CVE-2016-1019Critical· 9.8▾ Hadal⚠ Exploited in the wild0dayAdobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as exploited in the wild in April 2016.
▾ Hadal zone — Critical and actively exploited (CISA KEV / 0day)
impact 53.9 · likelihood 4.5 · exploitation 25 · ransomware 5
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 14.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due Mar 24, 2022
Last analysed / modified upstream
22%
Added to the CISA catalog on Mar 3, 2022. Federal remediation due Mar 24, 2022. View catalog ↗
Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as exploited in the wild in April 2016.
flash_player_desktop_runtime <= 21.0.0.197flash_player <= 18.0.0.333flash_player <= 21.0.0.197flash_player <= 11.2.202.577air_desktop_runtime <= 21.0.0.176air_sdk <= 21.0.0.176air_sdk_&_compiler <= 21.0.0.176Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-84397Medium· 5.4Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields
CVE-2026-81975High· 7.8Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user
CVE-2026-79908High· 7.8Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user
CVE-2026-82001Medium· 5.5Acrobat Reader is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service
CVE-2026-81997Medium· 6.3Acrobat Reader is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass
CVE-2026-81996High· 8.8Acrobat Reader is affected by an Incorrect Authorization vulnerability that could result in privilege escalation