Adobe Adobe Based in San Jose, best known for creating Photoshop, Acrobat (PDF).

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Adobe product.

RSS Feeds for Adobe security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Adobe products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Adobe Sorted by Most Security Vulnerabilities since 2018

Adobe Experience Manager1276 vulnerabilities
Adobe Experience Manager (AEM), is a comprehensive content management solution for building websites, mobile apps and forms

Adobe Acrobat577 vulnerabilities
Application for working with PDF documents

Adobe Commerce224 vulnerabilities

Adobe ColdFusion224 vulnerabilities
Web application server since 1995. Tag or script based programming language CFML.

Adobe Commerce191 vulnerabilities

Adobe InDesign175 vulnerabilities

Adobe Magento146 vulnerabilities

Adobe Illustrator137 vulnerabilities

Adobe Commerce B2b135 vulnerabilities

Adobe Dimension107 vulnerabilities

Adobe Bridge106 vulnerabilities

Adobe Photoshop101 vulnerabilities
Popular Photo Editing Software

Adobe Magento Open Source96 vulnerabilities

Adobe Substance 3d Painter86 vulnerabilities

Adobe Animate84 vulnerabilities

Adobe Substance 3d Stager84 vulnerabilities

Adobe Framemaker79 vulnerabilities

Adobe After Effects73 vulnerabilities

Adobe Connect70 vulnerabilities

Adobe Reader66 vulnerabilities

Adobe Substance 3d Designer52 vulnerabilities

Adobe Incopy45 vulnerabilities

Adobe Media Encoder43 vulnerabilities

Adobe Substance 3d Modeler41 vulnerabilities

Adobe Substance 3d Sampler41 vulnerabilities

Adobe Audition32 vulnerabilities

Adobe Premiere Pro27 vulnerabilities

Adobe Creative Cloud Desktop Application23 vulnerabilities
The desktop client for Adobe Creative Cloud

Adobe Magento Commerce21 vulnerabilities

Adobe Lightroom17 vulnerabilities

Adobe Dreamweaver14 vulnerabilities

Adobe Format Plugins12 vulnerabilities

Adobe Premiere Rush11 vulnerabilities

Adobe Substance 3d Viewer10 vulnerabilities

Adobe Photoshop Elements3 vulnerabilities

Adobe Robohelp2 vulnerabilities

Adobe Acrobat 20171 vulnerability

Adobe Acrobat 20201 vulnerability

Adobe Acrobat Reader 20171 vulnerability

Adobe Acrobat Reader 20201 vulnerability

Adobe Aero1 vulnerability

Adobe Air Sdk Compiler1 vulnerability

Adobe Livecycle1 vulnerability

Adobe Pdf Library Sdk1 vulnerability

Adobe Pass1 vulnerability

Recent Adobe Security Advisories

Advisory Title Published
APSB26-150 Security updates available for Adobe Connect | APSB26-150 September 22, 2026
APSB26-147 Security updates available for Content Credentials SDK | APSB26-147 September 22, 2026
APSB26-155 Security updates available for Adobe Substance3D - Modeler | APSB26-155 September 22, 2026
APSB26-148 Security Updates Available for Adobe Bridge | APSB26-148 September 22, 2026
APSB26-151 Security updates available for Adobe Experience Manager (AEM) Forms | APSB26-151 September 22, 2026
APSB26-145 Security Update Available for Adobe InDesign | APSB26-145 September 22, 2026
APSB26-141 Security Bulletin for Adobe Acrobat and Reader  | APSB26-141 September 8, 2026
APSB26-130 Security updates available for Adobe Photoshop | APSB26-130 September 8, 2026
APSB26-98 Security updates available for Adobe Experience Manager | APSB26-98 September 8, 2026
APSB26-136 Security updates available for Adobe Photoshop (Mobile) | APSB26-136 September 8, 2026

Known Exploited Adobe Vulnerabilities

The following Adobe vulnerabilities have recently been marked by CISA as Known to be Exploited by threat actors.

Title Description Added
Adobe Commerce and Magento Incorrect Authorization Vulnerability Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction.
CVE-2026-71362
September 24, 2026
Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vul Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code.
CVE-2026-75650
September 8, 2026
Adobe ColdFusion Path Traversal Vulnerability Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.
CVE-2026-48282 Exploit Probability: 99.0%
July 7, 2026
Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption.
CVE-2009-3459 Exploit Probability: 86.6%
May 20, 2026
Adobe Acrobat and Reader Prototype Pollution Vulnerability Adobe Acrobat and Reader contain a prototype pollution vulnerability that allows for arbitrary code execution.
CVE-2026-34621 Exploit Probability: 7.1%
April 13, 2026
Adobe Acrobat Use-After-Free Vulnerability Adobe Acrobat contains a use-after-free vulnerability that allows for code execution
CVE-2020-9715 Exploit Probability: 48.6%
April 13, 2026
Adobe Commerce and Magento Improper Input Validation Vulnerability Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API.
CVE-2025-54236 Exploit Probability: 94.5%
October 24, 2025
Adobe Experience Manager Forms Code Execution Vulnerability Adobe Experience Manager Forms in JEE contains an unspecified vulnerability that allows for arbitrary code execution.
CVE-2025-54253 Exploit Probability: 88.0%
October 15, 2025
Adobe ColdFusion Deserialization Vulnerability Adobe ColdFusion contains a deserialization vulnerability in the Apache BlazeDS library that allows for arbitrary code execution.
CVE-2017-3066 Exploit Probability: 90.6%
February 24, 2025
Adobe ColdFusion Improper Access Control Vulnerability Adobe ColdFusion contains an improper access control vulnerability that could allow an attacker to access or modify restricted files via an internet-exposed admin panel.
CVE-2024-20767 Exploit Probability: 98.5%
December 16, 2024
Adobe Flash Player Incorrect Default Permissions Vulnerability Adobe Flash Player contains an incorrect default permissions vulnerability in the Firefox sandbox that allows a remote attacker to execute arbitrary code via crafted SWF content.
CVE-2013-0643 Exploit Probability: 10.5%
September 17, 2024
Adobe Flash Player Code Execution Vulnerability Adobe Flash Player contains an unspecified vulnerability in the ExternalInterface ActionScript functionality that allows a remote attacker to execute arbitrary code via crafted SWF content.
CVE-2013-0648 Exploit Probability: 11.1%
September 17, 2024
Adobe Flash Player Double Free Vulnerablity Adobe Flash Player contains a double free vulnerability that allows a remote attacker to execute arbitrary code.
CVE-2014-0502 Exploit Probability: 24.8%
September 17, 2024
Adobe Flash Player Integer Underflow Vulnerablity Adobe Flash Player contains an integer underflow vulnerability that allows a remote attacker to execute arbitrary code.
CVE-2014-0497 Exploit Probability: 99.9%
September 17, 2024
Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) V Adobe Commerce and Magento Open Source contain an improper restriction of XML external entity reference (XXE) vulnerability that allows for remote code execution.
CVE-2024-34102 Exploit Probability: 100.0%
July 17, 2024
Adobe ColdFusion Deserialization of Untrusted Data Vulnerability Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution.
CVE-2023-38203 Exploit Probability: 97.1%
January 8, 2024
Adobe ColdFusion Deserialization of Untrusted Data Vulnerability Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution.
CVE-2023-29300 Exploit Probability: 100.0%
January 8, 2024
Adobe Acrobat and Reader Use-After-Free Vulnerability Adobe Acrobat and Reader contains a use-after-free vulnerability that allows for code execution in the context of the current user.
CVE-2023-21608 Exploit Probability: 61.5%
October 10, 2023
Adobe Acrobat and Reader Out-of-Bounds Write Vulnerability Adobe Acrobat and Reader contains an out-of-bounds write vulnerability that allows for code execution.
CVE-2023-26369 Exploit Probability: 6.7%
September 14, 2023
Adobe ColdFusion Deserialization of Untrusted Data Vulnerability Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could result in code execution in the context of the current user.
CVE-2023-26359 Exploit Probability: 17.0%
August 21, 2023

Of the known exploited vulnerabilities above, 11 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings. 5 known exploited Adobe vulnerabilities are in the top 5% (95th percentile or greater) of the EPSS exploit probability rankings.

Top 10 Riskiest Adobe Vulnerabilities

Based on the current exploit probability, these Adobe vulnerabilities are on CISA's Known Exploited vulnerabilities list (KEV) and are ranked by the current EPSS exploit probability.

Rank CVE EPSS Vulnerability
1 CVE-2024-34102 100.0% Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) V
2 CVE-2023-29300 100.0% Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
3 CVE-2018-15961 100.0% Adobe ColdFusion Remote Code Execution
4 CVE-2015-3113 99.9% Adobe Flash Player Heap-Based Buffer Overflow Vulnerability
5 CVE-2014-0497 99.9% Adobe Flash Player Integer Underflow Vulnerablity
6 CVE-2023-29298 99.8% Adobe ColdFusion Improper Access Control Vulnerability
7 CVE-2023-38205 99.7% Adobe ColdFusion Improper Access Control Vulnerability
8 CVE-2010-2861 99.7% Adobe ColdFusion Directory Traversal Vulnerability
9 CVE-2011-0611 99.4% Adobe Flash Player Remote Code Execution Vulnerability
10 CVE-2015-5119 99.3% Adobe Flash Player Use-After-Free Vulnerability

By the Year

In 2026 there have been 836 vulnerabilities in Adobe with an average score of 6.9 out of ten. Last year, in 2025 Adobe had 817 security vulnerabilities published. That is, 19 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.60.




Year Vulnerabilities Average Score
2026 836 6.93
2025 817 6.33
2024 753 6.20
2023 668 6.35
2022 421 6.77
2021 323 6.73
2020 344 7.74
2019 324 6.72
2018 94 7.91

It may take a day or so for new Adobe vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Adobe Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-84395 Sep 22, 2026
Premiere Pro SSRF Priv Esc in Desktop App Premiere Pro is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation potentially resulting in unauthorized write access. Exploitation of this issue does not require user interaction. Scope is changed.
CVE-2026-83963 Sep 22, 2026
Adobe Substance3D Modeler OOB Write Enables Code Exec Substance3D - Modeler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Substance 3d Modeler
CVE-2026-81998 Sep 22, 2026
Adobe Substance3D Modeler OOB Write Enables Code Exec Substance3D - Modeler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Substance 3d Modeler
CVE-2026-83962 Sep 22, 2026
Substance3D Modeler Stack-based Buffer Overflow Allows RCE via Malicious File Substance3D - Modeler is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Substance 3d Modeler
CVE-2026-79906 Sep 22, 2026
Out-of-Bounds Write in Substance3D Modeler Enables ACE Substance3D - Modeler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Substance 3d Modeler
CVE-2026-75743 Sep 22, 2026
Adobe Experience Manager Forms JEE CSRF Bypass Vulnerability Adobe Experience Manager Forms JEE is affected by a Cross-Site Request Forgery (CSRF) vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access, causing a limited disruption to availability. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page.
Experience Manager
CVE-2026-75745 Sep 22, 2026
Adobe Experience Manager Forms JEE: Incorrect Auth Enables Arbitrary Code Exec Adobe Experience Manager Forms JEE is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Experience Manager
CVE-2026-82000 Sep 22, 2026
SSRF in Adobe Experience Manager Forms JEE Allows Privilege Escalation Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access to internal resources. Exploitation of this issue does not require user interaction. Scope is changed.
Experience Manager
CVE-2026-81995 Sep 22, 2026
Adobe Experience Manager Forms JEE: Improper Input Validation Enabling ACO Adobe Experience Manager Forms JEE is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Experience Manager
CVE-2026-75744 Sep 22, 2026
Adobe AEM Forms JEE XSS Stored Vulnerability Adobe Experience Manager Forms JEE is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.
Experience Manager
CVE-2026-81999 Sep 22, 2026
SSRF in Adobe Experience Manager Forms JEE Enables Privilege Escalation Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. An attacker with high privileges could exploit this vulnerability to gain elevated access to internal resources. Exploitation of this issue does not require user interaction. Scope is changed.
Experience Manager
CVE-2026-75689 Sep 22, 2026
Adobe Connect Stored XSS via Form Fields Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.
Connect
CVE-2026-83964 Sep 22, 2026
Adobe Connect Improper Cert Validation leads to memory disclosure Adobe Connect is affected by an Improper Certificate Validation vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue does not require user interaction.
Connect
CVE-2026-34689 Sep 22, 2026
Adobe Connect Path Traversal (CVE-2026-34689) Enables Arbitrary File Read Adobe Connect is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed.
Connect
CVE-2026-75686 Sep 22, 2026
Adobe Connect Improper Input Validation Arbitrary Code Execution Adobe Connect is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.
Connect
CVE-2026-75682 Sep 22, 2026
Adobe Connect SQL Injection (CVE-2026-75682) Adobe Connect is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary SQL commands, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue does not require user interaction. Scope is changed.
Connect
CVE-2026-75698 Sep 22, 2026
Adobe Connect Reflected XSS in URL Enables Session Escape Adobe Connect is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.
Connect
CVE-2026-48361 Sep 22, 2026
Adobe Connect Stored XSS via Form Fields Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Connect
CVE-2026-75684 Sep 22, 2026
Adobe Connect Stored XSS in Form Fields Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.
Connect
CVE-2026-75697 Sep 22, 2026
Adobe Connect Stored XSS in Form Fields Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.
Connect
CVE-2026-75658 Sep 22, 2026
Adobe Bridge OOB Write Enabling Arbitrary Code Execution Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Bridge
CVE-2026-75656 Sep 22, 2026
Adobe Bridge OOB Read Disclosure via Malicious File Bridge is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Bridge
CVE-2026-75649 Sep 22, 2026
Adobe Bridge Heap Overflow in File Handling Arbitrary Code Exec Bridge is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Bridge
CVE-2026-75676 Sep 22, 2026
Adobe Bridge Stack BOV Vulnerability (CVE-2026-75676) Bridge is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Bridge
CVE-2026-75655 Sep 22, 2026
Adobe Bridge Uncontrolled Recursion CVE-2026-75655: RCE via Malicious File Bridge is affected by an Uncontrolled Recursion vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Bridge
CVE-2026-75665 Sep 22, 2026
Adobe Bridge Heap Buffer Overflow CVE-2026-75665 Enables Local Code Exec Bridge is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Bridge
CVE-2026-75663 Sep 22, 2026
Adobe Bridge OOB Write Arbitrary Code Exec via Malicious File Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Bridge
CVE-2026-75634 Sep 22, 2026
CAI Content Credentials Improper Input Validation Bypass CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized limited write access. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page.
CVE-2026-75632 Sep 22, 2026
Adobe CAI Content Credentials Uncontrolled Resource Consumption DoS CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user interaction.
CVE-2026-75633 Sep 22, 2026
Adobe CAI Content Credentials Improper Input Validation DoS CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page.
CVE-2026-19480 Sep 22, 2026
Adobe CAI Content Credentials: Improper Input Validation Bypass CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction.
CVE-2026-75638 Sep 22, 2026
CAI Content Credentials Improper Input Validation Bypass CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page.
CVE-2026-89277 Sep 22, 2026
Adobe CAI Content Credentials Integer Overflow DenialofService CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page.
CVE-2026-76194 Sep 22, 2026
Adobe CAI Content Credentials Improper Input Validation Bypass CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized limited write access. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page.
CVE-2026-84396 Sep 22, 2026
Adobe InDesign NULL Pointer Deref in Desktop Enabling DoS InDesign Desktop is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
InDesign
CVE-2026-76192 Sep 22, 2026
NULL Pointer Deref in Adobe InDesign Desktop causing DoS InDesign Desktop is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
InDesign
CVE-2026-75703 Sep 22, 2026
Adobe Campaign Classic (ACC) Code Injection Enables Arbitrary Execution Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
CVE-2026-84412 Sep 22, 2026
Acc Code Injection in Adobe Campaign Classic for Arbitrary Code Exec Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
CVE-2026-89276 Sep 22, 2026
Adobe Campaign Classic (ACC) Code Injection Enables Arbitrary Code Exec Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
CVE-2026-83660 Sep 22, 2026
Adobe Campaign Classic SSRF Privilege Escalation Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed.
CVE-2026-82013 Sep 22, 2026
Adobe Campaign Classic SSRF: Privilege Escalation Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access to internal resources. Exploitation of this issue does not require user interaction. Scope is changed.
CVE-2026-82003 Sep 22, 2026
Adobe Campaign Classic Improper Input Validation leads to arbitrary code exec Adobe Campaign Classic (ACC) is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.
CVE-2026-82009 Sep 22, 2026
Adobe Campaign Classic (ACC) SQL Injection Allows Arbitrary Code Exec Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary SQL commands. Exploitation of this issue does not require user interaction. Scope is changed.
CVE-2026-75721 Sep 22, 2026
Adobe Campaign Classic Improper Code Injection (CVE-2026-75721) Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
CVE-2026-75723 Sep 22, 2026
Adobe Campaign Classic Incorrect Auth Enables Arbitrary Code Exec Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
CVE-2026-73369 Sep 22, 2026
Adobe Campaign Classic CVE-2026-73369 Code Injection Allows Remote Code Exec Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
CVE-2026-75699 Sep 22, 2026
Adobe Campaign Classic Improper Code Generation (Code Injection) Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
CVE-2026-82011 Sep 22, 2026
Adobe Campaign Classic SQLi Bypass Vulnerability Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and limited write access. Exploitation of this issue does not require user interaction. Scope is changed.
CVE-2026-82008 Sep 22, 2026
Adobe Campaign Classic Improper Input Validation Allows Code Execution Adobe Campaign Classic (ACC) is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
CVE-2026-82443 Sep 22, 2026
Adobe Campaign Classic SSRF Enables Privilege Escalation Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access to internal resources. Exploitation of this issue does not require user interaction. Scope is changed.
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.