By vendor

Adobe vulnerabilities

Known CVEs affecting Adobe products, prioritized by severity, with SEC.co remediation and detection guidance.

132 published vulnerabilities · page 1 of 2

  • CVE-2026-47932HIGH 8.8

    Adobe ColdFusion versions 2023.19, 2025.8 and earlier contain a path traversal vulnerability that allows attackers to bypass security controls and access files outside their intended boundaries. An attacker must trick a user into opening a malicious file to exploit this flaw, making it a user-interaction-dependent attack. Once exploited, an attacker gains unauthorized access to sensitive data, can modify files, or disrupt system availability—with the ability to impact other systems or users connected to the vulnerable ColdFusion instance.

  • CVE-2026-48307HIGH 8.8

    Adobe ColdFusion versions 2025.9, 2023.20, and earlier contain a reflected cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into web pages. When a user clicks a specially crafted link, the injected script executes in their browser with their privileges, potentially enabling attackers to steal session tokens, modify page content, or perform unauthorized actions on their behalf. The vulnerability has a high CVSS score of 8.8, reflecting the potential for significant impact across confidentiality, integrity, and availability.

  • CVE-2026-47906HIGH 8.6

    Adobe Dreamweaver Desktop versions 21.7 and earlier contain a vulnerability stemming from reliance on an outdated or flawed third-party component. An attacker can exploit this flaw by distributing a malicious file—typically a project file or document—that, when opened by a user in Dreamweaver, executes arbitrary code with the privileges of the person running the application. The vulnerability requires user interaction (opening the file) to trigger, but once activated, it grants the attacker full control to read, modify, or delete data, or further compromise the system.

  • CVE-2026-47907HIGH 8.6

    Adobe Dreamweaver Desktop versions 21.7 and earlier contain a flaw that allows an attacker to run malicious code on a victim's computer. The vulnerability exists because Dreamweaver does not properly restrict access to certain functions. An attacker must trick a user into opening a specially crafted file—Dreamweaver itself will not automatically trigger the issue. Once exploited, the attacker gains the ability to execute code with the same permissions as the user running Dreamweaver, potentially compromising sensitive projects, credentials stored locally, or the broader system.

  • CVE-2026-48285HIGH 8.6

    Adobe ColdFusion contains a Server-Side Request Forgery (SSRF) vulnerability that allows attackers to bypass security controls and read sensitive data without any user interaction. Versions 2025.9, 2023.20, and earlier are affected. An attacker on the network can exploit this remotely to make the ColdFusion server fetch or interact with internal resources, potentially exposing confidential information or accessing protected systems behind the application.

  • CVE-2026-47929HIGH 8.4

    ColdFusion versions 2023.19, 2025.8 and earlier contain an authorization flaw that allows high-privileged attackers to execute arbitrary code within the context of the current user without requiring any user interaction. The vulnerability crosses trust boundaries, meaning an attacker with elevated permissions could escalate access or take control of affected accounts and sessions. This is a serious issue for organizations running vulnerable versions of ColdFusion.

  • CVE-2026-47931HIGH 8.4

    Adobe ColdFusion versions 2023.19, 2025.8 and earlier contain a flaw that allows attackers with high-level privileges to run malicious code on affected systems without requiring any user to click a link or take action. The vulnerability stems from the application not properly validating input data before processing it. While the attacker needs elevated access to the system, once they exploit this flaw, they can execute arbitrary code with the same permissions as the ColdFusion application itself, potentially compromising data and system integrity.

  • CVE-2026-47930HIGH 8.1

    Adobe ColdFusion contains a flaw that allows a user with basic system access to bypass built-in security controls and read or modify data they shouldn't be able to access. The vulnerability stems from improper validation of user input and affects multiple recent ColdFusion versions. Notably, an attacker does not need to trick an end user into clicking a malicious link or opening a file—the exploit can happen automatically if an authenticated user with low privileges interacts with an affected application.

  • CVE-2026-34693HIGH 8.0

    Adobe Experience Manager Forms JEE is vulnerable to a reflected cross-site scripting (XSS) flaw that allows attackers to inject malicious code into web pages. When a victim visits a specially crafted URL or interacts with a compromised page, the attacker can potentially hijack the user's session, escalate privileges, or take over their account. The vulnerability affects LTS SP1 and version 6.5.24.0 and earlier. Successful exploitation requires social engineering—tricking a user into clicking a malicious link or visiting a compromised site—but does not require the attacker to have direct system access.

  • CVE-2020-9695HIGH 7.8

    Adobe Acrobat Reader contains a memory corruption flaw that allows attackers to execute arbitrary code on a user's system when a victim opens a specially crafted PDF file. The vulnerability affects multiple versions across Windows and macOS platforms. While the flaw is serious, it requires an attacker to socially engineer a user into opening a malicious document, making it a targeted rather than worm-like threat.

  • CVE-2026-34695HIGH 7.8

    Adobe InDesign versions 21.3, 20.5.3 and earlier contain a stack-based buffer overflow vulnerability that could allow an attacker to execute arbitrary code on a victim's computer. An attacker would need to trick a user into opening a malicious file—there is no remote exploitation vector. The vulnerability affects InDesign on both Windows and macOS systems.

  • CVE-2026-34696HIGH 7.8

    Adobe InDesign versions 21.3, 20.5.3 and earlier contain a Use After Free memory vulnerability that allows attackers to execute arbitrary code on a user's computer. The flaw requires a user to open a specially crafted malicious file—there is no remote attack vector. Once triggered, an attacker gains full control of the application and can read, modify, or delete user data, install malware, or pivot to other systems with the privileges of the logged-in user.

  • CVE-2026-34697HIGH 7.8

    Adobe InDesign Desktop has a stack-based buffer overflow flaw that allows attackers to run arbitrary code on your computer if you open a malicious file. The vulnerability affects InDesign version 21.3, 20.5.3, and earlier on both Windows and macOS. It requires user interaction—the attacker must trick you into opening a crafted document—but once triggered, the code runs with your user privileges. This is a serious issue because InDesign documents are commonly shared and trusted, making social engineering attacks plausible.

  • CVE-2026-34698HIGH 7.8

    Adobe InDesign Desktop contains a memory handling flaw that allows attackers to execute arbitrary code on a user's computer if the user opens a specially crafted file. The vulnerability affects InDesign versions 21.3, 20.5.3 and earlier on both Windows and macOS systems. While the flaw is serious, exploiting it requires social engineering or file delivery—an attacker cannot trigger it remotely over the network.

  • CVE-2026-34699HIGH 7.8

    Adobe InDesign Desktop contains a heap memory vulnerability that could allow an attacker to execute arbitrary code on a victim's computer. The flaw exists in versions 21.3, 20.5.3, and earlier on both Windows and macOS. An attacker would need to trick a user into opening a specially crafted file—such as an InDesign document—to trigger the vulnerability. If successful, the attacker gains the same permissions as the logged-in user, potentially enabling data theft, malware installation, or lateral movement within a network.

  • CVE-2026-34700HIGH 7.8

    Adobe InDesign versions 21.3, 20.5.3 and earlier contain a memory vulnerability that allows an attacker to execute arbitrary code on a victim's computer. The attack requires social engineering—a user must be tricked into opening a malicious file. Once opened, the flaw allows the attacker to run code with the same privileges as the InDesign user, potentially compromising the entire system. This is a serious but not trivial threat: it requires user interaction and affects only specific InDesign versions, but the payoff for an attacker is significant.

  • CVE-2026-34701HIGH 7.8

    Adobe InDesign Desktop has a memory safety flaw that allows attackers to execute arbitrary code on a victim's machine by crafting a malicious document. When an unsuspecting user opens the file in InDesign 21.3, 20.5.3, or earlier versions, the vulnerability is triggered, giving the attacker the same privileges as the user running InDesign. This is a serious risk for design teams and publishers who regularly work with untrusted or externally-sourced documents.

  • CVE-2026-34702HIGH 7.8

    Adobe InDesign versions 21.3, 20.5.3 and earlier contain a stack-based buffer overflow flaw that allows attackers to execute arbitrary code with the privileges of the user running InDesign. The vulnerability requires social engineering—an attacker must trick a user into opening a specially crafted file. Once opened, the malicious file triggers the overflow and grants the attacker code execution on the victim's machine. This affects both Windows and macOS deployments of InDesign.

  • CVE-2026-34706HIGH 7.8

    Adobe InCopy, a professional editorial software tool, contains a vulnerability that allows attackers to execute malicious code on a user's system when the user opens a specially crafted file. The flaw stems from improper memory handling (out-of-bounds write) that can be exploited to gain full control of the affected system under the privileges of the logged-in user. Affected versions include InCopy 21.3, 20.5.3, and earlier releases. The attack requires social engineering—convincing a user to open a malicious document—but once successful, the impact is severe.

  • CVE-2026-34707HIGH 7.8

    Adobe InCopy versions 21.3, 20.5.3 and earlier contain a memory safety flaw that allows attackers to execute arbitrary code on affected systems. The vulnerability is triggered when a user opens a specially crafted malicious file, making it a file-based attack vector that relies on social engineering or document distribution. The flaw exists in how InCopy handles memory allocation during file parsing, creating conditions where an attacker-controlled payload can overwrite adjacent heap memory and gain code execution privileges.

  • CVE-2026-34708HIGH 7.8

    Adobe InCopy versions 21.3, 20.5.3 and earlier contain a stack-based buffer overflow flaw that could allow an attacker to execute arbitrary code with the privileges of the user running the application. The vulnerability requires an attacker to trick a user into opening a specially crafted malicious file, making it a user-interaction-dependent threat. InCopy is Adobe's collaborative editing companion to InDesign, widely used in publishing and design workflows, so this affects organizations relying on these tools for content creation and layout work.

  • CVE-2026-34709HIGH 7.8

    Adobe Substance3D Sampler versions 6.0.0 and earlier contain a memory corruption flaw that could allow attackers to execute arbitrary code on a victim's computer. The vulnerability requires a user to open a specially crafted malicious file, making social engineering the primary attack vector. Once exploited, an attacker gains the same privileges as the logged-in user, potentially compromising sensitive design assets, credentials, or system access.

  • CVE-2026-34710HIGH 7.8

    Adobe Substance3D Sampler versions 6.0.0 and earlier contain a flaw that allows attackers to execute arbitrary code on a user's computer. The vulnerability is triggered when a user opens a specially crafted malicious file in the application. Once the file is opened, an attacker gains the ability to run code with the same privileges as the logged-in user, potentially compromising design assets, stealing credentials, or pivoting to other systems on the network.

  • CVE-2026-47908HIGH 7.8

    Adobe Dreamweaver Desktop versions 21.7 and earlier contain a memory safety defect that could allow attackers to execute arbitrary code on a victim's computer. The vulnerability is triggered when a user opens a specially crafted file, making it a user-interaction-dependent attack. The flaw affects Windows and macOS systems running vulnerable Dreamweaver versions.

  • CVE-2026-47911HIGH 7.8

    Adobe Acrobat Reader contains a critical flaw that allows attackers to execute arbitrary code on a user's computer by tricking them into opening a specially crafted file. The vulnerability affects multiple recent versions across Windows and macOS systems. While the flaw requires user interaction—specifically opening a malicious PDF or document—the potential impact is severe, as successful exploitation grants the attacker the same privileges as the logged-in user.

  • CVE-2026-47912HIGH 7.8

    Adobe Acrobat Reader contains a use-after-free memory vulnerability that allows an attacker to execute arbitrary code on a victim's computer with the privileges of the logged-in user. The attack requires the victim to open a specially crafted malicious PDF file. Versions 24.001.30365, 26.001.21651, and earlier on Windows and macOS are affected. This is a serious flaw because it bypasses the application's normal security controls and gives attackers direct code execution capability.

  • CVE-2026-47913HIGH 7.8

    Adobe Acrobat Reader contains a use-after-free memory flaw that allows an attacker to execute arbitrary code if a user opens a specially crafted PDF file. The vulnerability affects Acrobat Reader version 24.001.30365, 26.001.21651 and earlier on both Windows and macOS. Because exploitation requires the victim to manually open a malicious document, this is not a wormable vulnerability, but it represents a meaningful risk in environments where users regularly receive files from untrusted sources.

  • CVE-2026-47914HIGH 7.8

    Adobe Acrobat Reader contains a use-after-free memory safety bug that allows attackers to execute arbitrary code on a victim's system. The vulnerability is triggered when a user opens a specially crafted PDF file, making it a file-based attack that relies entirely on social engineering or misdirection to succeed. Versions 24.001.30365, 26.001.21651, and earlier are vulnerable. Once exploited, an attacker gains the same privileges as the logged-in user, potentially enabling data theft, malware installation, or lateral movement within a network.

  • CVE-2026-47915HIGH 7.8

    Adobe Acrobat Reader contains a use-after-free memory vulnerability that allows attackers to execute arbitrary code with the privileges of the user running the application. The flaw affects Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier on Windows and macOS. An attacker must trick a user into opening a specially crafted malicious document for the vulnerability to be exploited. Once triggered, the attacker gains full control over the affected system, potentially allowing data theft, system compromise, or lateral movement within your network.

  • CVE-2026-47916HIGH 7.8

    Adobe Acrobat Reader contains a use-after-free memory defect that attackers can exploit to run arbitrary code with the same privileges as the user opening the file. The vulnerability affects multiple Acrobat Reader versions and requires an attacker to trick a user into opening a specially crafted malicious PDF or document. While the technical barrier to triggering the flaw is low, successful exploitation still depends on user action—someone must be convinced to open the dangerous file.

  • CVE-2026-47917HIGH 7.8

    Adobe Acrobat Reader contains a use-after-free memory defect that allows attackers to execute code with the same privileges as the user running the application. The vulnerability exists in versions 24.001.30365, 26.001.21651 and earlier on Windows and macOS systems. An attacker must trick a user into opening a specially crafted file to trigger the flaw, making this a file-based attack vector rather than a remote network vulnerability.

  • CVE-2026-47918HIGH 7.8

    Adobe Acrobat Reader contains a use-after-free vulnerability that allows attackers to execute arbitrary code on affected systems. The flaw requires a victim to open a malicious PDF or similar file, at which point the attacker's code runs with the same permissions as the user. Versions 24.001.30365, 26.001.21651, and earlier on Windows and macOS are vulnerable. This is a high-severity issue that should be prioritized for patching.

  • CVE-2026-47919HIGH 7.8

    Adobe Acrobat Reader contains a use-after-free flaw that allows an attacker to execute arbitrary code on a victim's computer. The attack requires the victim to open a specially crafted malicious PDF or document file. Once executed, the attacker gains the same privileges as the user running Acrobat Reader, potentially enabling data theft, system compromise, or further lateral movement.

  • CVE-2026-47920HIGH 7.8

    Adobe Acrobat Reader contains a use-after-free memory vulnerability that allows an attacker to execute arbitrary code with the privileges of the user opening a malicious PDF file. The vulnerability affects Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier on both Windows and macOS. Successful exploitation requires social engineering to convince a user to open a specially crafted document, but once opened, the attacker gains full code execution in that user's security context.

  • CVE-2026-47921HIGH 7.8

    Adobe Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier contain a use-after-free memory vulnerability that allows attackers to execute arbitrary code with the privileges of the logged-in user. The attack requires social engineering—a victim must be tricked into opening a malicious PDF or related file. This is a practical threat because Acrobat Reader is ubiquitous in enterprise and consumer environments, and users routinely open files from untrusted sources.

  • CVE-2026-47952HIGH 7.8

    Adobe Acrobat Reader contains a memory safety flaw that allows attackers to execute arbitrary code on a victim's computer when a malicious PDF or related document is opened. The vulnerability affects multiple versions across Windows and macOS platforms. While exploitation requires a user to be tricked into opening a specially crafted file, the impact is severe—an attacker could gain complete control of the user's system, steal data, or install malware. This is a classic code execution risk in a ubiquitous document viewer, making it a meaningful concern for any organization with Acrobat users.

  • CVE-2026-47955HIGH 7.8

    A Use After Free flaw in Adobe Acrobat Reader allows an attacker to execute arbitrary code on a victim's computer. The vulnerability exists in specific versions of Reader (24.001.30365, 26.001.21651 and earlier) and requires the victim to open a specially crafted malicious file. Once exploited, the attacker gains the same privileges as the user running the application, potentially allowing them to steal data, install malware, or modify documents.

  • CVE-2026-47959HIGH 7.8

    Adobe Acrobat Reader contains a flaw in how it processes certain file content that can cause the application to crash or allow an attacker to run arbitrary code with the same permissions as the user viewing the file. The vulnerability exists in versions 24.001.30365, 26.001.21651, and earlier across Windows and macOS. An attacker would need to trick a user into opening a specially crafted PDF or related document file to exploit this issue.

  • CVE-2026-47964HIGH 7.8

    Adobe's DNG SDK (Digital Negative Software Development Kit), a widely used library for processing raw image files, contains a heap-based buffer overflow flaw in versions 1.7.1 2536 and earlier. An attacker can craft a malicious DNG image file that, when opened by a user, triggers the overflow and executes arbitrary code with the privileges of the person viewing the file. No special access or authentication is required; the only barrier is social engineering to get a victim to open the file.

  • CVE-2026-47965HIGH 7.8

    Adobe Reader contains a critical flaw that allows attackers to run malicious code on a victim's computer if the user opens a specially crafted file. The vulnerability exists in versions 24.001.30365 and 26.001.21651 of Acrobat Reader and earlier releases. While the attacker cannot exploit this remotely—the victim must actively open the malicious file—successful exploitation grants the attacker the same permissions as the logged-in user, potentially enabling data theft, system compromise, or further lateral movement.

  • CVE-2026-48291HIGH 7.8

    A heap-based buffer overflow vulnerability in Adobe Format Plugins version 1.1.2 and earlier allows attackers to execute arbitrary code on an affected system. The vulnerability requires a user to open a specially crafted malicious file, making it a user-interaction-dependent attack. Once exploited, an attacker gains the same privileges as the user running the application, potentially compromising sensitive data or system integrity.

  • CVE-2026-48292HIGH 7.8

    Format Plugins, an Adobe product, contains a memory handling flaw that allows attackers to execute arbitrary code on affected systems. The vulnerability exists in versions 1.1.2 and earlier. An attacker must trick a user into opening a specially crafted file to trigger the vulnerability—there is no remote attack vector. Once exploited, the attacker gains the same privileges as the logged-in user, potentially leading to data theft, system compromise, or lateral movement within the network.

  • CVE-2026-48293HIGH 7.8

    Adobe InDesign Desktop is vulnerable to an out-of-bounds write flaw that could allow an attacker to execute arbitrary code on a victim's computer. The vulnerability affects InDesign versions 21.3, 20.5.3 and earlier running on Windows or macOS. An attacker would need to trick a user into opening a specially crafted file—there is no indication the vulnerability can be exploited remotely or without user action. Successfully exploiting this flaw gives an attacker the same privileges as the logged-in user, potentially allowing theft of data, installation of malware, or lateral movement within a network.

  • CVE-2026-48305HIGH 7.8

    Adobe Substance3D - Sampler contains a memory safety flaw that could allow an attacker to execute arbitrary code on a victim's machine. The vulnerability exists in versions 6.0.0 and earlier. An attacker would need to trick a user into opening a specially crafted malicious file—the code does not execute automatically or remotely. Once the file is opened, the attacker gains the same privileges as the user running the application, potentially allowing theft of data, installation of malware, or system compromise.

  • CVE-2026-48306HIGH 7.8

    Adobe Substance 3D Sampler versions 6.0.0 and earlier contain an out-of-bounds memory write flaw that allows attackers to execute arbitrary code with the privileges of the user running the application. The attack requires a victim to open a specially crafted malicious file, making it a file-based vector that could be delivered via email, file-sharing services, or compromised websites. This is a genuine code execution risk for design and creative professionals who rely on Substance 3D tools.

  • CVE-2026-47937HIGH 7.7

    Adobe Acrobat Reader contains a flaw in how it searches for and loads libraries or components from the file system. An attacker with administrator or elevated system privileges could craft a malicious file that, when opened by a user, tricks the application into running attacker-controlled code with the same permissions as the user who opened the file. The vulnerability requires both high system privileges to set up and user action to trigger—someone must explicitly open the crafted file.

  • CVE-2026-34711HIGH 7.5

    A flaw in CAI Content Credentials—a technology for tracking and verifying the authenticity of digital content—allows an attacker to crash applications using affected versions by sending specially crafted input that triggers an integer overflow. No user action is required; the attack can be executed remotely. The vulnerability affects multiple platforms including iOS, macOS, Android, Windows, and Linux systems that implement the c2pa-web or c2pa libraries.

  • CVE-2026-34712HIGH 7.5

    A flaw in Adobe's Content Credentials (C2PA) library allows an attacker to crash applications using the affected versions by sending specially crafted input. No user interaction is required, and no special permissions are needed—an attacker on the network can trigger this denial-of-service condition remotely. The vulnerability stems from the library's failure to properly validate input before processing it.

  • CVE-2026-34713HIGH 7.5

    CAI Content Credentials, Adobe's tooling for embedding verifiable credential information in digital media, contains a flaw that allows attackers to overwhelm affected systems with resource requests. An attacker can trigger a denial-of-service condition without needing to interact with a user or authenticate first. The vulnerability affects c2pa-web version 0.7.1 and c2pa version 0.80.1 and earlier.

  • CVE-2026-47960HIGH 7.4

    Adobe ColdFusion versions 2023.19, 2025.8 and earlier contain an XML External Entity (XXE) vulnerability that allows attackers to read arbitrary files from the server's file system. The vulnerability requires a victim to open a malicious file, making it a targeted attack vector. Once exploited, an attacker gains unauthorized access to sensitive data stored on the affected system, but cannot modify files or disrupt service availability.

  • CVE-2026-48294HIGH 7.4

    A vulnerability exists in Adobe Acrobat's PDF viewer extension for Chrome that allows attackers to steal session data from victims. The flaw is classified as a cross-site scripting (XSS) issue that can bypass same-origin protections, meaning malicious content on one website could access sensitive information from another site. An attacker would need to trick a user into visiting a malicious webpage or clicking a specially crafted link. The vulnerability affects Acrobat versions 26.5.2.2 and earlier.

  • CVE-2026-48314MEDIUM 6.5

    Adobe ColdFusion contains a path traversal vulnerability that allows an attacker to read and write files outside intended directory boundaries. Versions 2025.9, 2023.20 and earlier are affected. No user interaction is required for exploitation—an attacker can trigger the flaw remotely and directly access or modify sensitive files. The impact is classified as medium severity because while file access is limited, both confidentiality and integrity can be compromised.

  • CVE-2026-47909MEDIUM 6.3

    Dreamweaver Desktop versions 21.7 and earlier contain a flaw that allows attackers to read files from your computer that they shouldn't be able to access. The vulnerability requires social engineering—an attacker must trick you into opening a malicious file. Once opened, the attacker gains read access to sensitive data outside the application's normal boundaries. This is a local attack that doesn't require special permissions, but it does depend on user action.

  • CVE-2026-47910MEDIUM 6.3

    Dreamweaver Desktop versions 21.7 and earlier contain an authorization flaw that allows attackers to read files from your computer that they shouldn't have access to. The attacker must trick you into opening a malicious file, but once you do, they can potentially access sensitive documents and system files. This is a local attack that doesn't require special permissions to execute.

  • CVE-2026-47902MEDIUM 6.2

    CAI Content Credentials, Adobe's implementation of Content Provenance and Authentication, contains a flaw that allows attackers to consume excessive system resources without any user action required. This can crash or severely degrade applications using affected versions of the c2pa-web library (0.7.1 and earlier) or the c2pa core library (v0.80.1 and earlier). The vulnerability is a resource exhaustion issue—an attacker sends specially crafted input that forces the application to allocate memory or processing power until the system becomes unresponsive.

  • CVE-2026-47903MEDIUM 6.2

    CAI Content Credentials, Adobe's implementation for managing content provenance and authenticity, contains a flaw in how it validates input data. Versions [email protected], c2pa-v0.80.1 and earlier can be crashed by sending specially crafted input, causing a denial-of-service condition. No user interaction is required—an attacker can trigger the crash remotely, making this a network-reachable availability risk.

  • CVE-2026-47904MEDIUM 6.2

    CAI Content Credentials, a component used for managing digital content authenticity and provenance, contains a flaw that allows an attacker to consume excessive system resources without requiring user action. An affected application could become unresponsive or crash, effectively denying legitimate users access to the service. This is a local-level vulnerability, meaning an attacker needs some degree of system access to trigger the condition.

  • CVE-2026-47905MEDIUM 6.2

    A resource exhaustion vulnerability exists in Adobe's Content Credentials (C2PA) library that allows an attacker to consume excessive system resources and crash an application without requiring any user action. The vulnerability affects C2PA Web version 0.7.1 and earlier, as well as C2PA version 0.80.1 and earlier. An unauthenticated attacker with local access could trigger the issue remotely through the affected library, leading to a denial-of-service condition.

  • CVE-2020-9711MEDIUM 5.5

    Adobe Acrobat Reader versions 2020.009.20074, 2020.001.30002, 2017.011.30171, 2015.006.30523 and earlier contain a flaw that allows an attacker to read sensitive data from a computer's memory when a user opens a specially crafted PDF file. The vulnerability does not allow attackers to modify files or crash the application, but it does expose information that should remain private. An attacker would need to trick someone into opening a malicious PDF to exploit this issue.

  • CVE-2020-9713MEDIUM 5.5

    CVE-2020-9713 is a memory disclosure vulnerability in Adobe Acrobat and Reader that allows an attacker to read sensitive data from a victim's computer. The flaw occurs when the application improperly accesses memory outside intended boundaries while processing a malicious PDF file. An attacker must trick a user into opening a crafted document to exploit it—there is no remote attack vector. While the vulnerability cannot directly crash the application or alter files, it can expose confidential information such as cached credentials, encryption keys, or other sensitive data resident in memory at the time of exploitation.

  • CVE-2026-34657MEDIUM 5.5

    CAI Content Credentials, a library used to manage and verify digital content authenticity, contains a path traversal flaw in versions [email protected], c2pa-v0.80.1 and earlier. The vulnerability allows an attacker to write files to arbitrary locations on a system by crafting a malicious archive that, when extracted by a user, exploits insufficient pathname validation. This is a local attack requiring user interaction—an end user must actively extract or open the malicious file for the attack to succeed.

  • CVE-2026-34703MEDIUM 5.5

    A flaw in Adobe InDesign versions 21.3, 20.5.3 and earlier can cause the application to crash when a user opens a specially crafted malicious file. The vulnerability stems from improper handling of null pointer references in memory, which an attacker could weaponize by distributing a booby-trapped document. While this doesn't allow an attacker to steal data or take control of your system, it does enable denial-of-service attacks that interrupt work and productivity.

  • CVE-2026-34704MEDIUM 5.5

    InDesign Desktop has a vulnerability that causes the application to crash when a user opens a specially crafted malicious file. While the crash itself doesn't expose data or allow an attacker to take control of the system, it does disrupt work by forcing the application to shut down unexpectedly. Versions 21.3, 20.5.3, and earlier are affected. An attacker must trick someone into opening the malicious file—the vulnerability does not spread on its own or affect systems remotely.

  • CVE-2026-34705MEDIUM 5.5

    Adobe InDesign has a memory-reading vulnerability that can expose sensitive data stored in the application's working memory. When a user opens a specially crafted file, the vulnerability allows an attacker to read beyond the intended boundaries of memory, potentially revealing passwords, encryption keys, or other confidential information. This is a local attack that requires user interaction—the victim must be tricked into opening a malicious file. The vulnerability affects InDesign versions 21.3, 20.5.3, and earlier on both Windows and macOS systems.

  • CVE-2026-47923MEDIUM 5.5

    Adobe Acrobat Reader contains a flaw that allows an attacker to read sensitive data from a user's computer memory by tricking them into opening a specially crafted file. The vulnerability doesn't damage files or prevent the application from running, but it could expose confidential information like passwords, encryption keys, or personal data that happens to be in memory at the time of exploitation. Versions 24.001.30365, 26.001.21651 and earlier on Windows and macOS are affected.

  • CVE-2026-47924MEDIUM 5.5

    Adobe Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier contain a use-after-free memory flaw that could allow an attacker to read sensitive data from the application's memory. The vulnerability requires a user to open a crafted malicious PDF or document file, making this a low-friction attack that relies on social engineering rather than complex exploitation techniques. While memory disclosure alone does not enable direct system compromise, the leaked information could include credentials, encryption keys, or other confidential content.

  • CVE-2026-47925MEDIUM 5.5

    Adobe Acrobat Reader contains an integer overflow flaw that crashes the application when a user opens a specially crafted file. While this is a denial-of-service issue rather than a data breach or code execution vulnerability, it can disrupt business workflows. The flaw affects Acrobat Reader DC versions 24.001.30365, 26.001.21651 and earlier across Windows and macOS. An attacker must trick a user into opening a malicious PDF or document to trigger the crash.

  • CVE-2026-47926MEDIUM 5.5

    Adobe Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier contain a memory reading flaw that allows attackers to extract sensitive information from your system. The vulnerability requires a user to open a specially crafted malicious file, making social engineering a necessary component of any attack. While the flaw cannot be used to modify files or crash the application, the potential for exposing confidential data—such as encryption keys, credentials, or personal information resident in memory—presents a meaningful risk to organizations handling sensitive documents.

  • CVE-2026-47927MEDIUM 5.5

    Adobe's DNG SDK, a toolkit for processing Digital Negative image files, contains a flaw that allows an attacker to read sensitive data from a victim's computer memory. When a user opens a specially crafted malicious DNG image file, the SDK attempts to read data from memory regions it shouldn't access, potentially exposing passwords, encryption keys, or other confidential information. An attacker must trick a user into opening the malicious file—the vulnerability cannot be exploited remotely or automatically.

  • CVE-2026-47934MEDIUM 5.5

    Adobe's DNG SDK, a widely-used library for processing Digital Negative image files, contains a memory reading flaw that could expose sensitive data. When a user opens a specially crafted DNG image file, the SDK reads memory it shouldn't access, potentially leaking information like encryption keys, passwords, or other confidential data stored in application memory. The vulnerability requires user interaction—an attacker must trick someone into opening a malicious file—which limits its reach but doesn't eliminate the risk for targeted scenarios.

  • CVE-2026-47961MEDIUM 5.5

    Adobe Acrobat Reader contains an out-of-bounds read flaw that allows attackers to extract sensitive data from system memory. The vulnerability requires user interaction—specifically, opening a malicious PDF or document file. When triggered, the flaw exposes unintended memory contents that could include confidential information resident in the application's process space.

  • CVE-2026-47963MEDIUM 5.5

    Adobe's DNG SDK—a tool developers use to handle DNG (Digital Negative) image files—contains a flaw that lets attackers read private information from a computer's memory. The vulnerability exists in DNG SDK version 1.7.1 build 2536 and earlier. An attacker would need to trick a user into opening a specially crafted malicious file to trigger the leak. While the memory exposure is significant, the attack requires user action, which limits its immediate reach.

  • CVE-2026-48267MEDIUM 5.5

    Adobe DNG SDK versions 1.7.1 (build 2536) and earlier contain a flaw that can crash applications using the library when a user opens a specially crafted file. An attacker would need to trick a user into opening a malicious file—there's no remote exploitation vector. The result is a denial-of-service condition; the attacker cannot steal data or gain code execution.

  • CVE-2026-34692MEDIUM 5.4

    Adobe Experience Manager contains a cross-site scripting (XSS) flaw that allows attackers to inject and execute malicious JavaScript in a user's browser. The attack requires tricking a victim into visiting a specially crafted webpage while authenticated to AEM. Once executed, the attacker can steal session data, modify page content, or perform actions on behalf of the victim within the AEM interface.

  • CVE-2026-47935MEDIUM 5.4

    Adobe Experience Manager contains a DOM-based cross-site scripting (XSS) flaw that allows an attacker to inject malicious JavaScript code into a victim's browser session. The vulnerability affects multiple versions up to 6.5.24, LTS SP1, and 2026.04. An attacker must trick a user into visiting a specially crafted webpage to trigger the exploit, but once executed, the malicious script runs with the victim's privileges and can access or modify sensitive data within the AEM application context across different origin boundaries.

  • CVE-2026-47936MEDIUM 5.4

    Adobe Experience Manager contains a stored cross-site scripting (XSS) flaw that allows attackers with basic user permissions to embed malicious code into form fields. When other users view those pages, the attacker's JavaScript runs in their browsers. This is particularly concerning because the injected script can affect other domains or applications (indicated by the changed scope), potentially compromising session tokens or sensitive data from multiple contexts.

  • CVE-2026-47939MEDIUM 5.4

    Adobe Experience Manager (AEM) contains a stored cross-site scripting (XSS) vulnerability that allows low-privileged users to inject malicious JavaScript into form fields. When other users view pages containing these compromised fields, the injected scripts execute in their browsers. This is a persistence threat—the malicious payload remains in the system until remediated, affecting anyone who accesses the affected content.

  • CVE-2026-47941MEDIUM 5.4

    Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier contain a stored cross-site scripting (XSS) flaw in form field handling. A low-privileged user can inject malicious JavaScript that persists in the application and executes in other users' browsers when they view the affected page. This is a persistence problem: the attack code lives in the application, not just in a URL or temporary input. The scope change means the XSS can affect resources beyond the vulnerable component itself.

  • CVE-2026-47942MEDIUM 5.4

    Adobe Experience Manager contains a stored cross-site scripting (XSS) flaw that allows attackers with low-level user access to embed malicious scripts into form fields. When other users view pages containing these compromised fields, the attacker's JavaScript executes in their browsers. This represents a medium-severity risk because it requires both initial low-privileged access and user interaction, but affects multiple versions of a widely-deployed content management platform.

  • CVE-2026-47943MEDIUM 5.4

    Adobe Experience Manager (AEM) contains a stored cross-site scripting vulnerability affecting versions 6.5.24, LTS SP1, 2026.04 and earlier. A user with low-level permissions can inject malicious JavaScript code into form fields, which then executes when other users view the affected page. This is particularly risky because the malicious payload persists in the system rather than being temporary, and it affects the security boundary between different parts of the application (indicated by the scope change in the CVSS vector). The attack requires user interaction—victims must browse to the page containing the injected field—but the damage is real: attackers can steal session tokens, capture credentials, or perform unauthorized actions on behalf of victims.

  • CVE-2026-47944MEDIUM 5.4

    Adobe Experience Manager contains a stored cross-site scripting (XSS) vulnerability that allows low-privileged users to inject malicious JavaScript code into form fields. When other users view pages containing these compromised fields, the attacker's scripts execute in their browsers. This is a persistence issue—the malicious payload remains in the system until removed, affecting anyone who accesses the affected content.

  • CVE-2026-47945MEDIUM 5.4

    Adobe Experience Manager contains a stored cross-site scripting (XSS) flaw that allows attackers with low-level account access to inject malicious JavaScript into form fields. When legitimate users view pages containing these compromised fields, the malicious script executes in their browsers, potentially compromising their sessions, stealing credentials, or performing unauthorized actions on their behalf. The vulnerability affects multiple versions of AEM through version 2026.04 and earlier LTS releases.

  • CVE-2026-47946MEDIUM 5.4

    Adobe Experience Manager contains a DOM-based Cross-Site Scripting vulnerability that allows an attacker to inject malicious JavaScript code into a victim's browser session. The attack requires a logged-in user to visit a specially crafted webpage, at which point the attacker's script executes with the victim's privileges within the AEM application context. This can lead to unauthorized actions, data theft, or session hijacking depending on the victim's role and permissions.

  • CVE-2026-47947MEDIUM 5.4

    Adobe Experience Manager contains a DOM-based cross-site scripting (XSS) flaw that allows attackers to inject malicious JavaScript into web pages viewed by authenticated users. The vulnerability affects multiple AEM versions through 6.5.24, LTS SP1, and 2026.04. Successful exploitation requires convincing a user to visit an attacker-controlled or compromised webpage while logged into an affected AEM instance. The attacker's code would then execute with the victim's privileges, potentially stealing session data, modifying content, or performing actions on their behalf.

  • CVE-2026-47948MEDIUM 5.4

    Adobe Experience Manager versions up to 6.5.24, LTS SP1, and 2026.04 contain a stored cross-site scripting (XSS) flaw that allows attackers with low-level account access to inject malicious JavaScript into form fields. When other users view pages containing these compromised fields, the attacker's scripts execute in their browsers, potentially allowing credential theft, session hijacking, or other client-side attacks. The vulnerability requires user interaction (viewing the affected page) and a valid login, but can impact users across different security contexts.

  • CVE-2026-47949MEDIUM 5.4

    Adobe Experience Manager (AEM) contains a stored cross-site scripting (XSS) vulnerability in form fields that allows attackers with basic user privileges to inject malicious JavaScript. When legitimate users view pages containing these compromised fields, the injected scripts execute in their browsers, potentially enabling session hijacking, credential theft, or further compromise. The vulnerability affects AEM 6.5.24, LTS SP1, 2026.04, and earlier versions.

  • CVE-2026-47950MEDIUM 5.4

    Adobe Experience Manager (AEM) contains a stored cross-site scripting (XSS) flaw that allows low-privileged users to embed malicious scripts into form fields. When other users view pages containing these compromised fields, the attacker's JavaScript runs in their browsers with the victim's permissions. The vulnerability affects multiple AEM versions including 6.5.24, LTS SP1, 2026.04 and earlier.

  • CVE-2026-47951MEDIUM 5.4

    Adobe Experience Manager contains a stored cross-site scripting (XSS) vulnerability that allows attackers with low-level account privileges to embed malicious code into form fields. When other users visit pages containing these compromised fields, the injected scripts execute in their browsers, potentially compromising their sessions or stealing sensitive information. The vulnerability affects multiple AEM versions up to and including 6.5.24, LTS SP1, and 2026.04.

  • CVE-2026-47953MEDIUM 5.4

    Adobe Experience Manager contains a stored cross-site scripting (XSS) vulnerability in form field handling that allows low-privileged users to inject malicious scripts. When a victim visits a page containing an affected form field, the injected script executes in their browser with the victim's privileges, potentially compromising their session or stealing sensitive data. The vulnerability affects multiple versions of AEM through 2026.04 and requires authenticated access to exploit, limiting but not eliminating the attack surface.

  • CVE-2026-47954MEDIUM 5.4

    Adobe Experience Manager contains a stored cross-site scripting (XSS) flaw that allows attackers with basic user privileges to embed malicious code into form fields. When other users view pages containing these compromised fields, the injected scripts execute in their browsers, potentially allowing the attacker to steal credentials, session tokens, or perform actions on behalf of the victim. The vulnerability affects multiple versions of AEM up to and including 6.5.24, LTS SP1, and 2026.04.

  • CVE-2026-47956MEDIUM 5.4

    Adobe Experience Manager versions through 6.5.24, LTS SP1, and 2026.04 contain a stored cross-site scripting (XSS) flaw in form field handling. An attacker with basic user privileges can inject malicious JavaScript into vulnerable fields. When legitimate users view pages containing these fields, the injected scripts execute in their browsers. This is particularly concerning because the vulnerability changes scope—meaning an attacker could potentially affect other users or system functionality beyond the immediate form context.

  • CVE-2026-47957MEDIUM 5.4

    Adobe Experience Manager (AEM) versions 6.5.24, LTS SP1, 2026.04 and earlier contain a stored cross-site scripting (XSS) flaw in form field handling. An attacker with low-level system access can inject malicious JavaScript that persists in the application and executes whenever a user views the affected page, potentially allowing credential theft, session hijacking, or malware distribution. The vulnerability requires user interaction—a victim must navigate to the compromised form—but the attacker does not need elevated privileges to introduce the payload.

  • CVE-2026-47958MEDIUM 5.4

    Adobe Experience Manager (AEM) versions 6.5.24, LTS SP1, 2026.04 and earlier contain a stored cross-site scripting (XSS) flaw in form field handling. A low-privileged user can inject malicious JavaScript that persists in the application and executes when other users view the affected page. Because the vulnerability has a changed scope—meaning the impact crosses trust boundaries—it affects not just the immediate application but potentially other parts of the system or connected domains.

  • CVE-2026-47962MEDIUM 5.4

    Adobe Experience Manager is vulnerable to a stored cross-site scripting (XSS) attack where a low-privileged user can inject malicious JavaScript code into form fields. When other users—including administrators or content editors—view the page containing the compromised field, the malicious script executes in their browser. This can lead to credential theft, session hijacking, or unauthorized actions performed on behalf of the victim.

  • CVE-2026-47966MEDIUM 5.4

    Adobe Experience Manager contains a stored cross-site scripting (XSS) flaw in form field handling. An attacker with low-level access can inject malicious JavaScript that persists in the application. When other users view the compromised form, the injected script executes in their browsers, potentially allowing credential theft, session hijacking, or further compromise. The vulnerability affects multiple versions through 2026.04 and earlier.

  • CVE-2026-47970MEDIUM 5.4

    Adobe Experience Manager has a stored cross-site scripting (XSS) vulnerability in form fields that allows attackers with basic user privileges to inject malicious scripts. When other users view pages containing these compromised fields, the attacker's JavaScript executes in their browsers, potentially stealing data or performing unauthorized actions. The vulnerability affects multiple AEM versions through 2026.04.

  • CVE-2026-47972MEDIUM 5.4

    Adobe Experience Manager (AEM) contains a stored Cross-Site Scripting flaw that allows low-privileged users to inject malicious JavaScript into form fields. When other users view pages containing these compromised fields, the attacker's script executes in their browsers, potentially compromising sessions, stealing credentials, or performing actions on their behalf. The vulnerability affects multiple AEM versions through 2026.04.

  • CVE-2026-47973MEDIUM 5.4

    Adobe Experience Manager has a stored cross-site scripting (XSS) vulnerability that allows low-privileged users to inject malicious scripts into form fields. When other users view pages containing these compromised fields, the attacker's JavaScript executes in their browsers, potentially stealing credentials, session tokens, or sensitive data. The vulnerability affects multiple versions of AEM, including 6.5.24, LTS SP1, and 2026.04.

  • CVE-2026-47974MEDIUM 5.4

    Adobe Experience Manager has a stored cross-site scripting (XSS) vulnerability that allows attackers with low-level user access to inject malicious JavaScript into form fields. When other users view those compromised pages, the malicious code runs in their browsers. This is a scope-change vulnerability, meaning an attacker can potentially affect users beyond their normal permission level. The vulnerability affects multiple recent versions of AEM.

  • CVE-2026-47975MEDIUM 5.4

    Adobe Experience Manager (AEM) contains a stored cross-site scripting (XSS) vulnerability that allows attackers with basic user privileges to inject malicious scripts into form fields. When legitimate users visit pages containing these compromised fields, the attacker's JavaScript executes in their browsers. This is distinct from reflected XSS because the malicious payload persists in the application's database, affecting all subsequent visitors. The vulnerability requires user interaction—a victim must view the poisoned page—but the attacker needs only low-level access to inject the payload initially.