Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Adobe — Vulnerabilities & Security Advisories 4862

Browse all 4862 CVE security advisories affecting Adobe. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Adobe Systems Incorporated primarily develops multimedia and creativity software, most notably the PDF format and the Creative Cloud suite. With a vast attack surface encompassing 4,289 recorded CVEs, the company has historically faced significant security challenges. Common vulnerability classes include remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws, often stemming from complex legacy codebases and third-party integrations. Notable incidents include critical RCE vulnerabilities in Acrobat Reader and Flash Player, which were frequently exploited by state-sponsored actors and criminal syndicates. The discontinuation of Flash Player marked a pivotal shift, yet the persistence of high-severity bugs in PDF parsing and document processing engines continues to pose risks. Adobe’s extensive market share makes it a high-value target, necessitating rigorous patch management and secure coding practices to mitigate the ongoing threat landscape associated with its widely deployed enterprise and consumer applications.

CVE ID Title CVSS Severity Published
CVE-2026-47946 Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) — Adobe Experience Manager as a Cloud Service CWE-79 5.4 Medium 2026-06-09
CVE-2026-47973 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience Manager as a Cloud Service CWE-79 5.4 Medium 2026-06-09
CVE-2026-47987 Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) — Adobe Experience Manager as a Cloud Service CWE-79 5.4 Medium 2026-06-09
CVE-2026-47958 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience Manager as a Cloud Service CWE-79 5.4 Medium 2026-06-09
CVE-2026-48265 Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) — Adobe Experience Manager as a Cloud Service CWE-79 5.4 Medium 2026-06-09
CVE-2026-48288 Adobe Experience Manager | Improper Input Validation (CWE-20) — Adobe Experience Manager as a Cloud Service CWE-20 3.5 Low 2026-06-09
CVE-2026-48250 Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) — Adobe Experience Manager as a Cloud Service CWE-79 5.4 Medium 2026-06-09
CVE-2026-48271 Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) — Adobe Experience Manager as a Cloud Service CWE-79 5.4 Medium 2026-06-09
CVE-2026-47978 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience Manager as a Cloud Service CWE-79 5.4 Medium 2026-06-09
CVE-2026-47949 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience Manager as a Cloud Service CWE-79 5.4 Medium 2026-06-09
CVE-2026-48299 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience Manager as a Cloud Service CWE-79 5.4 Medium 2026-06-09
CVE-2026-48266 Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) — Adobe Experience Manager as a Cloud Service CWE-79 5.4 Medium 2026-06-09
CVE-2026-34672 CAI Content Credentials | Integer Underflow (Wrap or Wraparound) (CWE-191) — Content Credentials JS SDK CWE-191 6.2 Medium 2026-05-12
CVE-2026-34671 CAI Content Credentials | Integer Overflow or Wraparound (CWE-190) — Content Credentials JS SDK CWE-190 6.2 Medium 2026-05-12
CVE-2026-34669 CAI Content Credentials | Improper Input Validation (CWE-20) — Content Credentials JS SDK CWE-20 6.2 Medium 2026-05-12
CVE-2026-34678 CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400) — Content Credentials JS SDK CWE-400 6.2 Medium 2026-05-12
CVE-2026-34688 CAI Content Credentials | Improper Input Validation (CWE-20) — Content Credentials JS SDK CWE-20 6.2 Medium 2026-05-12
CVE-2026-34680 CAI Content Credentials | Integer Overflow or Wraparound (CWE-190) — Content Credentials JS SDK CWE-190 6.2 Medium 2026-05-12
CVE-2026-34668 CAI Content Credentials | Improper Input Validation (CWE-20) — Content Credentials JS SDK CWE-20 6.2 Medium 2026-05-12
CVE-2026-34673 CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400) — Content Credentials JS SDK CWE-400 6.2 Medium 2026-05-12
CVE-2026-34667 CAI Content Credentials | Integer Underflow (Wrap or Wraparound) (CWE-191) — Content Credentials JS SDK CWE-191 6.2 Medium 2026-05-12
CVE-2026-34665 CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400) — Content Credentials JS SDK CWE-400 7.5 High 2026-05-12
CVE-2026-34670 CAI Content Credentials | Improper Input Validation (CWE-20) — Content Credentials JS SDK CWE-20 6.2 Medium 2026-05-12
CVE-2026-34679 CAI Content Credentials | Improper Input Validation (CWE-20) — Content Credentials JS SDK CWE-20 6.2 Medium 2026-05-12
CVE-2026-34666 CAI Content Credentials | Improper Input Validation (CWE-20) — Content Credentials JS SDK CWE-20 6.2 Medium 2026-05-12
CVE-2026-34677 CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400) — Content Credentials JS SDK CWE-400 6.2 Medium 2026-05-12
CVE-2026-34656 Adobe Commerce | Improper Authorization (CWE-285) — Adobe Commerce CWE-285 4.3 Medium 2026-05-12
CVE-2026-34658 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Commerce CWE-79 4.8 Medium 2026-05-12
CVE-2026-34650 Adobe Commerce | Uncontrolled Resource Consumption (CWE-400) — Adobe Commerce CWE-400 7.5 High 2026-05-12
CVE-2026-34686 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Commerce CWE-79 8.7 High 2026-05-12

This page lists every published CVE security advisory associated with Adobe. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.