Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Adobe — Vulnerabilities & Security Advisories 4862

Browse all 4862 CVE security advisories affecting Adobe. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Adobe Systems Incorporated primarily develops multimedia and creativity software, most notably the PDF format and the Creative Cloud suite. With a vast attack surface encompassing 4,289 recorded CVEs, the company has historically faced significant security challenges. Common vulnerability classes include remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws, often stemming from complex legacy codebases and third-party integrations. Notable incidents include critical RCE vulnerabilities in Acrobat Reader and Flash Player, which were frequently exploited by state-sponsored actors and criminal syndicates. The discontinuation of Flash Player marked a pivotal shift, yet the persistence of high-severity bugs in PDF parsing and document processing engines continues to pose risks. Adobe’s extensive market share makes it a high-value target, necessitating rigorous patch management and secure coding practices to mitigate the ongoing threat landscape associated with its widely deployed enterprise and consumer applications.

CVE ID Title CVSS Severity Published
CVE-2026-21282 Adobe Commerce | Improper Input Validation (CWE-20) — Adobe Commerce CWE-20 5.3 Medium 2026-03-11
CVE-2026-21286 Adobe Commerce | Incorrect Authorization (CWE-863) — Adobe Commerce CWE-863 5.3 Medium 2026-03-11
CVE-2026-21294 Adobe Commerce | Server-Side Request Forgery (SSRF) (CWE-918) — Adobe Commerce CWE-918 5.5 Medium 2026-03-11
CVE-2026-21297 Adobe Commerce | Incorrect Authorization (CWE-863) — Adobe Commerce CWE-863 4.3 Medium 2026-03-11
CVE-2026-21284 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Commerce CWE-79 8.1 High 2026-03-11
CVE-2026-21359 Adobe Commerce | Incorrect Authorization (CWE-863) — Adobe Commerce CWE-863 4.7 Medium 2026-03-11
CVE-2026-21309 Adobe Commerce | Incorrect Authorization (CWE-863) — Adobe Commerce CWE-863 7.5 High 2026-03-11
CVE-2026-21292 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Commerce CWE-79 5.4 Medium 2026-03-11
CVE-2026-21310 Adobe Commerce | Improper Input Validation (CWE-20) — Adobe Commerce CWE-20 5.3 Medium 2026-03-11
CVE-2026-21285 Adobe Commerce | Incorrect Authorization (CWE-863) — Adobe Commerce CWE-863 4.3 Medium 2026-03-11
CVE-2026-21290 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Commerce CWE-79 8.7 High 2026-03-11
CVE-2026-21361 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Commerce CWE-79 8.1 High 2026-03-11
CVE-2026-21289 Adobe Commerce | Incorrect Authorization (CWE-863) — Adobe Commerce CWE-863 7.5 High 2026-03-11
CVE-2026-21360 Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) — Adobe Commerce CWE-22 6.8 Medium 2026-03-11
CVE-2026-21296 Adobe Commerce | Incorrect Authorization (CWE-863) — Adobe Commerce CWE-863 4.3 Medium 2026-03-11
CVE-2026-21311 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Commerce CWE-79 8.0 High 2026-03-11
CVE-2026-21295 Adobe Commerce | URL Redirection to Untrusted Site ('Open Redirect') (CWE-601) — Adobe Commerce CWE-601 3.1 Low 2026-03-11
CVE-2026-27241 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience Manager as a Cloud Service CWE-79 5.4 Medium 2026-03-11
CVE-2026-27244 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience Manager as a Cloud Service CWE-79 5.4 Medium 2026-03-11
CVE-2026-27255 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience Manager as a Cloud Service CWE-79 5.4 Medium 2026-03-11
CVE-2026-27251 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience Manager as a Cloud Service CWE-79 5.4 Medium 2026-03-11
CVE-2026-27223 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience Manager as a Cloud Service CWE-79 5.4 Medium 2026-03-11
CVE-2026-27262 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience Manager as a Cloud Service CWE-79 5.4 Medium 2026-03-11
CVE-2026-27232 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience Manager as a Cloud Service CWE-79 5.4 Medium 2026-03-11
CVE-2026-27249 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience Manager as a Cloud Service CWE-79 5.4 Medium 2026-03-11
CVE-2026-27247 Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) — Adobe Experience Manager as a Cloud Service CWE-79 5.4 Medium 2026-03-11
CVE-2026-27242 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience Manager as a Cloud Service CWE-79 5.4 Medium 2026-03-11
CVE-2026-27252 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience Manager as a Cloud Service CWE-79 5.4 Medium 2026-03-11
CVE-2026-27235 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience Manager as a Cloud Service CWE-79 5.4 Medium 2026-03-11
CVE-2026-27225 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience Manager as a Cloud Service CWE-79 5.4 Medium 2026-03-11

This page lists every published CVE security advisory associated with Adobe. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.