| CVE-2026-76195 | 10 | critical | campaign | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ( | 11d ago |
| CVE-2026-48303 | 10 | critical | campaign | Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by an Incorrect Authorization vuln | 88d ago |
| CVE-2026-48281 | 10 | critical | coldfusion | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that co | 67d ago |
| CVE-2026-48282exploited | 10 | critical | coldfusion | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restrict | 67d ago |
| CVE-2026-48283 | 10 | critical | coldfusion | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type | 67d ago |
| CVE-2026-48276 | 10 | critical | coldfusion | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type | 67d ago |
| CVE-2026-48286 | 10 | critical | campaign | Adobe Campaign Classic (ACC) versions 7.4.3 build 9396 and earlier are affected by an Incorrect Authorization vuln | 67d ago |
| CVE-2026-71398 | 10 | critical | campaign | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrar | 25d ago |
| CVE-2026-48277 | 10 | critical | coldfusion | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that co | 67d ago |
| CVE-2026-48331 | 10 | critical | campaign | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result i | 33d ago |
| CVE-2026-48316 | 10 | critical | coldfusion | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that co | 61d ago |
| CVE-2026-76193 | 10 | critical | campaign | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result i | 11d ago |
| CVE-2026-48449 | 10 | critical | campaign | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrar | 37d ago |
| CVE-2026-48330 | 10 | critical | campaign | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command | 33d ago |
| CVE-2026-48362 | 10 | critical | coldfusion | ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Inject | 25d ago |
| CVE-2026-47938 | 10 | critical | campaign | Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by a Server-Side Request Forgery ( | 88d ago |
| CVE-2026-27302 | 10 | critical | campaign | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrar | 25d ago |
| CVE-2026-76197 | 10 | critical | campaign | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ( | 11d ago |
| CVE-2026-48323 | 10 | critical | campaign | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engi | 33d ago |
| CVE-2026-48326 | 9.9 | critical | campaign | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command | 33d ago |
| CVE-2026-48318 | 9.9 | critical | coldfusion | ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulner | 53d ago |
| CVE-2026-48322 | 9.9 | critical | coldfusion | ColdFusion is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could re | 53d ago |
| CVE-2026-48333 | 9.8 | critical | campaign | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in privileg | 33d ago |
| CVE-2026-48359 | 9.6 | critical | experience manager | Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerabi | 53d ago |
| CVE-2026-48317 | 9.6 | critical | campaign | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code | 33d ago |
| CVE-2026-34659 | 9.6 | critical | connect desktop application | Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by a Deserialization of Untrusted Data vulne | 116d ago |
| CVE-2026-48259 | 9.6 | critical | experience manager | Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in ar | 53d ago |
| CVE-2026-47928 | 9.6 | critical | coldfusion | ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that co | 88d ago |
| CVE-2026-71384 | 9.6 | critical | coldfusion | is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. | 25d ago |
| CVE-2026-48284 | 9.6 | critical | coldfusion | ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution | 53d ago |
| CVE-2026-48313 | 9.3 | critical | coldfusion | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restrict | 67d ago |
| CVE-2026-48315 | 9.3 | critical | coldfusion | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that co | 67d ago |
| CVE-2026-48325 | 9.3 | critical | coldfusion | ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could result in arbitr | 53d ago |
| CVE-2026-48356 | 9.3 | critical | commerce | Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result i | 53d ago |
| CVE-2026-48334 | 9.3 | critical | illustrator | Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code executio | 53d ago |
| CVE-2026-34660 | 9.3 | critical | connect desktop application | Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by an Incorrect Authorization vulnerability | 116d ago |
| CVE-2026-34691 | 9.3 | critical | experience manager | Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a stored Cross-Site Scri | 88d ago |
| CVE-2026-48321 | 9.3 | critical | coldfusion | ColdFusion is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. | 53d ago |
| CVE-2026-48319 | 9.1 | critical | coldfusion | ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulner | 53d ago |
| CVE-2026-48358 | 9.1 | critical | commerce | Adobe Commerce is affected by an Improper Encoding or Escaping of Output vulnerability that could result in arbitr | 53d ago |
| CVE-2026-48324 | 9.1 | critical | coldfusion | ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | 53d ago |
| CVE-2026-48381 | 9 | critical | campaign | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command | 25d ago |
| CVE-2026-48327 | 9 | critical | coldfusion | ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution i | 53d ago |
| CVE-2026-47932 | 8.8 | high | coldfusion | ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Limitation of a Pathname to a Restrict | 88d ago |
| CVE-2026-48307 | 8.8 | high | coldfusion | ColdFusion versions 2025.9, 2023.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerabili | 67d ago |
| CVE-2026-71386 | 8.8 | high | coldfusion | is affected by a Cross-site Scripting (XSS) vulnerability that could result in arbitrary code execution in the con | 25d ago |
| CVE-2026-71387 | 8.8 | high | coldfusion | ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution i | 25d ago |
| CVE-2026-21273 | 8.7 | high | coldfusion | is affected by an Improper Input Validation vulnerability that could result in privilege escalation. | 25d ago |
| CVE-2026-47994 | 8.7 | high | commerce | Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-priv | 53d ago |
| CVE-2026-34686 | 8.7 | high | commerce | Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected | 116d ago |
| CVE-2026-34653 | 8.7 | high | commerce | Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected | 116d ago |
| CVE-2026-48397 | 8.6 | high | lightroom | Lightroom Classic is affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary | 25d ago |
| CVE-2026-48388 | 8.6 | high | photoshop installer | Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have result | 39d ago |
| CVE-2026-48441 | 8.6 | high | lightroom | Lightroom Classic is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | 25d ago |
| CVE-2026-48396 | 8.6 | high | bridge | Bridge is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in th | 39d ago |
| CVE-2026-47906 | 8.6 | high | dreamweaver | Dreamweaver Desktop versions 21.7 and earlier are affected by a Dependency on Vulnerable Third-Party Component vul | 88d ago |
| CVE-2026-47907 | 8.6 | high | dreamweaver | Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Access Control vulnerability that could | 88d ago |
| CVE-2026-48395 | 8.6 | high | bridge | Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the | 39d ago |
| CVE-2026-48310 | 8.6 | high | experience manager | Adobe Experience Manager is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Trav | 53d ago |
| CVE-2026-48285 | 8.6 | high | coldfusion | ColdFusion versions 2025.9, 2023.20 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability | 67d ago |
| CVE-2026-48350 | 8.6 | high | animate | Animate is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerabi | 53d ago |
| CVE-2026-48252 | 8.6 | high | experience manager | Adobe Experience Manager is affected by a Missing Authentication for Critical Function vulnerability that could re | 53d ago |
| CVE-2026-48448 | 8.6 | high | campaign | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command | 37d ago |
| CVE-2026-48275 | 8.6 | high | illustrator | Illustrator is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in | 53d ago |
| CVE-2026-47988 | 8.6 | high | commerce | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature byp | 53d ago |
| CVE-2026-48320 | 8.5 | high | coldfusion | ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. | 53d ago |
| CVE-2026-47929 | 8.4 | high | coldfusion | ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Incorrect Authorization vulnerability that coul | 88d ago |
| CVE-2026-47931 | 8.4 | high | coldfusion | ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that co | 88d ago |
| CVE-2026-34635 | 8.4 | high | coldfusion | is affected by a Use of Hard-coded Cryptographic Key vulnerability that could result in a Security feature bypass. | 25d ago |
| CVE-2026-48290 | 8.2 | high | c2pa | CAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arb | 53d ago |
| CVE-2026-48345 | 8.2 | high | animate | Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection | 53d ago |
| CVE-2026-21279 | 8.2 | high | coldfusion | is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. | 25d ago |
| CVE-2026-47984 | 8.2 | high | commerce | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature byp | 53d ago |
| CVE-2026-48363 | 8.2 | high | coldfusion | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element vulnerability | 54d ago |
| CVE-2026-48364 | 8.2 | high | coldfusion | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element vulnerability | 54d ago |
| CVE-2026-48390 | 8.2 | high | bridge | Bridge is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. | 39d ago |
| CVE-2026-48391 | 8.2 | high | bridge | Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the | 39d ago |
| CVE-2026-48440 | 8.1 | high | coldfusion | ColdFusion is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution | 25d ago |
| CVE-2026-47930 | 8.1 | high | coldfusion | ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that co | 88d ago |
| CVE-2026-47995 | 8.1 | high | commerce | Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-pri | 53d ago |
| CVE-2026-48349 | 8.1 | high | animate | Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in t | 53d ago |
| CVE-2026-34693 | 8 | high | experience manager | Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a reflected Cross-Site S | 88d ago |
| CVE-2026-48346 | 7.9 | high | animate | Animate is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the | 53d ago |
| CVE-2026-48392 | 7.8 | high | bridge | Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the co | 39d ago |
| CVE-2026-48393 | 7.8 | high | bridge | Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the co | 39d ago |
| CVE-2026-48394 | 7.8 | high | bridge | Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the co | 39d ago |
| CVE-2026-34674 | 7.8 | high | substance 3d painter | Substance3D - Sampler versions 5.1.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that c | 9d ago |
| CVE-2026-34681 | 7.8 | high | substance 3d designer | Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could | 116d ago |
| CVE-2026-34682 | 7.8 | high | substance 3d designer | Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could | 116d ago |
| CVE-2026-34636 | 7.8 | high | premiere pro | Premiere Pro versions 26.0.2, 25.6.4 and earlier are affected by an out-of-bounds write vulnerability that could r | 116d ago |
| CVE-2026-34637 | 7.8 | high | premiere pro | Premiere Pro versions 26.0.2, 25.6.4 and earlier are affected by an out-of-bounds write vulnerability that could r | 116d ago |
| CVE-2026-34638 | 7.8 | high | premiere pro | Premiere Pro versions 26.0.2, 25.6.4 and earlier are affected by a Use After Free vulnerability that could result | 116d ago |
| CVE-2026-34639 | 7.8 | high | media encoder | Media Encoder versions 26.0.2, 25.6.4 and earlier are affected by an out-of-bounds write vulnerability that could | 116d ago |
| CVE-2026-34640 | 7.8 | high | media encoder | Media Encoder versions 26.0.2, 25.6.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability | 116d ago |
| CVE-2026-34642 | 7.8 | high | after effects | After Effects versions 26.0, 25.6.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that co | 116d ago |
| CVE-2026-34643 | 7.8 | high | after effects | After Effects versions 26.0, 25.6.4 and earlier are affected by an out-of-bounds write vulnerability that could re | 116d ago |
| CVE-2026-34644 | 7.8 | high | after effects | After Effects versions 26.0, 25.6.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability th | 116d ago |
| CVE-2026-34661 | 7.8 | high | illustrator | Illustrator versions 29.8.6, 30.3 and earlier are affected by an out-of-bounds write vulnerability that could resu | 116d ago |
| CVE-2026-34675 | 7.8 | high | substance 3d painter | Substance3D - Painter versions 12.0.2 and earlier are affected by an out-of-bounds write vulnerability that could | 116d ago |
| CVE-2026-34676 | 7.8 | high | substance 3d painter | Substance3D - Painter versions 12.0.2 and earlier are affected by an out-of-bounds write vulnerability that could | 116d ago |