Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Adobe — Vulnerabilities & Security Advisories 4862

Browse all 4862 CVE security advisories affecting Adobe. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Adobe Systems Incorporated primarily develops multimedia and creativity software, most notably the PDF format and the Creative Cloud suite. With a vast attack surface encompassing 4,289 recorded CVEs, the company has historically faced significant security challenges. Common vulnerability classes include remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws, often stemming from complex legacy codebases and third-party integrations. Notable incidents include critical RCE vulnerabilities in Acrobat Reader and Flash Player, which were frequently exploited by state-sponsored actors and criminal syndicates. The discontinuation of Flash Player marked a pivotal shift, yet the persistence of high-severity bugs in PDF parsing and document processing engines continues to pose risks. Adobe’s extensive market share makes it a high-value target, necessitating rigorous patch management and secure coding practices to mitigate the ongoing threat landscape associated with its widely deployed enterprise and consumer applications.

CVE ID Title CVSS Severity Published
CVE-2026-34647 Adobe Commerce | Server-Side Request Forgery (SSRF) (CWE-918) — Adobe Commerce CWE-918 7.4 High 2026-05-12
CVE-2026-34685 Adobe Commerce | Improper Input Validation (CWE-20) — Adobe Commerce CWE-20 3.4 Low 2026-05-12
CVE-2026-34653 Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) — Adobe Commerce CWE-22 8.7 High 2026-05-12
CVE-2026-34652 Adobe Commerce | Dependency on Vulnerable Third-Party Component (CWE-1395) — Adobe Commerce CWE-1395 7.5 High 2026-05-12
CVE-2026-34645 Adobe Commerce | Incorrect Authorization (CWE-863) — Adobe Commerce CWE-863 7.5 High 2026-05-12
CVE-2026-34648 Adobe Commerce | Uncontrolled Resource Consumption (CWE-400) — Adobe Commerce CWE-400 7.5 High 2026-05-12
CVE-2026-34649 Adobe Commerce | Uncontrolled Resource Consumption (CWE-400) — Adobe Commerce CWE-400 7.5 High 2026-05-12
CVE-2026-34655 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Commerce CWE-79 4.8 Medium 2026-05-12
CVE-2026-34654 Adobe Commerce | Dependency on Vulnerable Third-Party Component (CWE-1395) — Adobe Commerce CWE-1395 5.3 Medium 2026-05-12
CVE-2026-34651 Adobe Commerce | Uncontrolled Resource Consumption (CWE-400) — Adobe Commerce CWE-400 7.5 High 2026-05-12
CVE-2026-34646 Adobe Commerce | Incorrect Authorization (CWE-863) — Adobe Commerce CWE-863 7.5 High 2026-05-12
CVE-2026-34690 After Effects | Stack-based Buffer Overflow (CWE-121) — After Effects CWE-121 7.8 High 2026-05-12
CVE-2026-34659 Adobe Connect | Deserialization of Untrusted Data (CWE-502) — Adobe Connect CWE-502 9.6 Critical 2026-05-12
CVE-2026-34660 Adobe Connect | Incorrect Authorization (CWE-863) — Adobe Connect CWE-863 9.3 Critical 2026-05-12
CVE-2026-34682 Substance3D - Designer | Out-of-bounds Write (CWE-787) — Adobe Substance 3D Designer CWE-787 7.8 High 2026-05-12
CVE-2026-34681 Substance3D - Designer | Out-of-bounds Write (CWE-787) — Adobe Substance 3D Designer CWE-787 7.8 High 2026-05-12
CVE-2026-34684 Substance3D - Designer | Out-of-bounds Write (CWE-787) — Adobe Substance 3D Designer CWE-787 7.8 High 2026-05-12
CVE-2026-34683 Substance3D - Designer | Out-of-bounds Write (CWE-787) — Adobe Substance 3D Designer CWE-787 7.8 High 2026-05-12
CVE-2026-34664 Substance3D - Designer | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) — Adobe Substance 3D Designer CWE-22 6.3 Medium 2026-05-12
CVE-2026-34662 Illustrator | NULL Pointer Dereference (CWE-476) — Illustrator Desktop 2026 CWE-476 5.5 Medium 2026-05-12
CVE-2026-34687 Illustrator | Heap-based Buffer Overflow (CWE-122) — Illustrator Desktop 2026 CWE-122 7.8 High 2026-05-12
CVE-2026-34663 Illustrator | Out-of-bounds Read (CWE-125) — Illustrator Desktop 2026 CWE-125 5.5 Medium 2026-05-12
CVE-2026-34661 Illustrator | Out-of-bounds Write (CWE-787) — Illustrator Desktop 2026 CWE-787 7.8 High 2026-05-12
CVE-2026-34676 Substance3D - Painter | Out-of-bounds Write (CWE-787) — Substance3D - Painter CWE-787 7.8 High 2026-05-12
CVE-2026-34675 Substance3D - Painter | Out-of-bounds Write (CWE-787) — Substance3D - Painter CWE-787 7.8 High 2026-05-12
CVE-2026-34644 After Effects | Integer Overflow or Wraparound (CWE-190) — After Effects CWE-190 7.8 High 2026-05-12
CVE-2026-34643 After Effects | Out-of-bounds Write (CWE-787) — After Effects CWE-787 7.8 High 2026-05-12
CVE-2026-34642 After Effects | Heap-based Buffer Overflow (CWE-122) — After Effects CWE-122 7.8 High 2026-05-12
CVE-2026-34640 Media Encoder | Integer Overflow or Wraparound (CWE-190) — Adobe Media Encoder CWE-190 7.8 High 2026-05-12
CVE-2026-34639 Media Encoder | Out-of-bounds Write (CWE-787) — Adobe Media Encoder CWE-787 7.8 High 2026-05-12

This page lists every published CVE security advisory associated with Adobe. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.