Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Adobe — Vulnerabilities & Security Advisories 4862

Browse all 4862 CVE security advisories affecting Adobe. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Adobe Systems Incorporated primarily develops multimedia and creativity software, most notably the PDF format and the Creative Cloud suite. With a vast attack surface encompassing 4,289 recorded CVEs, the company has historically faced significant security challenges. Common vulnerability classes include remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws, often stemming from complex legacy codebases and third-party integrations. Notable incidents include critical RCE vulnerabilities in Acrobat Reader and Flash Player, which were frequently exploited by state-sponsored actors and criminal syndicates. The discontinuation of Flash Player marked a pivotal shift, yet the persistence of high-severity bugs in PDF parsing and document processing engines continues to pose risks. Adobe’s extensive market share makes it a high-value target, necessitating rigorous patch management and secure coding practices to mitigate the ongoing threat landscape associated with its widely deployed enterprise and consumer applications.

CVE ID Title CVSS Severity Published
CVE-2026-82006 Photoshop Desktop | Heap-based Buffer Overflow (CWE-122) — Photoshop 2026 CWE-122 7.8 High 2026-09-08
CVE-2026-82007 Photoshop Desktop | Integer Overflow or Wraparound (CWE-190) — Photoshop 2026 CWE-190 7.8 High 2026-09-08
CVE-2026-75863 Photoshop Desktop | Integer Overflow or Wraparound (CWE-190) — Photoshop 2026 CWE-190 7.8 High 2026-09-08
CVE-2026-75991 Illustrator | Improper Input Validation (CWE-20) — Illustrator Desktop 2026 CWE-20 8.6 High 2026-09-08
CVE-2026-75990 Illustrator | Incorrect Authorization (CWE-863) — Illustrator Desktop 2026 CWE-863 8.6 High 2026-09-08
CVE-2026-75992 Illustrator | Out-of-bounds Write (CWE-787) — Illustrator Desktop 2026 CWE-787 7.8 High 2026-09-08
CVE-2026-82004 Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) — Adobe Campaign Classic CWE-78 10.0 Critical 2026-09-08
CVE-2026-76200 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Commerce CWE-79 9.3 Critical 2026-09-08
CVE-2026-77109 Adobe Commerce | Incorrect Authorization (CWE-863) — Adobe Commerce CWE-863 8.6 High 2026-09-08
CVE-2026-76201 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Commerce CWE-79 9.3 Critical 2026-09-08
CVE-2026-77110 Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) — Adobe Commerce CWE-22 7.6 High 2026-09-08
CVE-2026-77108 Adobe Commerce | Incorrect Authorization (CWE-863) — Adobe Commerce CWE-863 7.5 High 2026-09-08
CVE-2026-76202 Adobe Commerce | Incorrect Authorization (CWE-863) — Adobe Commerce CWE-863 8.2 High 2026-09-08
CVE-2026-77774 Adobe Commerce | Incorrect Authorization (CWE-863) — Adobe Commerce CWE-863 8.6 High 2026-09-08
CVE-2026-77111 Adobe Commerce | Incorrect Authorization (CWE-863) — Adobe Commerce CWE-863 8.7 High 2026-09-08
CVE-2026-76196 Photoshop Mobile | Session Fixation (CWE-384) — Photoshop Android CWE-384 7.4 High 2026-09-08
CVE-2026-79904 Photoshop Mobile | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) — Photoshop Android CWE-22 5.0 Medium 2026-09-08
CVE-2026-76191 Animate | Improper Control of Generation of Code ('Code Injection') (CWE-94) — Adobe Animate 2023 CWE-94 8.2 High 2026-09-08
CVE-2026-75650 Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) — Adobe Commerce CWE-1336 10.0 Critical 2026-09-07
CVE-2026-83959 Substance3D - Sampler | Heap-based Buffer Overflow (CWE-122) — Adobe Substance 3D Sampler CWE-122 7.8 High 2026-09-03
CVE-2026-83961 ColdFusion | Improper Authentication (CWE-287) — ColdFusion 2025 CWE-287 7.1 High 2026-09-03
CVE-2026-34616 DNG SDK | Out-of-bounds Read (CWE-125) — Adobe DNG Software Development Kit (SDK) CWE-125 5.5 Medium 2026-08-27
CVE-2026-34620 DNG SDK | Out-of-bounds Write (CWE-787) — Adobe DNG Software Development Kit (SDK) CWE-787 5.5 Medium 2026-08-27
CVE-2026-34674 Substance3D - Sampler | Heap-based Buffer Overflow (CWE-122) — Adobe Substance 3D Sampler CWE-122 7.8 High 2026-08-27
CVE-2026-75750 Substance3D - Painter | Heap-based Buffer Overflow (CWE-122) — Substance3D - Painter CWE-122 7.8 High 2026-08-25
CVE-2026-75767 Substance3D - Painter | Heap-based Buffer Overflow (CWE-122) — Substance3D - Painter CWE-122 7.8 High 2026-08-25
CVE-2026-75768 Substance3D - Painter | Untrusted Search Path (CWE-426) — Substance3D - Painter CWE-426 7.8 High 2026-08-25
CVE-2026-75766 Substance3D - Painter | Heap-based Buffer Overflow (CWE-122) — Substance3D - Painter CWE-122 7.8 High 2026-08-25
CVE-2026-75769 Substance3D - Painter | Heap-based Buffer Overflow (CWE-122) — Substance3D - Painter CWE-122 7.8 High 2026-08-25
CVE-2026-75752 Substance3D - Painter | Out-of-bounds Read (CWE-125) — Substance3D - Painter CWE-125 5.5 Medium 2026-08-25

This page lists every published CVE security advisory associated with Adobe. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.