Vendor
Adobe vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 658 vulnerabilities in Adobe: 53 in the last 7 days and 297 in the last 90 days, 148 of them critical and 83 exploited in the wild. The most recent, CVE-2026-89277, was published on 22 September 2026. 57 technologies have a page of their own.
- Last 7 days
- 53
- Last 90 days
- 297
- Critical, all time
- 148
- Exploited in the wild
- 83
About Adobe
Software company that develops creative, document, and marketing cloud applications.
Adobe technologies
- Adobe ColdFusion70
- Adobe Acrobat63
- Adobe Commerce62
- Adobe Acrobat Reader60
- Adobe Flash Player56
- Adobe AIR55
- Adobe Acrobat DC39
- Adobe Acrobat Reader DC37
- Adobe Reader32
- Adobe Magento Open Source24
- Adobe Bridge23
- Adobe Illustrator23
- Adobe Substance 3D Designer23
- Adobe InDesign22
- Adobe Magento Enterprise Edition22
- Adobe Substance 3D Painter21
- Adobe After Effects20
- Adobe C2pa20
- Adobe C2pa-Web19
- Adobe Substance3D Designer17
- Adobe Substance 3D Sampler16
- Adobe Substance3D Painter15
- Adobe DNG SDK14
- Adobe Commerce B2B13
- Adobe Commerce Webhooks Plugin13
- Adobe Content Credentials SDK13
- Adobe Substance 3d Stager13
- Adobe Substance3D Sampler13
- Adobe Substance3D Stager13
- Adobe Audition12
- Adobe Campaign Classic12
- Adobe Content Credentials Command-Line Tool12
- Adobe Content Credentials JS SDK12
- Adobe Content Credentials Rust SDK12
- Adobe Experience Manager as a Cloud Service12
- Adobe FrameMaker12
- Adobe C2pa-Rs11
- Adobe Substance 3d Modeler11
- Adobe Connect For Mobile9
- Adobe Dreamweaver9
- Adobe Lightroom9
- Adobe Lightroom Classic9
- Adobe Premiere Pro9
- Adobe Dng Software Development Kit8
- Adobe Photoshop Desktop8
- Adobe Animate7
- Adobe Media Encoder7
- Adobe Substance3D Modeler7
- Adobe C2pa-Rust6
- Adobe C2patool6
- Adobe InCopy5
- Adobe Magento4
- Adobe Content Authenticity SDK (c2pa-web)3
- Adobe Content Credentials3
- Adobe Experience Manager Forms JEE3
- Adobe Experience Manager Screens3
- Adobe Format Plugins3
Latest Adobe vulnerabilities
- CVE-2026-89277: Adobe Content Credentials integer overflow denial of servicemediumCVSS 5.5EPSS 0.3%
- CVE-2026-84396: Adobe InDesign Desktop NULL pointer dereferencemediumCVSS 5.5EPSS 0.1%
- CVE-2026-84395: Adobe Premiere Pro server-side request forgery vulnerabilityhighCVSS 7.1EPSS 0.3%
- CVE-2026-83964: Adobe Connect improper certificate validationmediumCVSS 6.2EPSS 0.1%
- CVE-2026-83963: Adobe Substance3D Modeler out-of-bounds writehighCVSS 7.8EPSS 0.1%
- CVE-2026-83962: Adobe Substance3D Modeler stack buffer overflowhighCVSS 7.8EPSS 0.2%
- CVE-2026-82000: Adobe Experience Manager Forms JEE server-side request forgerycriticalCVSS 9.6EPSS 0.7%
- CVE-2026-81999: Adobe Experience Manager Forms JEE server-side request forgeryhighCVSS 8.7EPSS 0.8%
- CVE-2026-81998: Adobe Substance3D Modeler out-of-bounds writehighCVSS 7.8EPSS 0.1%
- CVE-2026-81995: Adobe Experience Manager Forms JEE arbitrary code executioncriticalCVSS 9.1EPSS 1.2%
- CVE-2026-79906: Adobe Substance3D Modeler out-of-bounds writehighCVSS 7.8EPSS 0.1%
- CVE-2026-76194: Adobe CAI Content Credentials input validation bypassmediumCVSS 4.3EPSS 1.0%
- CVE-2026-76192: Adobe InDesign Desktop null pointer dereferencemediumCVSS 5.5EPSS 0.2%
- CVE-2026-75745: Adobe Experience Manager Forms JEE authorization bypasscriticalCVSS 10EPSS 1.2%
- CVE-2026-75744: Adobe Experience Manager Forms JEE stored XSS in form fieldshighCVSS 8.1EPSS 1.2%
- CVE-2026-75743: Adobe Experience Manager Forms JEE cross-site request forgeryhighCVSS 7.1EPSS 1.5%
- CVE-2026-75698: Adobe Connect reflected Cross-Site Scripting in web pagecriticalCVSS 9.3EPSS 0.3%
- CVE-2026-75697: Adobe Connect stored cross-site scripting in form fieldscriticalCVSS 9.3EPSS 0.3%
- CVE-2026-75689: Adobe Connect stored cross-site scriptingcriticalCVSS 9.3EPSS 0.3%
- CVE-2026-75686: Adobe Connect improper input validation vulnerabilitycriticalCVSS 9.3EPSS 1.1%
- CVE-2026-75684: Adobe Connect stored Cross-Site Scripting vulnerabilitycriticalCVSS 9.3EPSS 0.3%
- CVE-2026-75682: Adobe Connect SQL injection leading to arbitrary code executioncriticalCVSS 9.9EPSS 0.5%
- CVE-2026-75676: Adobe Bridge stack-based buffer overflowhighCVSS 7.8EPSS 0.2%
- CVE-2026-75665: Adobe Bridge heap-based buffer overflowhighCVSS 7.8EPSS 0.2%
- CVE-2026-75663: Adobe Bridge out-of-bounds write in file handlinghighCVSS 7.8EPSS 0.2%
Most severe Adobe vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2008-4250: Microsoft Windows buffer overflow in Server servicecriticalexploited in the wildCVSS 10EPSS 93.5%
- CVE-2025-54253: Adobe Experience Manager Forms remote code executioncriticalexploited in the wildCVSS 10EPSS 19.7%
- CVE-2026-75650: Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that…criticalexploited in the wildCVSS 10EPSS 4.0%
- CVE-2026-48282: Adobe ColdFusion path traversal in multiple versionscriticalexploited in the wildCVSS 10EPSS 1.0%
- CVE-2014-8439: Adobe Flash Player Dereferenced Pointer Vulnerabilitycriticalexploited in the wildCVSS 10
- CVE-2014-9163: Adobe Flash Player Stack-Based Buffer Overflow Vulnerabilitycriticalexploited in the wildCVSS 10
- CVE-2017-3066: Adobe ColdFusion Deserialization Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2014-0497: Adobe Flash Player Integer Underflow Vulnerablitycriticalexploited in the wildCVSS 9.8
- CVE-2024-34102: Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2023-29300: Adobe ColdFusion Deserialization of Untrusted Data Vulnerabilitycriticalexploited in the wildCVSS 9.8
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 11 | 8 | |
| 6 Jul 2026 | 2 | 1 | |
| 13 Jul 2026 | 91 | 13 | |
| 20 Jul 2026 | 1 | 0 | |
| 27 Jul 2026 | 13 | 1 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 22 | 4 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 41 | 3 | |
| 31 Aug 2026 | 2 | 0 | |
| 7 Sep 2026 | 61 | 6 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 53 | 25 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/adobe.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Adobe vulnerabilities", https://junglewise.ai/threats/vendors/adobe, 26 September 2026.