Brand
Adobe: actively exploited vulnerabilities
82 vulnerabilities in Adobe products (Flash Player, Acrobat / Reader, ColdFusion…) are in CISA’s catalog of exploited vulnerabilities, 3 of them added in the last 90 days. Last added: September 24, 2026.
The brand’s general security advisories page, not the advisory for a specific vulnerability (address checked September 28, 2026).
-
8 vulnerabilities added in the last 12 months
-
82 exploited vulnerabilities in the catalog, in total
-
2 added in the last 30 days
By category
Add just one Adobe category to your radar, or open its page.
- Browsers and web engines 36 vulnerabilities
- Office, PDF and utilities 23 vulnerabilities
- Web and application servers 16 vulnerabilities
- CMS, e-commerce and websites 6 vulnerabilities
- Frameworks and libraries 1 vulnerability
A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.
Affected products
- Flash Player 36 vulnerabilities · Browsers
- Acrobat / Reader 23 vulnerabilities · Office and PDF
- ColdFusion 16 vulnerabilities · Web servers
- Commerce (Magento) 5 vulnerabilities · CMS and websites
- BlazeDS 1 vulnerability · Frameworks
- Experience Manager (AEM) 1 vulnerability · CMS and websites
Name used by CISA: Adobe. Product families: indicative classification by this site.
Pace of additions
| Period | Vulnerabilities added |
|---|---|
| Sep 4, 2025 to Oct 3, 2025 | 0 |
| Oct 4, 2025 to Nov 2, 2025 | 2 |
| Nov 3, 2025 to Dec 2, 2025 | 0 |
| Dec 3, 2025 to Jan 1, 2026 | 0 |
| Jan 2, 2026 to Jan 31, 2026 | 0 |
| Feb 1, 2026 to Mar 2, 2026 | 0 |
| Mar 3, 2026 to Apr 1, 2026 | 0 |
| Apr 2, 2026 to May 1, 2026 | 2 |
| May 2, 2026 to May 31, 2026 | 1 |
| Jun 1, 2026 to Jun 30, 2026 | 0 |
| Jul 1, 2026 to Jul 30, 2026 | 1 |
| Jul 31, 2026 to Aug 29, 2026 | 0 |
| Aug 30, 2026 to Sep 28, 2026 (in progress) | 2 |
Patch first
In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this Adobe list.
Rank 1Adobe Commerce (Magento)
CVE-2026-71362Recently addedHunt for compromise (CISA)
Adobe Commerce and Magento Incorrect Authorization Vulnerability
Added to the catalog less than 30 days ago: ranked by date added.
- Added
- Sep 24, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.1 (critical)
Rank 2Adobe Commerce (Magento)
CVE-2026-75650Recently addedHunt for compromise (CISA)
Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
Added to the catalog less than 30 days ago: ranked by date added.
- Added
- Sep 8, 2026
- CISA deadline
- 3 days
- CVSS severity
- 10.0 (critical)
Rank 3Adobe ColdFusion
CVE-2026-48282Hunt for compromise (CISA)
Adobe ColdFusion Path Traversal Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Jul 7, 2026
- CISA deadline
- 3 days
- CVSS severity
- 10.0 (critical)
Rank 4Adobe Experience Manager (AEM)
CVE-2025-54253Adobe Experience Manager Forms Code Execution Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Oct 15, 2025
- CISA deadline
- 21 days
- CVSS severity
- 10.0 (critical)
Rank 5Adobe Commerce (Magento)
CVE-2025-54236Adobe Commerce and Magento Improper Input Validation Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Oct 24, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.1 (critical)
Rank 6Adobe Acrobat / Reader
CVE-2009-3459CVE from 2009, added in 2026
Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- May 20, 2026
- CISA deadline
- 14 days
- CVSS severity
- 8.8 (high)
Rank 7Adobe Acrobat / Reader
CVE-2026-34621Adobe Acrobat and Reader Prototype Pollution Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Apr 13, 2026
- CISA deadline
- 14 days
- CVSS severity
- 8.6 (high)
Rank 8Adobe Acrobat / Reader
CVE-2020-9715CVE from 2020, added in 2026
Adobe Acrobat Use-After-Free Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Apr 13, 2026
- CISA deadline
- 14 days
- CVSS severity
- 7.8 (high)
Rank 9Adobe ColdFusion
CVE-2017-3066CVE from 2017, added in 2025
Adobe ColdFusion Deserialization Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Feb 24, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 10Adobe Commerce (Magento)
CVE-2024-34102Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jul 17, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Show 37 more vulnerabilities
Rank 11Adobe ColdFusion
CVE-2023-29300Ransomware
Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jan 8, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 12Adobe ColdFusion
CVE-2023-38203Ransomware
Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jan 8, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 13Adobe ColdFusion
CVE-2023-26359Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Aug 21, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 14Adobe ColdFusion
CVE-2023-26360Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 15, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 15Adobe Acrobat / Reader
CVE-2011-2462CVE from 2011, added in 2022
Adobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jun 8, 2022
- CISA deadline
- 14 days
- CVSS severity
- 9.8 (critical)
Rank 16Adobe Acrobat / Reader
CVE-2014-0546CVE from 2014, added in 2022
Adobe Reader and Acrobat Sandbox Bypass Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 17Adobe Acrobat / Reader
CVE-2013-2729CVE from 2013, added in 2022
Adobe Reader and Acrobat Arbitrary Integer Overflow Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 28, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 18Adobe ColdFusion
CVE-2010-2861RansomwareCVE from 2010, added in 2022
Adobe ColdFusion Directory Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 19Adobe ColdFusion
CVE-2013-0625CVE from 2013, added in 2022
Adobe ColdFusion Authentication Bypass Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 7, 2022
- CISA deadline
- 184 days
- CVSS severity
- 9.8 (critical)
Rank 20Adobe ColdFusion
CVE-2013-0632CVE from 2013, added in 2022
Adobe ColdFusion Authentication Bypass Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 21Adobe Acrobat / Reader
CVE-2013-3346CVE from 2013, added in 2022
Adobe Reader and Acrobat Memory Corruption Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 22Adobe Commerce (Magento)
CVE-2022-24086Adobe Commerce and Magento Open Source Improper Input Validation Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Feb 15, 2022
- CISA deadline
- 14 days
- CVSS severity
- 9.8 (critical)
Rank 23Adobe ColdFusion
CVE-2018-15961CVE from 2018, added in 2021
Adobe ColdFusion Unrestricted File Upload Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 24Adobe ColdFusion
CVE-2018-4939CVE from 2018, added in 2021
Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 25Adobe Acrobat / Reader
CVE-2008-0655CVE from 2008, added in 2022
Adobe Acrobat and Reader Unspecified Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jun 8, 2022
- CISA deadline
- 14 days
- CVSS severity
- 8.8 (high)
Rank 26Adobe Acrobat / Reader
CVE-2009-3953CVE from 2009, added in 2022
Adobe Acrobat and Reader Universal 3D Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jun 8, 2022
- CISA deadline
- 14 days
- CVSS severity
- 8.8 (high)
Rank 27Adobe Acrobat / Reader
CVE-2018-4990CVE from 2018, added in 2022
Adobe Acrobat and Reader Double Free Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jun 8, 2022
- CISA deadline
- 14 days
- CVSS severity
- 8.8 (high)
Rank 28Adobe Acrobat / Reader
CVE-2009-0927CVE from 2009, added in 2022
Adobe Reader and Adobe Acrobat Stack-Based Buffer Overflow Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Rank 29Adobe Acrobat / Reader
CVE-2014-0496CVE from 2014, added in 2022
Adobe Reader and Acrobat Use-After-Free Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Rank 30Adobe Acrobat / Reader
CVE-2021-21017Adobe Acrobat and Reader Heap-based Buffer Overflow Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 14 days
- CVSS severity
- 8.8 (high)
Rank 31Adobe Acrobat / Reader
CVE-2021-28550Adobe Acrobat and Reader Use-After-Free Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 14 days
- CVSS severity
- 8.8 (high)
Rank 32Adobe Acrobat / Reader
CVE-2023-21608Adobe Acrobat and Reader Use-After-Free Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Oct 10, 2023
- CISA deadline
- 21 days
- CVSS severity
- 7.8 (high)
Rank 33Adobe Acrobat / Reader
CVE-2023-26369Adobe Acrobat and Reader Out-of-Bounds Write Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Sep 14, 2023
- CISA deadline
- 21 days
- CVSS severity
- 7.8 (high)
Rank 34Adobe Acrobat / Reader
CVE-2007-5659CVE from 2007, added in 2022
Adobe Acrobat and Reader Buffer Overflow Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jun 8, 2022
- CISA deadline
- 14 days
- CVSS severity
- 7.8 (high)
Rank 35Adobe Flash Player
CVE-2009-1862CVE from 2009, added in 2022
Adobe Acrobat and Reader, Flash Player Unspecified Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jun 8, 2022
- CISA deadline
- 14 days
- CVSS severity
- 7.8 (high)
Rank 36Adobe Acrobat / Reader
CVE-2009-4324CVE from 2009, added in 2022
Adobe Acrobat and Reader Use-After-Free Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jun 8, 2022
- CISA deadline
- 14 days
- CVSS severity
- 7.8 (high)
Rank 37Adobe Acrobat / Reader
CVE-2008-2992RansomwareCVE from 2008, added in 2022
Adobe Reader and Acrobat Input Validation Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 21 days
- CVSS severity
- 7.8 (high)
Rank 38Adobe Acrobat / Reader
CVE-2010-0188RansomwareCVE from 2010, added in 2022
Adobe Reader and Acrobat Arbitrary Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 21 days
- CVSS severity
- 7.8 (high)
Rank 39Adobe Acrobat / Reader
CVE-2013-0640CVE from 2013, added in 2022
Adobe Reader and Acrobat Memory Corruption Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 21 days
- CVSS severity
- 7.8 (high)
Rank 40Adobe Acrobat / Reader
CVE-2013-0641CVE from 2013, added in 2022
Adobe Reader Buffer Overflow Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 21 days
- CVSS severity
- 7.8 (high)
Rank 41Adobe ColdFusion
CVE-2023-29298Adobe ColdFusion Improper Access Control Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jul 20, 2023
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 42Adobe ColdFusion
CVE-2023-38205Adobe ColdFusion Improper Access Control Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jul 20, 2023
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 43Adobe ColdFusion
CVE-2013-0629CVE from 2013, added in 2022
Adobe ColdFusion Directory Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 7, 2022
- CISA deadline
- 184 days
- CVSS severity
- 7.5 (high)
Rank 44Adobe ColdFusion
CVE-2013-0631CVE from 2013, added in 2022
Adobe ColdFusion Information Disclosure Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 7, 2022
- CISA deadline
- 184 days
- CVSS severity
- 7.5 (high)
Rank 45Adobe ColdFusion
CVE-2024-20767Adobe ColdFusion Improper Access Control Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Dec 16, 2024
- CISA deadline
- 21 days
- CVSS severity
- 7.4 (high)
Rank 46Adobe Acrobat / Reader
CVE-2010-2883CVE from 2010, added in 2022
Adobe Acrobat and Reader Stack-Based Buffer Overflow Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jun 8, 2022
- CISA deadline
- 14 days
- CVSS severity
- 7.3 (high)
Rank 47Adobe BlazeDS
CVE-2009-3960RansomwareCVE from 2009, added in 2022
Adobe BlazeDS Information Disclosure Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 7, 2022
- CISA deadline
- 184 days
- CVSS severity
- 6.5 (medium)
End of life: remove
These products are no longer supported: no patch is coming. Remove them or isolate them from the network.
Adobe Flash Player
CVE-2013-0643End of lifeCVE from 2013, added in 2024
Adobe Flash Player Incorrect Default Permissions Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Sep 17, 2024
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Adobe Flash Player
CVE-2013-0648End of lifeCVE from 2013, added in 2024
Adobe Flash Player Code Execution Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Sep 17, 2024
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Adobe Flash Player
CVE-2014-0497End of lifeCVE from 2014, added in 2024
Adobe Flash Player Integer Underflow Vulnerablity
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Sep 17, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Adobe Flash Player
CVE-2014-0502End of lifeCVE from 2014, added in 2024
Adobe Flash Player Double Free Vulnerablity
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Sep 17, 2024
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Adobe Flash Player
CVE-2010-1297End of lifeCVE from 2010, added in 2022
Adobe Flash Player Memory Corruption Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Jun 8, 2022
- CISA deadline
- 14 days
- CVSS severity
- 7.8 (high)
Adobe Flash Player
CVE-2011-0609End of lifeCVE from 2011, added in 2022
Adobe Flash Player Unspecified Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Jun 8, 2022
- CISA deadline
- 14 days
- CVSS severity
- 7.8 (high)
Adobe Flash Player
CVE-2012-0754End of lifeCVE from 2012, added in 2022
Adobe Flash Player Memory Corruption Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Jun 8, 2022
- CISA deadline
- 14 days
- CVSS severity
- 8.1 (high)
Adobe Flash Player
CVE-2012-0767End of lifeCVE from 2012, added in 2022
Adobe Flash Player Cross-Site Scripting (XSS) Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Jun 8, 2022
- CISA deadline
- 14 days
- CVSS severity
- 6.1 (medium)
Adobe Flash Player
CVE-2012-5054End of lifeCVE from 2012, added in 2022
Adobe Flash Player Integer Overflow Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Jun 8, 2022
- CISA deadline
- 14 days
- CVSS severity
- 8.8 (high)
Adobe Flash Player
CVE-2014-8439End of lifeCVE from 2014, added in 2022
Adobe Flash Player Dereferenced Pointer Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- May 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Show 25 more vulnerabilities
Adobe Flash Player
CVE-2015-0310End of lifeCVE from 2015, added in 2022
Adobe Flash Player ASLR Bypass Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- May 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 7.8 (high)
Adobe Flash Player
CVE-2015-8651End of lifeCVE from 2015, added in 2022
Adobe Flash Player Integer Overflow Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- May 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Adobe Flash Player
CVE-2016-0984End of lifeCVE from 2016, added in 2022
Adobe Flash Player and AIR Use-After-Free Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- May 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Adobe Flash Player
CVE-2016-1010End of lifeCVE from 2016, added in 2022
Adobe Flash Player and AIR Integer Overflow Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- May 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Adobe Flash Player
CVE-2018-5002End of lifeCVE from 2018, added in 2022
Adobe Flash Player Stack-based Buffer Overflow Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- May 23, 2022
- CISA deadline
- 21 days
- CVSS severity
- 7.8 (high)
Adobe Flash Player
CVE-2014-9163End of lifeCVE from 2014, added in 2022
Adobe Flash Player Stack-Based Buffer Overflow Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Apr 13, 2022
- CISA deadline
- 21 days
- CVSS severity
- 7.8 (high)
Adobe Flash Player
CVE-2015-0311End of lifeCVE from 2015, added in 2022
Adobe Flash Player Remote Code Execution Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Apr 13, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Adobe Flash Player
CVE-2015-0313End of lifeCVE from 2015, added in 2022
Adobe Flash Player Use-After-Free Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Apr 13, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Adobe Flash Player
CVE-2015-3113End of lifeCVE from 2015, added in 2022
Adobe Flash Player Heap-Based Buffer Overflow Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Apr 13, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Adobe Flash Player
CVE-2015-5122End of lifeCVE from 2015, added in 2022
Adobe Flash Player Use-After-Free Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Apr 13, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Adobe Flash Player
CVE-2015-5123End of lifeCVE from 2015, added in 2022
Adobe Flash Player Use-After-Free Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Apr 13, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Adobe Flash Player
CVE-2012-2034End of lifeCVE from 2012, added in 2022
Adobe Flash Player Memory Corruption Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Mar 28, 2022
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Adobe Flash Player
CVE-2016-4171End of lifeCVE from 2016, added in 2022
Adobe Flash Player Remote Code Execution Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Adobe Flash Player
CVE-2016-7892End of lifeCVE from 2016, added in 2022
Adobe Flash Player Use-After-Free Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Adobe Flash Player
CVE-2011-0611End of lifeCVE from 2011, added in 2022
Adobe Flash Player Remote Code Execution Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Mar 3, 2022
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Adobe Flash Player
CVE-2012-1535End of lifeCVE from 2012, added in 2022
Adobe Flash Player Arbitrary Code Execution Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Mar 3, 2022
- CISA deadline
- 21 days
- CVSS severity
- 7.8 (high)
Adobe Flash Player
CVE-2015-3043End of lifeCVE from 2015, added in 2022
Adobe Flash Player Memory Corruption Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Mar 3, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Adobe Flash Player
CVE-2015-5119End of lifeCVE from 2015, added in 2022
Adobe Flash Player Use-After-Free Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Mar 3, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Adobe Flash Player
CVE-2015-7645RansomwareEnd of lifeCVE from 2015, added in 2022
Adobe Flash Player Arbitrary Code Execution Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Mar 3, 2022
- CISA deadline
- 21 days
- CVSS severity
- 7.8 (high)
Adobe Flash Player
CVE-2016-1019RansomwareEnd of lifeCVE from 2016, added in 2022
Adobe Flash Player Arbitrary Code Execution Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Mar 3, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Adobe Flash Player
CVE-2016-4117RansomwareEnd of lifeCVE from 2016, added in 2022
Adobe Flash Player Arbitrary Code Execution Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Mar 3, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Adobe Flash Player
CVE-2016-7855End of lifeCVE from 2016, added in 2022
Adobe Flash Player Use-After-Free Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Mar 3, 2022
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Adobe Flash Player
CVE-2017-11292End of lifeCVE from 2017, added in 2022
Adobe Flash Player Type Confusion Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Mar 3, 2022
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Adobe Flash Player
CVE-2018-15982RansomwareEnd of lifeCVE from 2018, added in 2022
Adobe Flash Player Use-After-Free Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Feb 15, 2022
- CISA deadline
- 181 days
- CVSS severity
- 7.8 (high)
Adobe Flash Player
CVE-2018-4878RansomwareEnd of lifeCVE from 2018, added in 2021
Adobe Flash Player Use-After-Free Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 7.8 (high)
Follow and verify
Get new Adobe vulnerabilities: RSS feed (add it to Outlook, Teams, Slack or your feed reader).
Indicative classification, based on the vendor and product names given by CISA. How products are classified.