Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Adobe — Vulnerabilities & Security Advisories 4862

Browse all 4862 CVE security advisories affecting Adobe. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Adobe Systems Incorporated primarily develops multimedia and creativity software, most notably the PDF format and the Creative Cloud suite. With a vast attack surface encompassing 4,289 recorded CVEs, the company has historically faced significant security challenges. Common vulnerability classes include remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws, often stemming from complex legacy codebases and third-party integrations. Notable incidents include critical RCE vulnerabilities in Acrobat Reader and Flash Player, which were frequently exploited by state-sponsored actors and criminal syndicates. The discontinuation of Flash Player marked a pivotal shift, yet the persistence of high-severity bugs in PDF parsing and document processing engines continues to pose risks. Adobe’s extensive market share makes it a high-value target, necessitating rigorous patch management and secure coding practices to mitigate the ongoing threat landscape associated with its widely deployed enterprise and consumer applications.

CVE ID Title CVSS Severity Published
CVE-2026-76197 Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) — Adobe Campaign Classic CWE-78 10.0 Critical 2026-08-25
CVE-2026-76193 Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918) — Adobe Campaign Classic CWE-918 10.0 Critical 2026-08-25
CVE-2026-48414 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Commerce CWE-79 7.7 High 2026-08-11
CVE-2026-48416 Adobe Commerce | Incorrect Authorization (CWE-863) — Adobe Commerce CWE-863 7.5 High 2026-08-11
CVE-2026-48413 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Commerce CWE-79 8.7 High 2026-08-11
CVE-2026-48415 Adobe Commerce | Incorrect Authorization (CWE-863) — Adobe Commerce CWE-863 7.6 High 2026-08-11
CVE-2026-48412 Adobe Commerce | Incorrect Authorization (CWE-863) — Adobe Commerce CWE-863 2.7 Low 2026-08-11
CVE-2026-48411 Adobe Commerce | Incorrect Authorization (CWE-863) — Adobe Commerce CWE-863 6.5 Medium 2026-08-11
CVE-2026-71362 Adobe Commerce | Incorrect Authorization (CWE-863) — Adobe Commerce CWE-863 9.1 Critical 2026-08-11
CVE-2026-48381 Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) — Adobe Campaign Classic CWE-89 9.0 Critical 2026-08-11
CVE-2026-71398 Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) — Adobe Campaign Classic CWE-863 10.0 Critical 2026-08-11
CVE-2026-27302 Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) — Adobe Campaign Classic CWE-863 10.0 Critical 2026-08-11
CVE-2026-48409 Lightroom Classic | Out-of-bounds Write (CWE-787) — Lightroom Classic CWE-787 7.8 High 2026-08-11
CVE-2026-48408 Lightroom Classic | Out-of-bounds Write (CWE-787) — Lightroom Classic CWE-787 7.8 High 2026-08-11
CVE-2026-48441 Lightroom Classic | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) — Lightroom Classic CWE-22 8.6 High 2026-08-11
CVE-2026-48447 Lightroom Classic | Incorrect Authorization (CWE-863) — Lightroom Classic CWE-863 7.7 High 2026-08-11
CVE-2026-48405 Lightroom Classic | Out-of-bounds Write (CWE-787) — Lightroom Classic CWE-787 7.8 High 2026-08-11
CVE-2026-48406 Lightroom Classic | Out-of-bounds Write (CWE-787) — Lightroom Classic CWE-787 7.8 High 2026-08-11
CVE-2026-48397 Lightroom Classic | Deserialization of Untrusted Data (CWE-502) — Lightroom Classic CWE-502 8.6 High 2026-08-11
CVE-2026-48407 Lightroom Classic | Out-of-bounds Write (CWE-787) — Lightroom Classic CWE-787 7.8 High 2026-08-11
CVE-2026-48404 Lightroom Classic | Out-of-bounds Write (CWE-787) — Lightroom Classic CWE-787 7.8 High 2026-08-11
CVE-2026-48410 Lightroom Classic | Out-of-bounds Write (CWE-787) — Lightroom Classic CWE-787 7.8 High 2026-08-11
CVE-2026-47940 Lightroom Classic | Integer Overflow or Wraparound (CWE-190) — Lightroom Classic CWE-190 7.8 High 2026-08-11
CVE-2026-48443 CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400) — Content Credentials Rust SDK CWE-400 6.2 Medium 2026-08-11
CVE-2026-48434 CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400) — Content Credentials Rust SDK CWE-400 6.2 Medium 2026-08-11
CVE-2026-47922 CAI Content Credentials | Server-Side Request Forgery (SSRF) (CWE-918) — Content Credentials Rust SDK CWE-918 4.7 Medium 2026-08-11
CVE-2026-71390 CAI Content Credentials | Improper Input Validation (CWE-20) — Content Credentials Rust SDK CWE-20 4.0 Medium 2026-08-11
CVE-2026-48445 CAI Content Credentials | Integer Overflow or Wraparound (CWE-190) — Content Credentials Rust SDK CWE-190 6.2 Medium 2026-08-11
CVE-2026-48442 CAI Content Credentials | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) — Content Credentials Rust SDK CWE-22 7.1 High 2026-08-11
CVE-2026-48387 CAI Content Credentials | Integer Overflow or Wraparound (CWE-190) — Content Credentials Rust SDK CWE-190 6.2 Medium 2026-08-11

This page lists every published CVE security advisory associated with Adobe. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.