Skip to content
English

Products › Brands

Brand

Adobe: actively exploited vulnerabilities

82 vulnerabilities in Adobe products (Flash Player, Acrobat / Reader, ColdFusion…) are in CISA’s catalog of exploited vulnerabilities, 3 of them added in the last 90 days. Last added: September 24, 2026.

The brand’s general security advisories page, not the advisory for a specific vulnerability (address checked September 28, 2026).

By category

Add just one Adobe category to your radar, or open its page.

A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.

Affected products

  • Flash Player 36 vulnerabilities · Browsers
  • Acrobat / Reader 23 vulnerabilities · Office and PDF
  • ColdFusion 16 vulnerabilities · Web servers
  • Commerce (Magento) 5 vulnerabilities · CMS and websites
  • BlazeDS 1 vulnerability · Frameworks
  • Experience Manager (AEM) 1 vulnerability · CMS and websites

Name used by CISA: Adobe. Product families: indicative classification by this site.

Pace of additions

Number of Adobe vulnerabilities added to CISA’s KEV catalog, per 30-day period (the last one, still in progress, ends on September 28, 2026). Source: CISA KEV catalog.
Catalog additions per 30-day period
PeriodVulnerabilities added
Sep 4, 2025 to Oct 3, 20250
Oct 4, 2025 to Nov 2, 20252
Nov 3, 2025 to Dec 2, 20250
Dec 3, 2025 to Jan 1, 20260
Jan 2, 2026 to Jan 31, 20260
Feb 1, 2026 to Mar 2, 20260
Mar 3, 2026 to Apr 1, 20260
Apr 2, 2026 to May 1, 20262
May 2, 2026 to May 31, 20261
Jun 1, 2026 to Jun 30, 20260
Jul 1, 2026 to Jul 30, 20261
Jul 31, 2026 to Aug 29, 20260
Aug 30, 2026 to Sep 28, 2026 (in progress)2

Patch first

In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this Adobe list.

  1. Rank 1Adobe Commerce (Magento)

    CVE-2026-71362

    Recently addedHunt for compromise (CISA)

    Adobe Commerce and Magento Incorrect Authorization Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 24, 2026
    CISA deadline
    3 days
    CVSS severity
    9.1 (critical)
  2. Rank 2Adobe Commerce (Magento)

    CVE-2026-75650

    Recently addedHunt for compromise (CISA)

    Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 8, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)
  3. Rank 3Adobe ColdFusion

    CVE-2026-48282

    Hunt for compromise (CISA)

    Adobe ColdFusion Path Traversal Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 7, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)
  4. Rank 4Adobe Experience Manager (AEM)

    CVE-2025-54253

    Adobe Experience Manager Forms Code Execution Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 15, 2025
    CISA deadline
    21 days
    CVSS severity
    10.0 (critical)
  5. Rank 5Adobe Commerce (Magento)

    CVE-2025-54236

    Adobe Commerce and Magento Improper Input Validation Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 24, 2025
    CISA deadline
    21 days
    CVSS severity
    9.1 (critical)
  6. Rank 6Adobe Acrobat / Reader

    CVE-2009-3459

    CVE from 2009, added in 2026

    Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    May 20, 2026
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  7. Rank 7Adobe Acrobat / Reader

    CVE-2026-34621

    Adobe Acrobat and Reader Prototype Pollution Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 13, 2026
    CISA deadline
    14 days
    CVSS severity
    8.6 (high)
  8. Rank 8Adobe Acrobat / Reader

    CVE-2020-9715

    CVE from 2020, added in 2026

    Adobe Acrobat Use-After-Free Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 13, 2026
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  9. Rank 9Adobe ColdFusion

    CVE-2017-3066

    CVE from 2017, added in 2025

    Adobe ColdFusion Deserialization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 24, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  10. Rank 10Adobe Commerce (Magento)

    CVE-2024-34102

    Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 17, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
Show 37 more vulnerabilities
  1. Rank 11Adobe ColdFusion

    CVE-2023-29300

    Ransomware

    Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 8, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  2. Rank 12Adobe ColdFusion

    CVE-2023-38203

    Ransomware

    Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 8, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  3. Rank 13Adobe ColdFusion

    CVE-2023-26359

    Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 21, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  4. Rank 14Adobe ColdFusion

    CVE-2023-26360

    Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 15, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  5. Rank 15Adobe Acrobat / Reader

    CVE-2011-2462

    CVE from 2011, added in 2022

    Adobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  6. Rank 16Adobe Acrobat / Reader

    CVE-2014-0546

    CVE from 2014, added in 2022

    Adobe Reader and Acrobat Sandbox Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  7. Rank 17Adobe Acrobat / Reader

    CVE-2013-2729

    CVE from 2013, added in 2022

    Adobe Reader and Acrobat Arbitrary Integer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  8. Rank 18Adobe ColdFusion

    CVE-2010-2861

    RansomwareCVE from 2010, added in 2022

    Adobe ColdFusion Directory Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  9. Rank 19Adobe ColdFusion

    CVE-2013-0625

    CVE from 2013, added in 2022

    Adobe ColdFusion Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 7, 2022
    CISA deadline
    184 days
    CVSS severity
    9.8 (critical)
  10. Rank 20Adobe ColdFusion

    CVE-2013-0632

    CVE from 2013, added in 2022

    Adobe ColdFusion Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  11. Rank 21Adobe Acrobat / Reader

    CVE-2013-3346

    CVE from 2013, added in 2022

    Adobe Reader and Acrobat Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  12. Rank 22Adobe Commerce (Magento)

    CVE-2022-24086

    Adobe Commerce and Magento Open Source Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 15, 2022
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  13. Rank 23Adobe ColdFusion

    CVE-2018-15961

    CVE from 2018, added in 2021

    Adobe ColdFusion Unrestricted File Upload Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  14. Rank 24Adobe ColdFusion

    CVE-2018-4939

    CVE from 2018, added in 2021

    Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  15. Rank 25Adobe Acrobat / Reader

    CVE-2008-0655

    CVE from 2008, added in 2022

    Adobe Acrobat and Reader Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  16. Rank 26Adobe Acrobat / Reader

    CVE-2009-3953

    CVE from 2009, added in 2022

    Adobe Acrobat and Reader Universal 3D Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  17. Rank 27Adobe Acrobat / Reader

    CVE-2018-4990

    CVE from 2018, added in 2022

    Adobe Acrobat and Reader Double Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  18. Rank 28Adobe Acrobat / Reader

    CVE-2009-0927

    CVE from 2009, added in 2022

    Adobe Reader and Adobe Acrobat Stack-Based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  19. Rank 29Adobe Acrobat / Reader

    CVE-2014-0496

    CVE from 2014, added in 2022

    Adobe Reader and Acrobat Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  20. Rank 30Adobe Acrobat / Reader

    CVE-2021-21017

    Adobe Acrobat and Reader Heap-based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  21. Rank 31Adobe Acrobat / Reader

    CVE-2021-28550

    Adobe Acrobat and Reader Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  22. Rank 32Adobe Acrobat / Reader

    CVE-2023-21608

    Adobe Acrobat and Reader Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 10, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  23. Rank 33Adobe Acrobat / Reader

    CVE-2023-26369

    Adobe Acrobat and Reader Out-of-Bounds Write Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 14, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  24. Rank 34Adobe Acrobat / Reader

    CVE-2007-5659

    CVE from 2007, added in 2022

    Adobe Acrobat and Reader Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  25. Rank 35Adobe Flash Player

    CVE-2009-1862

    CVE from 2009, added in 2022

    Adobe Acrobat and Reader, Flash Player Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  26. Rank 36Adobe Acrobat / Reader

    CVE-2009-4324

    CVE from 2009, added in 2022

    Adobe Acrobat and Reader Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  27. Rank 37Adobe Acrobat / Reader

    CVE-2008-2992

    RansomwareCVE from 2008, added in 2022

    Adobe Reader and Acrobat Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  28. Rank 38Adobe Acrobat / Reader

    CVE-2010-0188

    RansomwareCVE from 2010, added in 2022

    Adobe Reader and Acrobat Arbitrary Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  29. Rank 39Adobe Acrobat / Reader

    CVE-2013-0640

    CVE from 2013, added in 2022

    Adobe Reader and Acrobat Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  30. Rank 40Adobe Acrobat / Reader

    CVE-2013-0641

    CVE from 2013, added in 2022

    Adobe Reader Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  31. Rank 41Adobe ColdFusion

    CVE-2023-29298

    Adobe ColdFusion Improper Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 20, 2023
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  32. Rank 42Adobe ColdFusion

    CVE-2023-38205

    Adobe ColdFusion Improper Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 20, 2023
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  33. Rank 43Adobe ColdFusion

    CVE-2013-0629

    CVE from 2013, added in 2022

    Adobe ColdFusion Directory Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 7, 2022
    CISA deadline
    184 days
    CVSS severity
    7.5 (high)
  34. Rank 44Adobe ColdFusion

    CVE-2013-0631

    CVE from 2013, added in 2022

    Adobe ColdFusion Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 7, 2022
    CISA deadline
    184 days
    CVSS severity
    7.5 (high)
  35. Rank 45Adobe ColdFusion

    CVE-2024-20767

    Adobe ColdFusion Improper Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 16, 2024
    CISA deadline
    21 days
    CVSS severity
    7.4 (high)
  36. Rank 46Adobe Acrobat / Reader

    CVE-2010-2883

    CVE from 2010, added in 2022

    Adobe Acrobat and Reader Stack-Based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    7.3 (high)
  37. Rank 47Adobe BlazeDS

    CVE-2009-3960

    RansomwareCVE from 2009, added in 2022

    Adobe BlazeDS Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 7, 2022
    CISA deadline
    184 days
    CVSS severity
    6.5 (medium)

End of life: remove

These products are no longer supported: no patch is coming. Remove them or isolate them from the network.

  1. Adobe Flash Player

    CVE-2013-0643

    End of lifeCVE from 2013, added in 2024

    Adobe Flash Player Incorrect Default Permissions Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Sep 17, 2024
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  2. Adobe Flash Player

    CVE-2013-0648

    End of lifeCVE from 2013, added in 2024

    Adobe Flash Player Code Execution Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Sep 17, 2024
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  3. Adobe Flash Player

    CVE-2014-0497

    End of lifeCVE from 2014, added in 2024

    Adobe Flash Player Integer Underflow Vulnerablity

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Sep 17, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  4. Adobe Flash Player

    CVE-2014-0502

    End of lifeCVE from 2014, added in 2024

    Adobe Flash Player Double Free Vulnerablity

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Sep 17, 2024
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  5. Adobe Flash Player

    CVE-2010-1297

    End of lifeCVE from 2010, added in 2022

    Adobe Flash Player Memory Corruption Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  6. Adobe Flash Player

    CVE-2011-0609

    End of lifeCVE from 2011, added in 2022

    Adobe Flash Player Unspecified Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  7. Adobe Flash Player

    CVE-2012-0754

    End of lifeCVE from 2012, added in 2022

    Adobe Flash Player Memory Corruption Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    8.1 (high)
  8. Adobe Flash Player

    CVE-2012-0767

    End of lifeCVE from 2012, added in 2022

    Adobe Flash Player Cross-Site Scripting (XSS) Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    6.1 (medium)
  9. Adobe Flash Player

    CVE-2012-5054

    End of lifeCVE from 2012, added in 2022

    Adobe Flash Player Integer Overflow Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  10. Adobe Flash Player

    CVE-2014-8439

    End of lifeCVE from 2014, added in 2022

    Adobe Flash Player Dereferenced Pointer Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
Show 25 more vulnerabilities
  1. Adobe Flash Player

    CVE-2015-0310

    End of lifeCVE from 2015, added in 2022

    Adobe Flash Player ASLR Bypass Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  2. Adobe Flash Player

    CVE-2015-8651

    End of lifeCVE from 2015, added in 2022

    Adobe Flash Player Integer Overflow Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  3. Adobe Flash Player

    CVE-2016-0984

    End of lifeCVE from 2016, added in 2022

    Adobe Flash Player and AIR Use-After-Free Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  4. Adobe Flash Player

    CVE-2016-1010

    End of lifeCVE from 2016, added in 2022

    Adobe Flash Player and AIR Integer Overflow Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  5. Adobe Flash Player

    CVE-2018-5002

    End of lifeCVE from 2018, added in 2022

    Adobe Flash Player Stack-based Buffer Overflow Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    May 23, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  6. Adobe Flash Player

    CVE-2014-9163

    End of lifeCVE from 2014, added in 2022

    Adobe Flash Player Stack-Based Buffer Overflow Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Apr 13, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  7. Adobe Flash Player

    CVE-2015-0311

    End of lifeCVE from 2015, added in 2022

    Adobe Flash Player Remote Code Execution Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Apr 13, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  8. Adobe Flash Player

    CVE-2015-0313

    End of lifeCVE from 2015, added in 2022

    Adobe Flash Player Use-After-Free Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Apr 13, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  9. Adobe Flash Player

    CVE-2015-3113

    End of lifeCVE from 2015, added in 2022

    Adobe Flash Player Heap-Based Buffer Overflow Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Apr 13, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  10. Adobe Flash Player

    CVE-2015-5122

    End of lifeCVE from 2015, added in 2022

    Adobe Flash Player Use-After-Free Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Apr 13, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  11. Adobe Flash Player

    CVE-2015-5123

    End of lifeCVE from 2015, added in 2022

    Adobe Flash Player Use-After-Free Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Apr 13, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  12. Adobe Flash Player

    CVE-2012-2034

    End of lifeCVE from 2012, added in 2022

    Adobe Flash Player Memory Corruption Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  13. Adobe Flash Player

    CVE-2016-4171

    End of lifeCVE from 2016, added in 2022

    Adobe Flash Player Remote Code Execution Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  14. Adobe Flash Player

    CVE-2016-7892

    End of lifeCVE from 2016, added in 2022

    Adobe Flash Player Use-After-Free Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  15. Adobe Flash Player

    CVE-2011-0611

    End of lifeCVE from 2011, added in 2022

    Adobe Flash Player Remote Code Execution Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  16. Adobe Flash Player

    CVE-2012-1535

    End of lifeCVE from 2012, added in 2022

    Adobe Flash Player Arbitrary Code Execution Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  17. Adobe Flash Player

    CVE-2015-3043

    End of lifeCVE from 2015, added in 2022

    Adobe Flash Player Memory Corruption Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  18. Adobe Flash Player

    CVE-2015-5119

    End of lifeCVE from 2015, added in 2022

    Adobe Flash Player Use-After-Free Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  19. Adobe Flash Player

    CVE-2015-7645

    RansomwareEnd of lifeCVE from 2015, added in 2022

    Adobe Flash Player Arbitrary Code Execution Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  20. Adobe Flash Player

    CVE-2016-1019

    RansomwareEnd of lifeCVE from 2016, added in 2022

    Adobe Flash Player Arbitrary Code Execution Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  21. Adobe Flash Player

    CVE-2016-4117

    RansomwareEnd of lifeCVE from 2016, added in 2022

    Adobe Flash Player Arbitrary Code Execution Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  22. Adobe Flash Player

    CVE-2016-7855

    End of lifeCVE from 2016, added in 2022

    Adobe Flash Player Use-After-Free Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  23. Adobe Flash Player

    CVE-2017-11292

    End of lifeCVE from 2017, added in 2022

    Adobe Flash Player Type Confusion Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  24. Adobe Flash Player

    CVE-2018-15982

    RansomwareEnd of lifeCVE from 2018, added in 2022

    Adobe Flash Player Use-After-Free Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Feb 15, 2022
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  25. Adobe Flash Player

    CVE-2018-4878

    RansomwareEnd of lifeCVE from 2018, added in 2021

    Adobe Flash Player Use-After-Free Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)

Follow and verify

Get new Adobe vulnerabilities: RSS feed (add it to Outlook, Teams, Slack or your feed reader).

Indicative classification, based on the vendor and product names given by CISA. How products are classified.