Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Adobe — Vulnerabilities & Security Advisories 4862

Browse all 4862 CVE security advisories affecting Adobe. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Adobe Systems Incorporated primarily develops multimedia and creativity software, most notably the PDF format and the Creative Cloud suite. With a vast attack surface encompassing 4,289 recorded CVEs, the company has historically faced significant security challenges. Common vulnerability classes include remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws, often stemming from complex legacy codebases and third-party integrations. Notable incidents include critical RCE vulnerabilities in Acrobat Reader and Flash Player, which were frequently exploited by state-sponsored actors and criminal syndicates. The discontinuation of Flash Player marked a pivotal shift, yet the persistence of high-severity bugs in PDF parsing and document processing engines continues to pose risks. Adobe’s extensive market share makes it a high-value target, necessitating rigorous patch management and secure coding practices to mitigate the ongoing threat landscape associated with its widely deployed enterprise and consumer applications.

CVE ID Title CVSS Severity Published
CVE-2026-27289 Photoshop Desktop | Out-of-bounds Read (CWE-125) — Photoshop Desktop CWE-125 7.8 High 2026-04-14
CVE-2026-34618 Illustrator | Out-of-bounds Write (CWE-787) — Illustrator Desktop 2026 CWE-787 7.8 High 2026-04-14
CVE-2026-34625 Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) — Adobe Experience Manager CWE-79 5.4 Medium 2026-04-14
CVE-2026-34623 Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) — Adobe Experience Manager CWE-79 5.4 Medium 2026-04-14
CVE-2026-34624 Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) — Adobe Experience Manager CWE-79 5.4 Medium 2026-04-14
CVE-2026-27288 Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) — Adobe Experience Manager CWE-79 5.4 Medium 2026-04-14
CVE-2026-27303 Adobe Connect | Deserialization of Untrusted Data (CWE-502) — Adobe Connect CWE-502 9.6 Critical 2026-04-14
CVE-2026-34617 Adobe Connect | Cross-site Scripting (XSS) (CWE-79) — Adobe Connect CWE-79 8.7 High 2026-04-14
CVE-2026-21331 Adobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79) — Adobe Connect CWE-79 6.1 Medium 2026-04-14
CVE-2026-27246 Adobe Connect | Cross-site Scripting (DOM-based XSS) (CWE-79) — Adobe Connect CWE-79 9.3 Critical 2026-04-14
CVE-2026-34614 Adobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79) — Adobe Connect CWE-79 6.1 Medium 2026-04-14
CVE-2026-27245 Adobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79) — Adobe Connect CWE-79 9.3 Critical 2026-04-14
CVE-2026-34615 Adobe Connect | Deserialization of Untrusted Data (CWE-502) — Adobe Connect CWE-502 9.3 Critical 2026-04-14
CVE-2026-27243 Adobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79) — Adobe Connect CWE-79 9.3 Critical 2026-04-14
CVE-2026-34628 InDesign Desktop | Heap-based Buffer Overflow (CWE-122) — InDesign Desktop CWE-122 7.8 High 2026-04-14
CVE-2026-34629 InDesign Desktop | Heap-based Buffer Overflow (CWE-122) — InDesign Desktop CWE-122 7.8 High 2026-04-14
CVE-2026-34627 InDesign Desktop | Heap-based Buffer Overflow (CWE-122) — InDesign Desktop CWE-122 7.8 High 2026-04-14
CVE-2026-27258 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience Manager as a Cloud Service CWE-79 5.4 Medium 2026-04-14
CVE-2026-27284 InDesign Desktop | Out-of-bounds Read (CWE-125) — InDesign Desktop CWE-125 7.8 High 2026-04-14
CVE-2026-27285 InDesign Desktop | Heap-based Buffer Overflow (CWE-122) — InDesign Desktop CWE-122 5.5 Medium 2026-04-14
CVE-2026-27286 InDesign Desktop | Heap-based Buffer Overflow (CWE-122) — InDesign Desktop CWE-122 5.5 Medium 2026-04-14
CVE-2026-27283 InDesign Desktop | Use After Free (CWE-416) — InDesign Desktop CWE-416 7.8 High 2026-04-14
CVE-2026-27238 InDesign Desktop | Heap-based Buffer Overflow (CWE-122) — InDesign Desktop CWE-122 7.8 High 2026-04-14
CVE-2026-27291 InDesign Desktop | Out-of-bounds Write (CWE-787) — InDesign Desktop CWE-787 7.8 High 2026-04-14
CVE-2026-34622 Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321) — Acrobat DC CWE-1321 8.6 High 2026-04-14
CVE-2026-34626 Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321) — Acrobat DC CWE-1321 6.3 Medium 2026-04-14
CVE-2026-34621 Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321) — Acrobat DC CWE-1321 8.6 High 2026-04-11
CVE-2026-27309 Substance3D - Stager | Use After Free (CWE-416) — Substance3D - Stager CWE-416 7.8 High 2026-03-27
CVE-2026-21291 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Commerce CWE-79 4.8 Medium 2026-03-11
CVE-2026-21293 Adobe Commerce | Server-Side Request Forgery (SSRF) (CWE-918) — Adobe Commerce CWE-918 5.5 Medium 2026-03-11

This page lists every published CVE security advisory associated with Adobe. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.