Adobe Systems Incorporated commands one of the largest vulnerability footprints in the software landscape, driven by a moderately broad but deeply embedded product portfolio spanning document handling, content management, and multimedia authoring. The vendor's exposure concentrates in flagship products such as Acrobat DC, Acrobat Reader DC, and Experience Manager, which reach millions of users and enterprise deployments across personal, business, and supply-chain contexts. Vulnerabilities affecting Adobe recur through memory-safety and input-handling weakness classes including out-of-bounds reads and writes, use-after-free conditions, buffer-boundary violations, and cross-site scripting, reflecting the native-code complexity and web-integration depth inherent to these widely distributed applications. The memory-safety patterns are characteristic of large, feature-rich codebases that handle untrusted document formats and user input at scale, making them a durable focus for remediation efforts across defender organizations. Current exploitation activity, severity distribution, and CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Adobe Systems Incorporated over time
Of all the CVEs published by Adobe Systems Incorporated as a CNA, 97.7% affect products that Adobe Systems Incorporated develops as a vendor.
Of all the CVEs published that affect products developed by Adobe Systems Incorporated, 95.4% are self-published by Adobe Systems Incorporated as a CNA.
Signals from CVEs in this vendor scope (7426 CVEs).
7,426 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-15961CRITICAL Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file upload vulnerability. Successful exploitation | Sep 25, 2018 | 9.8 | 99 | YES | YES |
CVE-2010-2861CRITICAL Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parame | Aug 11, 2010 | 9.8 | 99 | YES | YES |
CVE-2025-54236CRITICAL Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attac | Sep 9, 2025 | 9.1 | 98 | YES | YES |
CVE-2024-34102CRITICAL Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could re | Jun 13, 2024 | 9.8 | 98 | YES | YES |
CVE-2024-20767HIGH ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could leverage | Mar 18, 2024 | 7.4 | 98 | YES | YES |
CVE-2023-29300CRITICAL Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could | Jul 12, 2023 | 9.8 | 98 | YES | YES |
CVE-2023-26360CRITICAL Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Access Control vulnerability that could result in arbitrary code | Mar 23, 2023 | 9.8 | 98 | YES | YES |
CVE-2022-24086CRITICAL Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of th | Feb 16, 2022 | 9.8 | 98 | YES | YES |
CVE-2016-4117CRITICAL Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016. | May 11, 2016 | 9.8 | 98 | YES | YES |
CVE-2015-5122CRITICAL Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 1 | Jul 14, 2015 | 9.8 | 98 | YES | YES |
Signals from CVEs in this vendor scope (7426 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Adobe Systems Incorporated.
Media articles that mention a CVE ID that affects a product developed by Adobe Systems Incorporated — matched by CVE ID, not by vendor name.