VulnSea

Adobe has 509 CVEs on record between 2010 and 2026. Disclosure cadence is accelerating: 251 in the last 90 days against 72 in the 90 before. The busiest recent month was September 2026 with 224. The median CVSS is 6.2 (medium), with 52 rated critical. 2% have been exploited in the wild, in line with the corpus average. The median gap from publication to a KEV listing is 2139 days (8 cases). The dominant weakness classes are CWE-79 (198) and CWE-787 (55). Most affected products: experience_manager (185), acrobat (37), coldfusion (32).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
2% vs 1% corpus
Median CVSS
6.2
Publish → KEV
2139 d median(8)
Last 90 days
251 prev 72

Products

  • experience_manager 185
  • acrobat 37
  • coldfusion 32
  • commerce 28
  • campaign 22
  • after_effects 18
509
Total CVEs
52
Critical
8
CISA KEV
9
Exploited

Adobe vulnerabilities

CVEs affecting Adobe, newest first. Open any entry for full detail, references, and exploit status.

509 CVEsRSS

CVE-2026-79906High· 7.8
5d ago

Substance3D - Modeler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user

Substance3D - Modeler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

▾ Twilightadobe · substance_3d_modelerEPSS 0.14%via NVD
CVE-2026-75744High· 8.1
5d ago

Adobe Experience Manager Forms JEE is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields

Adobe Experience Manager Forms JEE is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be e…

▾ TwilightAdobe · AEM 6.5 Forms JEEEPSS 1.2%via NVD
CVE-2026-83962High· 7.8
5d ago

Substance3D - Modeler is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user

Substance3D - Modeler is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must…

▾ Twilightadobe · substance_3d_modelerEPSS 0.17%via NVD
CVE-2026-81998High· 7.8
5d ago

Substance3D - Modeler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user

Substance3D - Modeler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

▾ Twilightadobe · substance_3d_modelerEPSS 0.14%via NVD
CVE-2026-75745Critical· 10.0
5d ago

Adobe Experience Manager Forms JEE is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user

Adobe Experience Manager Forms JEE is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrar…

▾ MidnightAdobe · AEM 6.5 Forms JEEEPSS 1.2%via NVD
CVE-2026-83963High· 7.8
5d ago

Substance3D - Modeler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user

Substance3D - Modeler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

▾ Twilightadobe · substance_3d_modelerEPSS 0.14%via NVD
CVE-2026-89275Critical· 10.0
5d ago

Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user

Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulne…

▾ Midnightadobe · campaignEPSS 1.2%via NVD
CVE-2026-82010Critical· 9.9
5d ago

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-pri…

▾ Midnightadobe · campaignEPSS 0.97%via NVD
CVE-2026-82011Critical· 9.1
5d ago

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in a Security feature bypass

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage th…

▾ Midnightadobe · campaignEPSS 0.55%via NVD
CVE-2026-82008Critical· 9.9
5d ago

Adobe Campaign Classic (ACC) is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user

Adobe Campaign Classic (ACC) is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execut…

▾ Midnightadobe · campaignEPSS 0.53%via NVD
CVE-2026-75728Critical· 9.1
5d ago

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code…

▾ Midnightadobe · campaignEPSS 1.0%via NVD
CVE-2026-82443Critical· 9.6
5d ago

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access to internal reso…

▾ Midnightadobe · campaignEPSS 0.35%via NVD
CVE-2026-75699Critical· 10.0
5d ago

Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user

Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulne…

▾ Midnightadobe · campaignEPSS 1.2%via NVD
CVE-2026-75723Critical· 10.0
5d ago

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code…

▾ Midnightadobe · campaignEPSS 1.2%via NVD
CVE-2026-75721Critical· 10.0
5d ago

Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user

Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulne…

▾ Midnightadobe · campaignEPSS 1.2%via NVD
CVE-2026-73369Critical· 10.0
5d ago

Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user

Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulne…

▾ Midnightadobe · campaignEPSS 1.2%via NVD
CVE-2026-82013Critical· 9.9
5d ago

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access to internal reso…

▾ Midnightadobe · campaignEPSS 0.82%via NVD
CVE-2026-82009Critical· 9.1
5d ago

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attack…

▾ Midnightadobe · campaignEPSS 0.99%via NVD
CVE-2026-82003High· 8.5
5d ago

Adobe Campaign Classic (ACC) is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user

Adobe Campaign Classic (ACC) is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execut…

▾ Twilightadobe · campaignEPSS 0.46%via NVD
CVE-2026-84412Critical· 10.0
5d ago

Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user

Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulne…

▾ Midnightadobe · campaignEPSS 1.2%via NVD
CVE-2026-83660Critical· 9.9
5d ago

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed.

▾ Midnightadobe · campaignEPSS 0.34%via NVD
CVE-2026-89276Critical· 9.9
5d ago

Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user

Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could expl…

▾ Midnightadobe · campaignEPSS 0.53%via NVD
CVE-2026-75703Critical· 10.0
5d ago

Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user

Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulne…

▾ Midnightadobe · campaignEPSS 1.2%via NVD
CVE-2026-84397Medium· 5.4
1w ago

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in …

▾ SunlitAdobe · Adobe Experience Manager as a Cloud ServiceEPSS 0.63%via NVD
CVE-2026-81975High· 7.8
2w ago

Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user

Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

▾ Twilightadobe · acrobatEPSS 0.38%via NVD
CVE-2026-79908High· 7.8
2w ago

Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user

Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malici…

▾ Twilightadobe · acrobatEPSS 0.26%via NVD
CVE-2026-82001Medium· 5.5
2w ago

Acrobat Reader is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service

Acrobat Reader is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application deni…

▾ Sunlitadobe · acrobatEPSS 0.23%via NVD
CVE-2026-81997Medium· 6.3
2w ago

Acrobat Reader is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass

Acrobat Reader is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploita…

▾ Sunlitadobe · acrobatEPSS 0.24%via NVD
CVE-2026-81996High· 8.8
2w ago

Acrobat Reader is affected by an Incorrect Authorization vulnerability that could result in privilege escalation

Acrobat Reader is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access. Exploitation of this issue does not req…

▾ Twilightadobe · acrobatEPSS 0.24%via NVD
CVE-2026-81994High· 8.2
2w ago

Acrobat Reader is affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could lead to arbitrary file system read

Acrobat Reader is affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to acces…

▾ Twilightadobe · acrobatEPSS 0.60%via NVD
Adobe vulnerabilities (CVEs) — page 2 · VulnSea