Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Adobe — Vulnerabilities & Security Advisories 4862

Browse all 4862 CVE security advisories affecting Adobe. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Adobe Systems Incorporated primarily develops multimedia and creativity software, most notably the PDF format and the Creative Cloud suite. With a vast attack surface encompassing 4,289 recorded CVEs, the company has historically faced significant security challenges. Common vulnerability classes include remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws, often stemming from complex legacy codebases and third-party integrations. Notable incidents include critical RCE vulnerabilities in Acrobat Reader and Flash Player, which were frequently exploited by state-sponsored actors and criminal syndicates. The discontinuation of Flash Player marked a pivotal shift, yet the persistence of high-severity bugs in PDF parsing and document processing engines continues to pose risks. Adobe’s extensive market share makes it a high-value target, necessitating rigorous patch management and secure coding practices to mitigate the ongoing threat landscape associated with its widely deployed enterprise and consumer applications.

CVE ID Title CVSS Severity Published
CVE-2026-48436 CAI Content Credentials | Improper Input Validation (CWE-20) — Content Credentials Rust SDK CWE-20 6.5 Medium 2026-08-11
CVE-2026-48446 CAI Content Credentials | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) — Content Credentials Rust SDK CWE-22 5.5 Medium 2026-08-11
CVE-2026-48438 CAI Content Credentials | NULL Pointer Dereference (CWE-476) — Content Credentials Rust SDK CWE-476 7.5 High 2026-08-11
CVE-2026-48444 CAI Content Credentials | Integer Overflow or Wraparound (CWE-190) — Content Credentials Rust SDK CWE-190 6.2 Medium 2026-08-11
CVE-2026-48439 CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400) — Content Credentials Rust SDK CWE-400 7.5 High 2026-08-11
CVE-2026-48435 CAI Content Credentials | Integer Underflow (Wrap or Wraparound) (CWE-191) — Content Credentials Rust SDK CWE-191 6.2 Medium 2026-08-11
CVE-2026-48437 CAI Content Credentials | Improper Certificate Validation (CWE-295) — Content Credentials Rust SDK CWE-295 5.5 Medium 2026-08-11
CVE-2026-71389 CAI Content Credentials | Integer Underflow (Wrap or Wraparound) (CWE-191) — Content Credentials Rust SDK CWE-191 6.2 Medium 2026-08-11
CVE-2026-71387 ColdFusion | Incorrect Authorization (CWE-863) — ColdFusion 2025 CWE-863 8.8 High 2026-08-11
CVE-2026-48385 ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) — ColdFusion 2025 CWE-78 7.7 High 2026-08-11
CVE-2026-21279 ColdFusion | Improper Input Validation (CWE-20) — ColdFusion 2025 CWE-20 8.2 High 2026-08-11
CVE-2026-71383 ColdFusion | Incorrect Authorization (CWE-863) — ColdFusion 2025 CWE-863 7.3 High 2026-08-11
CVE-2026-48384 ColdFusion | Improper Input Validation (CWE-20) — ColdFusion 2025 CWE-20 4.9 Medium 2026-08-11
CVE-2026-48375 ColdFusion | Incorrect Authorization (CWE-863) — ColdFusion 2025 CWE-863 6.5 Medium 2026-08-11
CVE-2026-21269 ColdFusion | Cross-site Scripting (Stored XSS) (CWE-79) — ColdFusion 2025 CWE-79 4.6 Medium 2026-08-11
CVE-2026-48376 ColdFusion | Improper Encoding or Escaping of Output (CWE-116) — ColdFusion 2025 CWE-116 5.4 Medium 2026-08-11
CVE-2026-48440 ColdFusion | Heap-based Buffer Overflow (CWE-122) — ColdFusion 2025 CWE-122 8.1 High 2026-08-11
CVE-2026-34635 ColdFusion | Use of Hard-coded Cryptographic Key (CWE-321) — ColdFusion 2025 CWE-321 8.4 High 2026-08-11
CVE-2026-48386 ColdFusion | Use of a Broken or Risky Cryptographic Algorithm (CWE-327) — ColdFusion 2025 CWE-327 7.5 High 2026-08-11
CVE-2026-48362 ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) — ColdFusion 2025 CWE-78 10.0 Critical 2026-08-11
CVE-2026-71386 ColdFusion | Cross-site Scripting (XSS) (CWE-79) — ColdFusion 2025 CWE-79 8.8 High 2026-08-11
CVE-2026-71384 ColdFusion | Incorrect Authorization (CWE-863) — ColdFusion 2025 CWE-863 9.6 Critical 2026-08-11
CVE-2026-25652 ColdFusion | Incorrect Authorization (CWE-863) — ColdFusion 2025 CWE-863 7.8 High 2026-08-11
CVE-2026-21273 ColdFusion | Improper Input Validation (CWE-20) — ColdFusion 2025 CWE-20 8.7 High 2026-08-11
CVE-2026-71381 Adobe Genuine Software Integrity Service | CWE-863 Incorrect Authorization — Adobe Genuine Software Integrity Service CWE-863 4.0 Medium 2026-08-07
CVE-2026-48323 Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) — Adobe Campaign Classic CWE-1336 10.0 Critical 2026-08-03
CVE-2026-48333 Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) — Adobe Campaign Classic CWE-863 9.8 Critical 2026-08-03
CVE-2026-48331 Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918) — Adobe Campaign Classic CWE-918 10.0 Critical 2026-08-03
CVE-2026-48317 Adobe Campaign Classic (ACC) | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') (CWE-95) — Adobe Campaign Classic CWE-95 9.6 Critical 2026-08-03
CVE-2026-48330 Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) — Adobe Campaign Classic CWE-89 10.0 Critical 2026-08-03

This page lists every published CVE security advisory associated with Adobe. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.