVE-2026-48259 Adobe Experience Manager | Server-Side Request Forgery (SSRF) (CWE-918) — Adobe Experience Manager as a Cloud Service CWE-918 9.6 Critical 2026-07-14
CVE-2026-48310 Adobe Experience Manager | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) — Adobe Experience Manager as a Cloud Service CWE-22 8.6 High 2026-07-14
CVE-2026-48359 Adobe Experience Manager | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611) — Adobe Experience Manager as a Cloud Service CWE-611 9.6 Critical 2026-07-14
CVE-2026-48263 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience Manager as a Cloud Service CWE-79 5.4 Medium 2026-07-14

This page lists every published CVE security advisory associated with Adobe. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.