Skip to content

Data collected

CVEs Live

Adobe vulnerabilities exploited in the wild

The Adobe CVEs that CISA lists as exploited, newest first. Only confirmed exploitation appears here, each with its EPSS and the CVSS as published.

Build snapshot collected · KEV catalog 2026.10.02 · EPSS of 2 Oct 2026 · not a live feed: collected once, at build time

82
flaws with confirmed attacks
11
used by ransomware
4.7%
of the whole catalog

12 vulnerabilities · newest first.Showing the entries bundled with this page while the full catalog loads.

RSS of KEV additions
  1. CVE-2026-71362Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Adobe · Commerce and Magento

    Adobe Commerce and Magento Incorrect Authorization Vulnerability

    Severity

    9.1CRITICALCVSS 3.1 · adobe.com

    Attack probability (EPSS)

    87.5%99.8th pct

    KEV dates

    added due
  2. CVE-2026-75650Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Adobe · Commerce and Magento

    Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability

    Severity

    10.0CRITICALCVSS 3.1 · adobe.com

    Attack probability (EPSS)

    3.95%90th pct

    KEV dates

    added due
  3. CVE-2026-48282Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Adobe · ColdFusion

    Adobe ColdFusion Path Traversal Vulnerability

    Severity

    10.0CRITICALCVSS 3.1 · adobe.com

    Attack probability (EPSS)

    42.4%99th pct

    KEV dates

    added due
  4. CVE-2009-3459Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Adobe · Acrobat and Reader

    Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability

    Severity

    8.8HIGHCVSS 3.1 · CISA-ADP

    Attack probability (EPSS)

    86.6%99.7th pct

    KEV dates

    added due
  5. CVE-2020-9715Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Adobe · Acrobat

    Adobe Acrobat Use-After-Free Vulnerability

    Severity

    7.8HIGHCVSS 3.1 · NVD

    Attack probability (EPSS)

    48.6%99th pct

    KEV dates

    added due
  6. CVE-2026-34621Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Adobe · Acrobat and Reader

    Adobe Acrobat and Reader Prototype Pollution Vulnerability

    Severity

    8.6HIGHCVSS 3.1 · adobe.com

    Attack probability (EPSS)

    2.18%82th pct

    KEV dates

    added due
  7. CVE-2025-54236Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Adobe · Commerce and Magento

    Adobe Commerce and Magento Improper Input Validation Vulnerability

    Severity

    9.1CRITICALCVSS 3.1 · adobe.com

    Attack probability (EPSS)

    94.5%99.9th pct

    KEV dates

    added due
  8. CVE-2025-54253Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Adobe · Experience Manager (AEM) Forms

    Adobe Experience Manager Forms Code Execution Vulnerability

    Severity

    10.0CRITICALCVSS 3.1 · adobe.com

    Attack probability (EPSS)

    88.0%99.8th pct

    KEV dates

    added due
  9. CVE-2017-3066Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Adobe · ColdFusion

    Adobe ColdFusion Deserialization Vulnerability

    Severity

    9.8CRITICALCVSS 3.1 · NVD

    Attack probability (EPSS)

    90.6%99.8th pct

    KEV dates

    added due
  10. CVE-2024-20767Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Adobe · ColdFusion

    Adobe ColdFusion Improper Access Control Vulnerability

    Severity

    7.4HIGHCVSS 3.1 · adobe.com

    Attack probability (EPSS)

    98.5%99.9th pct

    KEV dates

    added due
  11. CVE-2014-0497Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Adobe · Flash Player

    Adobe Flash Player Integer Underflow Vulnerablity

    Severity

    9.8CRITICALCVSS 3.1 · NVD

    Attack probability (EPSS)

    99.9%100th pct

    KEV dates

    added due
  12. CVE-2014-0502Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Adobe · Flash Player

    Adobe Flash Player Double Free Vulnerablity

    Severity

    8.8HIGHCVSS 3.1 · NVD

    Attack probability (EPSS)

    24.8%98th pct

    KEV dates

    added due

Adobe products in the catalog

Among the most recent entries, the products that appear most often are:

  • ColdFusion3 entries
  • Commerce and Magento2 entries
  • Acrobat and Reader2 entries
  • Flash Player2 entries
  • Acrobat1 entry
  • Commerce and Magento1 entry
  • Experience Manager (AEM) Forms1 entry

Product names are the ones CISA uses in the catalog. To check a specific Adobe CVE that is not on this page, use the CVE lookup: it shows the record, the affected versions and the EPSS score even when the CVE is not in KEV.

Other vendors

Questions

How many Adobe vulnerabilities are known to be exploited?

The CISA KEV catalog, version 2026.10.02, lists 82 Adobe vulnerabilities as of 3 Oct 2026. CISA marks 11 of them as known to be used in ransomware campaigns.

What is the most recent Adobe entry in KEV?

CVE-2026-71362 (Adobe Commerce and Magento Incorrect Authorization Vulnerability), added on 24 Sep 2026 with a due date of 27 Sep 2026 for US federal agencies, as of the collection of 3 Oct 2026.

Does this page list every Adobe CVE?

No. It lists only the Adobe CVEs that CISA has confirmed as exploited. Adobe publishes many more CVEs that are not in KEV; look up any of them by identifier in the CVE lookup to see its record and EPSS score.

In what order should Adobe vulnerabilities be patched?

Everything on this page is already confirmed as exploited, so all of it is urgent where the product is in use. Within the list, entries marked with known ransomware use and those with the highest EPSS come first in the "Risk" order; internet-facing systems should go before internal ones.

Related sections