Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Adobe — Vulnerabilities & Security Advisories 4862

Browse all 4862 CVE security advisories affecting Adobe. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Adobe Systems Incorporated primarily develops multimedia and creativity software, most notably the PDF format and the Creative Cloud suite. With a vast attack surface encompassing 4,289 recorded CVEs, the company has historically faced significant security challenges. Common vulnerability classes include remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws, often stemming from complex legacy codebases and third-party integrations. Notable incidents include critical RCE vulnerabilities in Acrobat Reader and Flash Player, which were frequently exploited by state-sponsored actors and criminal syndicates. The discontinuation of Flash Player marked a pivotal shift, yet the persistence of high-severity bugs in PDF parsing and document processing engines continues to pose risks. Adobe’s extensive market share makes it a high-value target, necessitating rigorous patch management and secure coding practices to mitigate the ongoing threat landscape associated with its widely deployed enterprise and consumer applications.

CVE ID Title CVSS Severity Published
CVE-2026-48260 Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) — Adobe Experience Manager as a Cloud Service CWE-79 5.4 Medium 2026-07-14
CVE-2026-48355 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience Manager as a Cloud Service CWE-79 5.4 Medium 2026-07-14
CVE-2026-48261 Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) — Adobe Experience Manager as a Cloud Service CWE-79 5.4 Medium 2026-07-14
CVE-2026-48262 Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) — Adobe Experience Manager as a Cloud Service CWE-79 5.4 Medium 2026-07-14
CVE-2026-48253 Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) — Adobe Experience Manager as a Cloud Service CWE-79 5.4 Medium 2026-07-14
CVE-2026-48252 Adobe Experience Manager | Missing Authentication for Critical Function (CWE-306) — Adobe Experience Manager as a Cloud Service CWE-306 8.6 High 2026-07-14
CVE-2026-48255 Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) — Adobe Experience Manager as a Cloud Service CWE-79 5.4 Medium 2026-07-14
CVE-2026-48257 Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) — Adobe Experience Manager as a Cloud Service CWE-79 5.4 Medium 2026-07-14
CVE-2026-48254 Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) — Adobe Experience Manager as a Cloud Service CWE-79 5.4 Medium 2026-07-14
CVE-2026-48309 Audition | Out-of-bounds Write (CWE-787) — Audition CWE-787 7.8 High 2026-07-14
CVE-2026-47967 Audition | Out-of-bounds Write (CWE-787) — Audition CWE-787 7.8 High 2026-07-14
CVE-2026-47969 Audition | Out-of-bounds Read (CWE-125) — Audition CWE-125 5.5 Medium 2026-07-14
CVE-2026-48365 Audition | Out-of-bounds Write (CWE-787) — Audition CWE-787 7.8 High 2026-07-14
CVE-2026-47968 Audition | Out-of-bounds Write (CWE-787) — Audition CWE-787 7.8 High 2026-07-14
CVE-2026-48368 Audition | Out-of-bounds Write (CWE-787) — Audition CWE-787 7.8 High 2026-07-14
CVE-2026-48363 ColdFusion | Uncontrolled Search Path Element (CWE-427) — ColdFusion 2025 CWE-427 8.2 High 2026-07-13
CVE-2026-48364 ColdFusion | Uncontrolled Search Path Element (CWE-427) — ColdFusion 2025 CWE-427 8.2 High 2026-07-13
CVE-2026-48267 DNG SDK | NULL Pointer Dereference (CWE-476) — Adobe DNG Software Development Kit (SDK) CWE-476 5.5 Medium 2026-07-06
CVE-2026-48316 ColdFusion | Improper Input Validation (CWE-20) — ColdFusion 2025 CWE-20 10.0 Critical 2026-07-06
CVE-2026-48315 ColdFusion | Improper Input Validation (CWE-20) — ColdFusion 2025 CWE-20 9.3 Critical 2026-06-30
CVE-2026-48281 ColdFusion | Improper Input Validation (CWE-20) — ColdFusion 2025 CWE-20 10.0 Critical 2026-06-30
CVE-2026-48277 ColdFusion | Improper Input Validation (CWE-20) — ColdFusion 2025 CWE-20 10.0 Critical 2026-06-30
CVE-2026-48285 ColdFusion | Server-Side Request Forgery (SSRF) (CWE-918) — ColdFusion 2025 CWE-918 8.6 High 2026-06-30
CVE-2026-48313 ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) — ColdFusion 2025 CWE-22 9.3 Critical 2026-06-30
CVE-2026-48314 ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) — ColdFusion 2025 CWE-22 6.5 Medium 2026-06-30
CVE-2026-48307 ColdFusion | Cross-site Scripting (Reflected XSS) (CWE-79) — ColdFusion 2025 CWE-79 8.8 High 2026-06-30
CVE-2026-48276 ColdFusion | Unrestricted Upload of File with Dangerous Type (CWE-434) — ColdFusion 2025 CWE-434 10.0 Critical 2026-06-30
CVE-2026-48282 ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) — ColdFusion 2025 CWE-22 10.0 Critical 2026-06-30
CVE-2026-48283 ColdFusion | Unrestricted Upload of File with Dangerous Type (CWE-434) — ColdFusion 2025 CWE-434 10.0 Critical 2026-06-30
CVE-2026-48286 Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) — Adobe Campaign Classic CWE-863 10.0 Critical 2026-06-30

This page lists every published CVE security advisory associated with Adobe. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.