Adobe Based in San Jose, best known for creating Photoshop, Acrobat (PDF).
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Adobe product.
RSS Feeds for Adobe security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Adobe products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Adobe Sorted by Most Security Vulnerabilities since 2018
Adobe Experience Manager1162 vulnerabilities
Adobe Experience Manager (AEM), is a comprehensive content management solution for building websites, mobile apps and forms
Adobe ColdFusion198 vulnerabilities
Web application server since 1995. Tag or script based programming language CFML.
Adobe Creative Cloud Desktop Application23 vulnerabilities
The desktop client for Adobe Creative Cloud
Recent Adobe Security Advisories
| Advisory | Title | Published |
|---|---|---|
| APSB26-114 | Security updates available for Adobe Campaign Classic | APSB26-114 | July 29, 2026 |
| APSB26-87 | Security updates available for Adobe Format Plugins | APSB26-87 | July 28, 2026 |
| APSB26-89 | Security Updates Available for Adobe Bridge | APSB26-89 | July 28, 2026 |
| APSB26-73 | Security Updates Available for Adobe Commerce | APSB26-73 | July 14, 2026 |
| APSB26-81 | Security Updates Available for Adobe Bridge | APSB26-81 | July 14, 2026 |
| APSB26-74 | Security updates available for Adobe Experience Manager | APSB26-74 | July 14, 2026 |
| APSB26-79 | Security Updates Available for Adobe Illustrator | APSB26-79 | July 14, 2026 |
| APSB26-71 | Security Updates Available for Adobe Audition | APSB26-71 | July 14, 2026 |
| APSB26-80 | Security updates available for Content Credentials SDK | APSB26-80 | July 14, 2026 |
| APSB26-77 | Security update available for Adobe Creative Cloud Desktop Application | APSB26-77 | July 14, 2026 |
Known Exploited Adobe Vulnerabilities
The following Adobe vulnerabilities have recently been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| Adobe ColdFusion Path Traversal Vulnerability |
Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user. CVE-2026-48282 Exploit Probability: 99.0% |
July 7, 2026 |
| Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability |
Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption. CVE-2009-3459 Exploit Probability: 86.6% |
May 20, 2026 |
| Adobe Acrobat Use-After-Free Vulnerability |
Adobe Acrobat contains a use-after-free vulnerability that allows for code execution CVE-2020-9715 Exploit Probability: 48.4% |
April 13, 2026 |
| Adobe Acrobat and Reader Prototype Pollution Vulnerability |
Adobe Acrobat and Reader contain a prototype pollution vulnerability that allows for arbitrary code execution. CVE-2026-34621 Exploit Probability: 7.1% |
April 13, 2026 |
| Adobe Commerce and Magento Improper Input Validation Vulnerability |
Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API. CVE-2025-54236 Exploit Probability: 96.7% |
October 24, 2025 |
| Adobe Experience Manager Forms Code Execution Vulnerability |
Adobe Experience Manager Forms in JEE contains an unspecified vulnerability that allows for arbitrary code execution. CVE-2025-54253 Exploit Probability: 87.5% |
October 15, 2025 |
| Adobe ColdFusion Deserialization Vulnerability |
Adobe ColdFusion contains a deserialization vulnerability in the Apache BlazeDS library that allows for arbitrary code execution. CVE-2017-3066 Exploit Probability: 90.6% |
February 24, 2025 |
| Adobe ColdFusion Improper Access Control Vulnerability |
Adobe ColdFusion contains an improper access control vulnerability that could allow an attacker to access or modify restricted files via an internet-exposed admin panel. CVE-2024-20767 Exploit Probability: 98.5% |
December 16, 2024 |
| Adobe Flash Player Code Execution Vulnerability |
Adobe Flash Player contains an unspecified vulnerability in the ExternalInterface ActionScript functionality that allows a remote attacker to execute arbitrary code via crafted SWF content. CVE-2013-0648 Exploit Probability: 11.1% |
September 17, 2024 |
| Adobe Flash Player Incorrect Default Permissions Vulnerability |
Adobe Flash Player contains an incorrect default permissions vulnerability in the Firefox sandbox that allows a remote attacker to execute arbitrary code via crafted SWF content. CVE-2013-0643 Exploit Probability: 10.5% |
September 17, 2024 |
| Adobe Flash Player Integer Underflow Vulnerablity |
Adobe Flash Player contains an integer underflow vulnerability that allows a remote attacker to execute arbitrary code. CVE-2014-0497 Exploit Probability: 99.9% |
September 17, 2024 |
| Adobe Flash Player Double Free Vulnerablity |
Adobe Flash Player contains a double free vulnerability that allows a remote attacker to execute arbitrary code. CVE-2014-0502 Exploit Probability: 24.2% |
September 17, 2024 |
| Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) V |
Adobe Commerce and Magento Open Source contain an improper restriction of XML external entity reference (XXE) vulnerability that allows for remote code execution. CVE-2024-34102 Exploit Probability: 100.0% |
July 17, 2024 |
| Adobe ColdFusion Deserialization of Untrusted Data Vulnerability |
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution. CVE-2023-38203 Exploit Probability: 96.5% |
January 8, 2024 |
| Adobe ColdFusion Deserialization of Untrusted Data Vulnerability |
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution. CVE-2023-29300 Exploit Probability: 100.0% |
January 8, 2024 |
| Adobe Acrobat and Reader Use-After-Free Vulnerability |
Adobe Acrobat and Reader contains a use-after-free vulnerability that allows for code execution in the context of the current user. CVE-2023-21608 Exploit Probability: 61.5% |
October 10, 2023 |
| Adobe Acrobat and Reader Out-of-Bounds Write Vulnerability |
Adobe Acrobat and Reader contains an out-of-bounds write vulnerability that allows for code execution. CVE-2023-26369 Exploit Probability: 7.0% |
September 14, 2023 |
| Adobe ColdFusion Deserialization of Untrusted Data Vulnerability |
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could result in code execution in the context of the current user. CVE-2023-26359 Exploit Probability: 17.9% |
August 21, 2023 |
| Adobe ColdFusion Improper Access Control Vulnerability |
Adobe ColdFusion contains an improper access control vulnerability that allows for a security feature bypass. CVE-2023-29298 Exploit Probability: 99.8% |
July 20, 2023 |
| Adobe ColdFusion Improper Access Control Vulnerability |
Adobe ColdFusion contains an improper access control vulnerability that allows for a security feature bypass. CVE-2023-38205 Exploit Probability: 99.8% |
July 20, 2023 |
Of the known exploited vulnerabilities above, 13 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings. 5 known exploited Adobe vulnerabilities are in the top 5% (95th percentile or greater) of the EPSS exploit probability rankings.
Top 10 Riskiest Adobe Vulnerabilities
Based on the current exploit probability, these Adobe vulnerabilities are on CISA's Known Exploited vulnerabilities list (KEV) and are ranked by the current EPSS exploit probability.
| Rank | CVE | EPSS | Vulnerability |
|---|---|---|---|
| 1 | CVE-2024-34102 | 100.0% | Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) V |
| 2 | CVE-2023-29300 | 100.0% | Adobe ColdFusion Deserialization of Untrusted Data Vulnerability |
| 3 | CVE-2018-15961 | 100.0% | Adobe ColdFusion Remote Code Execution |
| 4 | CVE-2015-3113 | 99.9% | Adobe Flash Player Heap-Based Buffer Overflow Vulnerability |
| 5 | CVE-2014-0497 | 99.9% | Adobe Flash Player Integer Underflow Vulnerablity |
| 6 | CVE-2023-38205 | 99.8% | Adobe ColdFusion Improper Access Control Vulnerability |
| 7 | CVE-2023-29298 | 99.8% | Adobe ColdFusion Improper Access Control Vulnerability |
| 8 | CVE-2010-2861 | 99.7% | Adobe ColdFusion Directory Traversal Vulnerability |
| 9 | CVE-2015-5119 | 99.3% | Adobe Flash Player Use-After-Free Vulnerability |
| 10 | CVE-2022-24086 | 99.1% | Adobe Commerce and Magento Open Source Improper Input Validation Vulnerability |
By the Year
In 2026 there have been 510 vulnerabilities in Adobe with an average score of 6.9 out of ten. Last year, in 2025 Adobe had 817 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in Adobe in 2026 could surpass last years number. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.56.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 510 | 6.90 |
| 2025 | 817 | 6.34 |
| 2024 | 753 | 6.20 |
| 2023 | 668 | 6.35 |
| 2022 | 421 | 6.77 |
| 2021 | 323 | 6.73 |
| 2020 | 344 | 7.74 |
| 2019 | 324 | 6.72 |
| 2018 | 94 | 7.91 |
It may take a day or so for new Adobe vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Adobe Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-34641 | Jul 31, 2026 |
OOB Write in Premiere Pro 26.2.2 (Adobe) Arbitrary Code ExecPremiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. |
|
| CVE-2026-48449 | Jul 30, 2026 |
Adobe Campaign Classic ACC Incorrect Auth leads to RCE (Current User Context)Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. |
|
| CVE-2026-48448 | Jul 30, 2026 |
SQL Injection in Adobe Campaign Classic allows file system readAdobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to gain file system read access. Exploitation of this issue does not require user interaction. Scope is changed. |
|
| CVE-2026-48394 | Jul 28, 2026 |
Adobe Bridge OOB Write Enables Arbitrary Code ExecBridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. |
|
| CVE-2026-48374 | Jul 28, 2026 |
Adobe Bridge Path Traversal via Malicious FileBridge is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file. |
|
| CVE-2026-48391 | Jul 28, 2026 |
Adobe Bridge Untrusted Search Path CVE202648391Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. |
|
| CVE-2026-48392 | Jul 28, 2026 |
Adobe Bridge OOB Write VULN Enables Arbitrary Code ExecutionBridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. |
|
| CVE-2026-48390 | Jul 28, 2026 |
Adobe Bridge Improper Auth Priv Esc from Malicious FileBridge is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read and write access. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. |
|
| CVE-2026-48393 | Jul 28, 2026 |
Adobe Bridge OOB Write Arbitrary Code ExecBridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. |
|
| CVE-2026-48395 | Jul 28, 2026 |
Adobe Bridge Untrusted Search Path Vulnerability Enables Arbitrary Code ExecutionBridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. |
|
| CVE-2026-48396 | Jul 28, 2026 |
Adobe Bridge Incorrect Auth Arbitrary Code Exec (CVE-2026-48396)Bridge is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. |
|
| CVE-2026-48372 | Jul 28, 2026 |
Adobe Format Plugins Heap Buffer Overflow: Arbitrary Code ExecutionFormat Plugins is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. |
|
| CVE-2026-48388 | Jul 28, 2026 |
Adobe Photoshop Installer Uncontrolled Search Path Element CVE-2026-48388Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in the context of the current user. An attacker could have exploited this vulnerability by placing a malicious library in a directory searched by the installer. Exploitation of this issue required user interaction in that a victim must have been running the installer. Scope is changed. |
|
| CVE-2026-48389 | Jul 20, 2026 |
Adobe DNG SDK 1.7.1 and earlier Buffer Overflow (user interaction)DNG SDK versions 1.7.1 2536 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. |
|
| CVE-2026-48373 | Jul 17, 2026 |
Adobe Acrobat Reader: Heap Buffer Overflow -> Arbitrary Code ExecutionAcrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. |
|
| CVE-2026-48295 | Jul 14, 2026 |
Adobe CAI Content Credentials: Insufficient Credentials (CVE202648295)CAI Content Credentials is affected by an Insufficiently Protected Credentials vulnerability that could result in disclosure of sensitive information. An attacker could leverage this vulnerability to gain unauthorized read access. Exploitation of this issue does not require user interaction. |
|
| CVE-2026-48290 | Jul 14, 2026 |
SSRF in CAI Content Credentials Enables Arbitrary Code ExecCAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed. |
|
| CVE-2026-48357 | Jul 14, 2026 |
CAI Content Credentials Uncontrolled Resource Consumption DoSCAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user interaction. |
|
| CVE-2026-48296 | Jul 14, 2026 |
Integer Underflow in Adobe CAI Content Credentials Leads to DoSCAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction. |
|
| CVE-2026-48287 | Jul 14, 2026 |
Adobe CAI Content Credentials Untrusted Search Path (USP) RCECAI Content Credentials is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed. |
|
| CVE-2026-48312 | Jul 14, 2026 |
Adobe CAI Content Credentials: Improper Input Validation BypassCAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction. |
|
| CVE-2026-48351 | Jul 14, 2026 |
Adobe CAI Content Credentials Improper Input Validation: Denial-of-ServiceCAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction. |
|
| CVE-2026-48302 | Jul 14, 2026 |
CVE-2026-48302: CAI Content Credentials Improper Input Validation DoSCAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction. |
|
| CVE-2026-48354 | Jul 14, 2026 |
Adobe CAI Content Credentials Integer Overflow DoS VulnerabilityCAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction. |
|
| CVE-2026-48298 | Jul 14, 2026 |
Adobe CAI Content Credentials Integer Underflow DoSCAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction. |
|
| CVE-2026-48352 | Jul 14, 2026 |
Adobe CAI Content Credentials Improper Input Validation DoSCAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction. |
|
| CVE-2026-48353 | Jul 14, 2026 |
CAI Content Credentials Improper Input Validation File Read via Malicious FileCAI Content Credentials is affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file. |
|
| CVE-2026-48336 | Jul 14, 2026 |
Adobe Illustrator OOB write arbitrary code exec (CVE-2026-48336)Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. |
|
| CVE-2026-48335 | Jul 14, 2026 |
Illustrator OOB Write Leading to Arbitrary Code Exec via Malicious File (CVE202648335)Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. |
|
| CVE-2026-48337 | Jul 14, 2026 |
Adobe Illustrator OOB Write for Arbitrary Code ExecutionIllustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. |
|
| CVE-2026-48334 | Jul 14, 2026 |
Adobe Illustrator Improper Input Validation Allows Arbitrary Code ExecutionIllustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. |
|
| CVE-2026-48275 | Jul 14, 2026 |
Untrusted Search Path in Adobe Illustrator: Arbitrary Code Exec via Malicious FileIllustrator is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. |
|
| CVE-2026-48320 | Jul 14, 2026 |
Adobe ColdFusion Reflected XSS via Malicious File (CVE-2026-48320)ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. |
|
| CVE-2026-48324 | Jul 14, 2026 |
ColdFusion SQL Injection Leading to Arbitrary Code ExecutionColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed. |
|
| CVE-2026-48332 | Jul 14, 2026 |
ColdFusion SSRF Bypass Enabling Unauthorized Read Access (CVE202648332)ColdFusion is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed. |
|
| CVE-2026-48318 | Jul 14, 2026 |
Adobe ColdFusion Path Traversal: Arbitrary File ReadColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed. |
|
| CVE-2026-48338 | Jul 14, 2026 |
ColdFusion Path Traversal Allows Arbitrary File ReadColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed. |
|
| CVE-2026-48327 | Jul 14, 2026 |
Adobe ColdFusion Incorrect Auth Enables Arbitrary Code ExecColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. |
|
| CVE-2026-48329 | Jul 14, 2026 |
ColdFusion Insufficient Session Expiration Allows Security Feature BypassColdFusion is affected by an Insufficient Session Expiration vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction. |
|
| CVE-2026-48321 | Jul 14, 2026 |
Adobe ColdFusion Auth Bypass: Priv Escalation & R/W AccessColdFusion is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read and write access. Exploitation of this issue does not require user interaction. Scope is changed. |
|
| CVE-2026-48319 | Jul 14, 2026 |
Adobe ColdFusion Path Traversal Arbitrary Code Exec HotspotColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed. |
|
| CVE-2026-48322 | Jul 14, 2026 |
ColdFusion Improper Control of Code Generation - RCEColdFusion is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. |
|
| CVE-2026-48284 | Jul 14, 2026 |
Adobe ColdFusion Improper Input Validation Enables A/CExecutionColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. |
|
| CVE-2026-48328 | Jul 14, 2026 |
Improper Input Validation in CF Allows SFB & Unauthorized Read AccessColdFusion is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed. |
|
| CVE-2026-48325 | Jul 14, 2026 |
ColdFusion Auth Bypass Enables Arbitrary Code Exec (CVE-2026-48325)ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. |
|
| CVE-2026-48340 | Jul 14, 2026 |
Untrusted Pointer Deref. in Adobe Bridge Enables RCEBridge is affected by an Untrusted Pointer Dereference vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. |
|
| CVE-2026-48343 | Jul 14, 2026 |
Adobe Bridge OOB Write -> Arbitrary Code ExecutionBridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. |
|
| CVE-2026-48339 | Jul 14, 2026 |
Adobe Bridge Heap Buffer Overflow Enables User-Interactive Arbitrary ExecBridge is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. |
|
| CVE-2026-48311 | Jul 14, 2026 |
Adobe Bridge OOB Write Arbitrary Code Execution via Malicious FileBridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. |
|
| CVE-2026-48342 | Jul 14, 2026 |
Adobe Bridge: Integer Overflow Allows Code Exec via FileBridge is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. |
|