Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Adobe Acrobat contains a use-after-free vulnerability that allows for code execution Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Adobe Acrobat and Reader contain a prototype pollution vulnerability that allows for arbitrary code execution. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Adobe Experience Manager Forms in JEE contains an unspecified vulnerability that allows for arbitrary code execution. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVE-2025-54253EPSS 87.5%AdobeExperience Manager (AEM) Forms
Adobe ColdFusion contains a deserialization vulnerability in the Apache BlazeDS library that allows for arbitrary code execution. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Adobe ColdFusion contains an improper access control vulnerability that could allow an attacker to access or modify restricted files via an internet-exposed admin panel. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Adobe Flash Player contains a double free vulnerability that allows a remote attacker to execute arbitrary code. Required action: The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.
Adobe Flash Player contains an unspecified vulnerability in the ExternalInterface ActionScript functionality that allows a remote attacker to execute arbitrary code via crafted SWF content. Required action: The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.
Adobe Flash Player contains an incorrect default permissions vulnerability in the Firefox sandbox that allows a remote attacker to execute arbitrary code via crafted SWF content. Required action: The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.
Adobe Flash Player contains an integer underflow vulnerability that allows a remote attacker to execute arbitrary code. Required action: The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.
Adobe Commerce and Magento Open Source contain an improper restriction of XML external entity reference (XXE) vulnerability that allows for remote code execution. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVE-2024-34102EPSS 100.0%AdobeCommerce and Magento Open Source
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Adobe Acrobat and Reader contains a use-after-free vulnerability that allows for code execution in the context of the current user. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Adobe Acrobat and Reader contains an out-of-bounds write vulnerability that allows for code execution. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could result in code execution in the context of the current user. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Adobe ColdFusion contains an improper access control vulnerability that allows for a security feature bypass. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Adobe ColdFusion contains an improper access control vulnerability that allows for a security feature bypass. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for remote code execution. Required action: Apply updates per vendor instructions.
Adobe Acrobat and Reader have a double free vulnerability that could lead to remote code execution. Required action: Apply updates per vendor instructions.
Adobe Flash Player contains an integer overflow vulnerability that allows remote attackers to execute code via malformed arguments. Required action: The impacted product is end-of-life and should be disconnected if still in use.
Adobe Flash Player contains a XSS vulnerability that allows remote attackers to inject web script or HTML. Required action: The impacted product is end-of-life and should be disconnected if still in use.
Adobe Flash Player contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS). Required action: The impacted product is end-of-life and should be disconnected if still in use.
The Universal 3D (U3D) component in Adobe Reader and Acrobat contains a memory corruption vulnerability which could allow remote attackers to execute code or cause denial-of-service (DoS). Required action: Apply updates per vendor instructions.
Adobe Flash Player contains an unspecified vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS). Required action: The impacted product is end-of-life and should be disconnected if still in use.
Adobe Acrobat and Reader contain a stack-based buffer overflow vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS). Required action: Apply updates per vendor instructions.
Adobe Flash Player contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS). Required action: The impacted product is end-of-life and should be disconnected if still in use.
Use-after-free vulnerability in Adobe Acrobat and Reader allows remote attackers to execute code via a crafted PDF file. Required action: Apply updates per vendor instructions.
Adobe Acrobat and Reader contains an array boundary issue in Universal 3D (U3D) support that could lead to remote code execution. Required action: Apply updates per vendor instructions.
Adobe Acrobat and Reader and Adobe Flash Player allows remote attackers to execute code or cause denial-of-service (DoS). Required action: For Adobe Acrobat and Reader, apply updates per vendor instructions. For Adobe Flash Player, the impacted product is end-of-life and should be disconnected if still in use.
CVE-2009-1862EPSS 25.0%Acrobat and Reader, Flash PlayerAdobe
Adobe Acrobat and Reader contains an unespecified vulnerability described as a design flaw which could allow a specially crafted file to be printed silently an arbitrary number of times. Required action: Apply updates per vendor instructions.
Adobe Acrobat and Reader contain a buffer overflow vulnerability that allows remote attackers to execute code via a PDF file with long arguments to unspecified JavaScript methods. Required action: Apply updates per vendor instructions.
Integer overflow vulnerability in Adobe Flash Player and AIR allows attackers to execute code. Required action: The impacted products are end-of-life and should be disconnected if still in use.
Use-after-free vulnerability in Adobe Flash Player and Adobe AIR allows attackers to execute code. Required action: The impacted products are end-of-life and should be disconnected if still in use.
Adobe Flash Player does not properly restrict discovery of memory addresses, which allows attackers to bypass the address space layout randomization (ASLR) protection mechanism. Required action: The impacted product is end-of-life and should be disconnected if still in use.
Integer overflow in Adobe Flash Player allows attackers to execute code. Required action: The impacted product is end-of-life and should be disconnected if still in use.
Adobe Flash Player has a vulnerability in the way it handles a dereferenced memory pointer which could lead to code execution. Required action: The impacted product is end-of-life and should be disconnected if still in use.
Adobe Reader and Acrobat on Windows allow attackers to bypass a sandbox protection mechanism, and consequently execute native code in a privileged context. Required action: Apply updates per vendor instructions.
Adobe Flash Player have a stack-based buffer overflow vulnerability that could lead to remote code execution. Required action: The impacted product is end-of-life and should be disconnected if still in use.
Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS). Required action: The impacted product is end-of-life and should be disconnected if still in use.
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS). Required action: The impacted product is end-of-life and should be disconnected if still in use.
Heap-based buffer overflow vulnerability in Adobe Flash Player allows remote attackers to execute code. Required action: The impacted product is end-of-life and should be disconnected if still in use.
Use-after-free vulnerability in Adobe Flash Player allows remote attackers to execute code. Required action: The impacted product is end-of-life and should be disconnected if still in use.
Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute code. Required action: The impacted product is end-of-life and should be disconnected if still in use.
Stack-based buffer overflow in Adobe Flash Player allows attackers to execute code remotely. Required action: The impacted product is end-of-life and should be disconnected if still in use.
Adobe Flash Player contains a memory corruption vulnerability that allows for remote code execution or denial-of-service (DoS). Required action: The impacted product is end-of-life and should be disconnected if still in use.
Adobe Flash Player has an exploitable use-after-free vulnerability in the TextField class. Required action: The impacted product is end-of-life and should be disconnected if still in use.
Unspecified vulnerability in Adobe Flash Player allows for remote code execution. Required action: The impacted product is end-of-life and should be disconnected if still in use.
A directory traversal vulnerability exists in the administrator console in Adobe ColdFusion which allows remote attackers to read arbitrary files. Required action: Apply updates per vendor instructions.
Adobe Coldfusion contains an unspecified vulnerability, which could result in information disclosure from a compromised server. Required action: Apply updates per vendor instructions.
Adobe Coldfusion contains a directory traversal vulnerability, which could permit an unauthorized user access to restricted directories. Required action: Apply updates per vendor instructions.
Adobe Coldfusion contains an authentication bypass vulnerability, which could result in an unauthorized user gaining administrative access. Required action: Apply updates per vendor instructions.
Adobe BlazeDS, which is utilized in LifeCycle and Coldfusion, contains a vulnerability that allows for information disclosure. Required action: Apply updates per vendor instructions.
Adobe Flash Player contains a type confusion vulnerability which can allow for remote code execution. Required action: The impacted product is end-of-life and should be disconnected if still in use.
Use-after-free vulnerability in Adobe Flash Player Windows and OS and Linux allows remote attackers to execute arbitrary code. Required action: The impacted product is end-of-life and should be disconnected if still in use.
An access of resource using incompatible type vulnerability exists within Adobe Flash Player that allows an attacker to perform remote code execution. Required action: The impacted product is end-of-life and should be disconnected if still in use.
Adobe Flash Player allows remote attackers to cause a denial of service or possibly execute arbitrary code. Required action: The impacted product is end-of-life and should be disconnected if still in use.
Adobe Flash Player allows remote attackers to execute arbitrary code via a crafted SWF file. Required action: The impacted product is end-of-life and should be disconnected if still in use.
A use-after-free vulnerability exists within the ActionScript 3 ByteArray class in Adobe Flash Player that allows an attacker to perform remote code execution. Required action: The impacted product is end-of-life and should be disconnected if still in use.
A memory corruption vulnerability exists in Adobe Flash Player that allows an attacker to perform remote code execution. Required action: The impacted product is end-of-life and should be disconnected if still in use.
Adobe Reader and Acrobat contain a use-after-free vulnerability which can allow for code execution. Required action: Apply updates per vendor instructions.
Adobe Reader and Acrobat contain a memory corruption vulnerability which can allow attackers to execute arbitrary code or cause a denial of service. Required action: Apply updates per vendor instructions.
A buffer overflow vulnerability exists in Adobe Reader which allows an attacker to perform remote code execution. Required action: Apply updates per vendor instructions.
An memory corruption vulnerability exists in the acroform.dll in Adobe Reader that allows an attacker to perform remote code execution. Required action: Apply updates per vendor instructions.
An authentication bypass vulnerability exists in Adobe ColdFusion which could result in an unauthorized user gaining administrative access. Required action: Apply updates per vendor instructions.
Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute arbitrary code or cause a denial of service via crafted SWF content. Required action: The impacted product is end-of-life and should be disconnected if still in use.
Adobe Flash Player contains a vulnerability that allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content. Required action: The impacted product is end-of-life and should be disconnected if still in use.
Unspecified vulnerability in Adobe Reader and Acrobat allows attackers to cause a denial of service or possibly execute arbitrary code. Required action: Apply updates per vendor instructions.
Adobe Acrobat and Reader contain an input validation issue in a JavaScript method that could potentially lead to remote code execution. Required action: Apply updates per vendor instructions.
Adobe Commerce and Magento Open Source contain an improper input validation vulnerability which can allow for arbitrary code execution. Required action: Apply updates per vendor instructions.
CVE-2022-24086EPSS 99.2%AdobeCommerce and Magento Open Source
Adobe Flash Player com.adobe.tvsdk.mediacore.metadata Use After Free Vulnerability Required action: The impacted product is end-of-life and should be disconnected if still in use.
Acrobat Acrobat and Reader contain a heap-based buffer overflow vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user. Required action: Apply updates per vendor instructions.
Adobe Acrobat and Reader contains a use-after-free vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user. Required action: Apply updates per vendor instructions.
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could allow for code execution. Required action: Apply updates per vendor instructions.
Adobe ColdFusion contains an unrestricted file upload vulnerability that could allow for code execution. Required action: Apply updates per vendor instructions.
Adobe Flash Player contains a use-after-free vulnerability that could allow for code execution. Required action: The impacted product is end-of-life and should be disconnected if still in use.