Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Adobe — Vulnerabilities & Security Advisories 4862

Browse all 4862 CVE security advisories affecting Adobe. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Adobe Systems Incorporated primarily develops multimedia and creativity software, most notably the PDF format and the Creative Cloud suite. With a vast attack surface encompassing 4,289 recorded CVEs, the company has historically faced significant security challenges. Common vulnerability classes include remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws, often stemming from complex legacy codebases and third-party integrations. Notable incidents include critical RCE vulnerabilities in Acrobat Reader and Flash Player, which were frequently exploited by state-sponsored actors and criminal syndicates. The discontinuation of Flash Player marked a pivotal shift, yet the persistence of high-severity bugs in PDF parsing and document processing engines continues to pose risks. Adobe’s extensive market share makes it a high-value target, necessitating rigorous patch management and secure coding practices to mitigate the ongoing threat landscape associated with its widely deployed enterprise and consumer applications.

CVE ID Title CVSS Severity Published
CVE-2026-21317 Audition | Out-of-bounds Read (CWE-125) — Audition CWE-125 5.5 Medium 2026-02-10
CVE-2026-21314 Audition | Out-of-bounds Read (CWE-125) — Audition CWE-125 5.5 Medium 2026-02-10
CVE-2026-21301 Substance3D - Modeler | NULL Pointer Dereference (CWE-476) — Substance3D - Modeler CWE-476 5.5 Medium 2026-01-13
CVE-2026-21299 Substance3D - Modeler | Out-of-bounds Write (CWE-787) — Substance3D - Modeler CWE-787 7.8 High 2026-01-13
CVE-2026-21298 Substance3D - Modeler | Out-of-bounds Write (CWE-787) — Substance3D - Modeler CWE-787 7.8 High 2026-01-13
CVE-2026-21300 Substance3D - Modeler | NULL Pointer Dereference (CWE-476) — Substance3D - Modeler CWE-476 5.5 Medium 2026-01-13
CVE-2026-21303 Substance3D - Modeler | Out-of-bounds Read (CWE-125) — Substance3D - Modeler CWE-125 5.5 Medium 2026-01-13
CVE-2026-21302 Substance3D - Modeler | Out-of-bounds Read (CWE-125) — Substance3D - Modeler CWE-125 5.5 Medium 2026-01-13
CVE-2026-21308 Substance3D - Designer | Out-of-bounds Read (CWE-125) — Adobe Substance 3D Designer CWE-125 5.5 Medium 2026-01-13
CVE-2026-21307 Substance3D - Designer | Out-of-bounds Write (CWE-787) — Adobe Substance 3D Designer CWE-787 7.8 High 2026-01-13
CVE-2026-21306 Substance3D - Sampler | Out-of-bounds Write (CWE-787) — Adobe Substance 3D Sampler CWE-787 7.8 High 2026-01-13
CVE-2026-21287 Substance3D - Stager | Use After Free (CWE-416) — Substance3D - Stager CWE-416 7.8 High 2026-01-13
CVE-2026-21305 Substance3D - Painter | Out-of-bounds Write (CWE-787) — Substance3D - Painter CWE-787 7.8 High 2026-01-13
CVE-2026-21283 Bridge | Heap-based Buffer Overflow (CWE-122) — Bridge CWE-122 7.8 High 2026-01-13
CVE-2026-21281 InCopy | Heap-based Buffer Overflow (CWE-122) — InCopy CWE-122 7.8 High 2026-01-13
CVE-2026-21280 Illustrator | Untrusted Search Path (CWE-426) — Illustrator Desktop 2026 CWE-426 8.6 High 2026-01-13
CVE-2026-21288 Illustrator | NULL Pointer Dereference (CWE-476) — Illustrator Desktop 2026 CWE-476 5.5 Medium 2026-01-13
CVE-2026-21277 InDesign Desktop | Heap-based Buffer Overflow (CWE-122) — InDesign Desktop CWE-122 7.8 High 2026-01-13
CVE-2026-21304 InDesign Desktop | Heap-based Buffer Overflow (CWE-122) — InDesign Desktop CWE-122 7.8 High 2026-01-13
CVE-2026-21275 InDesign Desktop | Access of Uninitialized Pointer (CWE-824) — InDesign Desktop CWE-824 7.8 High 2026-01-13
CVE-2026-21278 InDesign Desktop | Out-of-bounds Read (CWE-125) — InDesign Desktop CWE-125 5.5 Medium 2026-01-13
CVE-2026-21276 InDesign Desktop | Access of Uninitialized Pointer (CWE-824) — InDesign Desktop CWE-824 7.8 High 2026-01-13
CVE-2026-21267 Dreamweaver Desktop | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) — Adobe Dreamweaver Desktop CWE-78 8.6 High 2026-01-13
CVE-2026-21271 Dreamweaver Desktop | Improper Input Validation (CWE-20) — Adobe Dreamweaver Desktop CWE-20 8.6 High 2026-01-13
CVE-2026-21274 Dreamweaver Desktop | Incorrect Authorization (CWE-863) — Adobe Dreamweaver Desktop CWE-863 7.8 High 2026-01-13
CVE-2026-21272 Dreamweaver Desktop | Improper Input Validation (CWE-20) — Adobe Dreamweaver Desktop CWE-20 8.6 High 2026-01-13
CVE-2026-21268 Dreamweaver Desktop | Improper Input Validation (CWE-20) — Adobe Dreamweaver Desktop CWE-20 8.6 High 2026-01-13
CVE-2025-64622 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience Manager CWE-79 5.4 Medium 2025-12-10
CVE-2025-64582 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience Manager CWE-79 5.4 Medium 2025-12-10
CVE-2025-64547 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience Manager CWE-79 5.4 Medium 2025-12-10

This page lists every published CVE security advisory associated with Adobe. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.