CVE-2016-4117Critical· 9.8▾ Hadal⚠ Exploited in the wildPoC availableAdobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016.
▾ Hadal zone — Critical and actively exploited (CISA KEV / 0day)
impact 53.9 · likelihood 18.9 · exploitation 25 · ransomware 5
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 3 sources. Availability, not in-the-wild use.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 10.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due Mar 24, 2022
Last analysed / modified upstream
94%
Exploit-DB · 1 GitHub repo · Metasploit ×1 (last check)
Added to the CISA catalog on Mar 3, 2022. Federal remediation due Mar 24, 2022. View catalog ↗
Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016.
flash_player <= 21.0.0.226enterprise_linux_desktop = 5.0enterprise_linux_desktop = 6.0enterprise_linux_server = 5.0enterprise_linux_server = 6.0enterprise_linux_server_from_rhui = 5.0enterprise_linux_server_from_rhui = 6.0enterprise_linux_workstation = 5.0enterprise_linux_workstation = 6.0evergreen = 11.4opensuse = 13.1opensuse = 13.2linux_enterprise_desktop = 12linux_enterprise_workstation_extension = 12Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2018-15982High· 7.8Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability
CVE-2011-0627High· 8.8Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.21 on Android allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content…
CVE-2026-84397Medium· 5.4Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields
CVE-2026-81975High· 7.8Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user
CVE-2026-79908High· 7.8Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user
CVE-2026-82001Medium· 5.5Acrobat Reader is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service