Exploited CVEs / By vendor / Adobe

Adobe vulnerabilities actively exploited

80 Adobe CVEs on the CISA Known Exploited Vulnerabilities catalog, newest first. Refreshed daily.

Every CVE below is confirmed exploited in the wild, not just theoretically severe. The newest addition is CVE-2026-48282 (ColdFusion, added 2026-07-07). 10 of the 80 are used in ransomware campaigns. New CISA KEV entries appear here the day they are cataloged; the freshest across all vendors are on exploited this week.

80 exploited CVEs10 ransomware-linked
Senserva AI Opinion and rich prompt for Adobe exploited CVEs

Copy this prompt into Claude, ChatGPT, or Copilot. The facts are included, sourced from this page.

Flash Player: 33 exploited CVEs

CVEProductAdded to KEVSignals
CVE-2013-0643Flash Player2024-09-17CVSS 8.8, EPSS 11%
CVE-2013-0648Flash Player2024-09-17CVSS 8.8, EPSS 11%
CVE-2014-0497Flash Player2024-09-17CVSS 9.8, EPSS 100%
CVE-2014-0502Flash Player2024-09-17CVSS 8.8, EPSS 24%
CVE-2010-1297Flash Player2022-06-08CVSS 7.8, EPSS 82%
CVE-2011-0609Flash Player2022-06-08CVSS 7.8, EPSS 67%
CVE-2012-0754Flash Player2022-06-08CVSS 8.1, EPSS 92%
CVE-2012-0767Flash Player2022-06-08CVSS 6.1, EPSS 7%
CVE-2012-5054Flash Player2022-06-08CVSS 8.8, EPSS 21%
CVE-2014-8439Flash Player2022-05-25CVSS 8.8, EPSS 20%
CVE-2015-0310Flash Player2022-05-25CVSS 7.8, EPSS 15%
CVE-2015-8651Flash Player2022-05-25CVSS 8.8, EPSS 68%
CVE-2018-5002Flash Player2022-05-23CVSS 7.8, EPSS 25%
CVE-2014-9163Flash Player2022-04-13CVSS 7.8, EPSS 20%
CVE-2015-0311Flash Player2022-04-13CVSS 9.8, EPSS 86%
CVE-2015-0313Flash Player2022-04-13CVSS 9.8, EPSS 96%
CVE-2015-3113Flash Player2022-04-13CVSS 9.8, EPSS 100%
CVE-2015-5122Flash Player2022-04-13CVSS 9.8, EPSS 94%
CVE-2015-5123Flash Player2022-04-13CVSS 9.8, EPSS 18%
CVE-2012-2034Flash Player2022-03-28CVSS 7.5, EPSS 8%
CVE-2016-4171Flash Player2022-03-25CVSS 9.8, EPSS 20%
CVE-2016-7892Flash Player2022-03-25CVSS 8.8, EPSS 19%
CVE-2011-0611Flash Player2022-03-03CVSS 8.8, EPSS 94%
CVE-2012-1535Flash Player2022-03-03CVSS 7.8, EPSS 70%
CVE-2015-3043Flash Player2022-03-03CVSS 9.8, EPSS 74%
CVE-2015-5119Flash Player2022-03-03CVSS 9.8, EPSS 99%
CVE-2015-7645Flash Player2022-03-03ransomware, CVSS 7.8, EPSS 68%
CVE-2016-1019Flash Player2022-03-03ransomware, CVSS 9.8, EPSS 22%
CVE-2016-4117Flash Player2022-03-03CVSS 9.8, EPSS 94%
CVE-2016-7855Flash Player2022-03-03CVSS 8.8, EPSS 25%
CVE-2017-11292Flash Player2022-03-03CVSS 8.8, EPSS 12%
CVE-2018-15982Flash Player2022-02-15ransomware, CVSS 7.8, EPSS 82%
CVE-2018-4878Flash Player2021-11-03ransomware, CVSS 7.8, EPSS 90%

ColdFusion: 16 exploited CVEs

CVEProductAdded to KEVSignals
CVE-2026-48282ColdFusion2026-07-07CVSS 10.0, EPSS 99%
CVE-2017-3066ColdFusion2025-02-24CVSS 9.8, EPSS 91%
CVE-2024-20767ColdFusion2024-12-16CVSS 7.4, EPSS 99%
CVE-2023-29300ColdFusion2024-01-08ransomware, CVSS 9.8, EPSS 100%
CVE-2023-38203ColdFusion2024-01-08ransomware, CVSS 9.8, EPSS 97%
CVE-2023-26359ColdFusion2023-08-21CVSS 9.8, EPSS 18%
CVE-2023-29298ColdFusion2023-07-20CVSS 7.5, EPSS 100%
CVE-2023-38205ColdFusion2023-07-20CVSS 7.5, EPSS 100%
CVE-2023-26360ColdFusion2023-03-15CVSS 8.6, EPSS 97%
CVE-2010-2861ColdFusion2022-03-25ransomware, CVSS 9.8, EPSS 100%
CVE-2013-0625ColdFusion2022-03-07CVSS 9.8, EPSS 94%
CVE-2013-0629ColdFusion2022-03-07CVSS 7.5, EPSS 66%
CVE-2013-0631ColdFusion2022-03-07CVSS 7.5, EPSS 66%
CVE-2013-0632ColdFusion2022-03-03CVSS 9.8, EPSS 94%
CVE-2018-15961ColdFusion2021-11-03CVSS 9.8, EPSS 100%
CVE-2018-4939ColdFusion2021-11-03CVSS 9.8, EPSS 63%

Acrobat and Reader: 13 exploited CVEs

CVEProductAdded to KEVSignals
CVE-2009-3459Acrobat and Reader2026-05-20CVSS 8.8, EPSS 87%
CVE-2026-34621Acrobat and Reader2026-04-13CVSS 8.6, EPSS 7%
CVE-2023-21608Acrobat and Reader2023-10-10CVSS 7.8, EPSS 61%
CVE-2023-26369Acrobat and Reader2023-09-14CVSS 7.8, EPSS 7%
CVE-2007-5659Acrobat and Reader2022-06-08CVSS 7.8, EPSS 94%
CVE-2008-0655Acrobat and Reader2022-06-08CVSS 8.8, EPSS 37%
CVE-2009-3953Acrobat and Reader2022-06-08CVSS 8.8, EPSS 84%
CVE-2009-4324Acrobat and Reader2022-06-08CVSS 7.8, EPSS 82%
CVE-2010-2883Acrobat and Reader2022-06-08CVSS 7.3, EPSS 82%
CVE-2018-4990Acrobat and Reader2022-06-08CVSS 8.8, EPSS 37%
CVE-2008-2992Acrobat and Reader2022-03-03ransomware, CVSS 7.8, EPSS 98%
CVE-2021-21017Acrobat and Reader2021-11-03CVSS 8.8, EPSS 86%
CVE-2021-28550Acrobat and Reader2021-11-03CVSS 8.8, EPSS 52%

Reader and Acrobat: 8 exploited CVEs

CVEProductAdded to KEVSignals
CVE-2011-2462Reader and Acrobat2022-06-08CVSS 9.8, EPSS 87%
CVE-2014-0546Reader and Acrobat2022-05-25CVSS 9.8, EPSS 22%
CVE-2013-2729Reader and Acrobat2022-03-28CVSS 9.8, EPSS 67%
CVE-2009-0927Reader and Acrobat2022-03-25CVSS 8.8, EPSS 97%
CVE-2010-0188Reader and Acrobat2022-03-03ransomware, CVSS 7.8, EPSS 88%
CVE-2013-0640Reader and Acrobat2022-03-03CVSS 7.8, EPSS 87%
CVE-2013-3346Reader and Acrobat2022-03-03CVSS 9.8, EPSS 79%
CVE-2014-0496Reader and Acrobat2022-03-03CVSS 8.8, EPSS 40%

Other Adobe products

CVEProductAdded to KEVSignals
CVE-2020-9715Acrobat2026-04-13CVSS 7.8, EPSS 48%
CVE-2025-54236Commerce and Magento2025-10-24CVSS 9.1, EPSS 95%
CVE-2025-54253Experience Manager (AEM) Forms2025-10-15CVSS 10.0, EPSS 88%
CVE-2024-34102Commerce and Magento Open Source2024-07-17CVSS 9.8, EPSS 100%
CVE-2009-1862Acrobat and Reader, Flash Player2022-06-08CVSS 7.8, EPSS 25%
CVE-2016-0984Flash Player and AIR2022-05-25CVSS 8.8, EPSS 55%
CVE-2016-1010Flash Player and AIR2022-05-25CVSS 8.8, EPSS 20%
CVE-2009-3960BlazeDS2022-03-07ransomware, CVSS 6.5, EPSS 90%
CVE-2013-0641Reader2022-03-03CVSS 7.8, EPSS 32%
CVE-2022-24086Commerce and Magento Open Source2022-02-15CVSS 9.8, EPSS 99%

Common questions about exploited Adobe CVEs

Which Adobe vulnerabilities are actively exploited?

As of August 2026, 80 Adobe CVEs are on the CISA Known Exploited Vulnerabilities catalog, meaning exploitation in the wild is confirmed. The most-listed products are Flash Player (33), ColdFusion (16), Acrobat and Reader (13), Reader and Acrobat (8). 10 are linked to ransomware campaigns.

What is the newest exploited Adobe CVE?

CVE-2026-48282, affecting ColdFusion, added to the CISA KEV catalog on 2026-07-07. This page refreshes daily, so the newest entry is always first in the table.

How urgent are these Adobe CVEs?

KEV listing is the strongest fix-first signal there is: it means confirmed exploitation, not a prediction. Patch these ahead of higher-CVSS issues that nobody is exploiting. Check the vendor advisory (linked below) for fixed versions and workarounds.

Can I ask my own AI about exploited Adobe CVEs?

Yes. This page includes a free copy-paste AI prompt carrying the newest Adobe KEV entries, with CVSS, EPSS, and ransomware context, into Claude, ChatGPT, or Copilot. The data is refreshed twice a day (5 AM and 3 PM US Central).

All vendors, searchable with due dates and CSV export: the exploited-CVE tracker. Every vendor with a page: exploited by vendor.

Most searched on Senserva right now

New to a term on this page? CVE, KB, KEV, CVSS, and EPSS are each explained once, on the Senserva security lexicon. Reference: Microsoft CVE and vulnerability management and the Microsoft patching guide.
Provided as is, without warranty; verify against the vendor advisory before acting. Data notice and terms.