LIVE · cybersecurity feed
Live wire
vendor1 exploited in the wild

Adobe

237 CVEs published in the last four months and 12 stories. Exploited flaws first.

Critical43
High194
Medium0
Exploited (KEV)1

Patch these first

CVECVSSSeverityProductSummaryPublished
CVE-2026-48282exploited10criticalcoldfusionColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restrict67d ago

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-7619510criticalcampaignAdobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command (11d ago
CVE-2026-4830310criticalcampaignAdobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by an Incorrect Authorization vuln88d ago
CVE-2026-4828110criticalcoldfusionColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that co67d ago
CVE-2026-48282exploited10criticalcoldfusionColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restrict67d ago
CVE-2026-4828310criticalcoldfusionColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type67d ago
CVE-2026-4827610criticalcoldfusionColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type67d ago
CVE-2026-4828610criticalcampaignAdobe Campaign Classic (ACC) versions 7.4.3 build 9396 and earlier are affected by an Incorrect Authorization vuln67d ago
CVE-2026-7139810criticalcampaignAdobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrar25d ago
CVE-2026-4827710criticalcoldfusionColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that co67d ago
CVE-2026-4833110criticalcampaignAdobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result i33d ago
CVE-2026-4831610criticalcoldfusionColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that co61d ago
CVE-2026-7619310criticalcampaignAdobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result i11d ago
CVE-2026-4844910criticalcampaignAdobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrar37d ago
CVE-2026-4833010criticalcampaignAdobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command 33d ago
CVE-2026-4836210criticalcoldfusionColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Inject25d ago
CVE-2026-4793810criticalcampaignAdobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by a Server-Side Request Forgery (88d ago
CVE-2026-2730210criticalcampaignAdobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrar25d ago
CVE-2026-7619710criticalcampaignAdobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command (11d ago
CVE-2026-4832310criticalcampaignAdobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engi33d ago
CVE-2026-483269.9criticalcampaignAdobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command 33d ago
CVE-2026-483189.9criticalcoldfusionColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulner53d ago
CVE-2026-483229.9criticalcoldfusionColdFusion is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could re53d ago
CVE-2026-483339.8criticalcampaignAdobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in privileg33d ago
CVE-2026-483599.6criticalexperience managerAdobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerabi53d ago
CVE-2026-483179.6criticalcampaignAdobe Campaign Classic (ACC) is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code33d ago
CVE-2026-346599.6criticalconnect desktop applicationAdobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by a Deserialization of Untrusted Data vulne116d ago
CVE-2026-482599.6criticalexperience managerAdobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in ar53d ago
CVE-2026-479289.6criticalcoldfusionColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that co88d ago
CVE-2026-713849.6criticalcoldfusionis affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass.25d ago
CVE-2026-482849.6criticalcoldfusionColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution53d ago
CVE-2026-483139.3criticalcoldfusionColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restrict67d ago
CVE-2026-483159.3criticalcoldfusionColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that co67d ago
CVE-2026-483259.3criticalcoldfusionColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could result in arbitr53d ago
CVE-2026-483569.3criticalcommerceAdobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result i53d ago
CVE-2026-483349.3criticalillustratorIllustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code executio53d ago
CVE-2026-346609.3criticalconnect desktop applicationAdobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by an Incorrect Authorization vulnerability 116d ago
CVE-2026-346919.3criticalexperience managerAdobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a stored Cross-Site Scri88d ago
CVE-2026-483219.3criticalcoldfusionColdFusion is affected by an Incorrect Authorization vulnerability that could result in privilege escalation.53d ago
CVE-2026-483199.1criticalcoldfusionColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulner53d ago
CVE-2026-483589.1criticalcommerceAdobe Commerce is affected by an Improper Encoding or Escaping of Output vulnerability that could result in arbitr53d ago
CVE-2026-483249.1criticalcoldfusionColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 53d ago
CVE-2026-483819criticalcampaignAdobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command 25d ago
CVE-2026-483279criticalcoldfusionColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution i53d ago
CVE-2026-479328.8highcoldfusionColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Limitation of a Pathname to a Restrict88d ago
CVE-2026-483078.8highcoldfusionColdFusion versions 2025.9, 2023.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerabili67d ago
CVE-2026-713868.8highcoldfusionis affected by a Cross-site Scripting (XSS) vulnerability that could result in arbitrary code execution in the con25d ago
CVE-2026-713878.8highcoldfusionColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution i25d ago
CVE-2026-212738.7highcoldfusionis affected by an Improper Input Validation vulnerability that could result in privilege escalation.25d ago
CVE-2026-479948.7highcommerceAdobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-priv53d ago
CVE-2026-346868.7highcommerceAdobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected 116d ago
CVE-2026-346538.7highcommerceAdobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected 116d ago
CVE-2026-483978.6highlightroomLightroom Classic is affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary 25d ago
CVE-2026-483888.6highphotoshop installerAdobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have result39d ago
CVE-2026-484418.6highlightroomLightroom Classic is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')25d ago
CVE-2026-483968.6highbridgeBridge is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in th39d ago
CVE-2026-479068.6highdreamweaverDreamweaver Desktop versions 21.7 and earlier are affected by a Dependency on Vulnerable Third-Party Component vul88d ago
CVE-2026-479078.6highdreamweaverDreamweaver Desktop versions 21.7 and earlier are affected by an Improper Access Control vulnerability that could 88d ago
CVE-2026-483958.6highbridgeBridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the 39d ago
CVE-2026-483108.6highexperience managerAdobe Experience Manager is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Trav53d ago
CVE-2026-482858.6highcoldfusionColdFusion versions 2025.9, 2023.20 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability67d ago
CVE-2026-483508.6highanimateAnimate is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerabi53d ago
CVE-2026-482528.6highexperience managerAdobe Experience Manager is affected by a Missing Authentication for Critical Function vulnerability that could re53d ago
CVE-2026-484488.6highcampaignAdobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command 37d ago
CVE-2026-482758.6highillustratorIllustrator is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in53d ago
CVE-2026-479888.6highcommerceAdobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature byp53d ago
CVE-2026-483208.5highcoldfusionColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability.53d ago
CVE-2026-479298.4highcoldfusionColdFusion versions 2023.19, 2025.8 and earlier are affected by an Incorrect Authorization vulnerability that coul88d ago
CVE-2026-479318.4highcoldfusionColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that co88d ago
CVE-2026-346358.4highcoldfusionis affected by a Use of Hard-coded Cryptographic Key vulnerability that could result in a Security feature bypass.25d ago
CVE-2026-482908.2highc2paCAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arb53d ago
CVE-2026-483458.2highanimateAnimate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection53d ago
CVE-2026-212798.2highcoldfusionis affected by an Improper Input Validation vulnerability that could result in a Security feature bypass.25d ago
CVE-2026-479848.2highcommerceAdobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature byp53d ago
CVE-2026-483638.2highcoldfusionColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element vulnerability 54d ago
CVE-2026-483648.2highcoldfusionColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element vulnerability 54d ago
CVE-2026-483908.2highbridgeBridge is affected by an Incorrect Authorization vulnerability that could result in privilege escalation.39d ago
CVE-2026-483918.2highbridgeBridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the 39d ago
CVE-2026-484408.1highcoldfusionColdFusion is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution25d ago
CVE-2026-479308.1highcoldfusionColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that co88d ago
CVE-2026-479958.1highcommerceAdobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-pri53d ago
CVE-2026-483498.1highanimateAnimate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in t53d ago
CVE-2026-346938highexperience managerAdobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a reflected Cross-Site S88d ago
CVE-2026-483467.9highanimateAnimate is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the53d ago
CVE-2026-483927.8highbridgeBridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the co39d ago
CVE-2026-483937.8highbridgeBridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the co39d ago
CVE-2026-483947.8highbridgeBridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the co39d ago
CVE-2026-346747.8highsubstance 3d painterSubstance3D - Sampler versions 5.1.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that c9d ago
CVE-2026-346817.8highsubstance 3d designerSubstance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could116d ago
CVE-2026-346827.8highsubstance 3d designerSubstance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could116d ago
CVE-2026-346367.8highpremiere proPremiere Pro versions 26.0.2, 25.6.4 and earlier are affected by an out-of-bounds write vulnerability that could r116d ago
CVE-2026-346377.8highpremiere proPremiere Pro versions 26.0.2, 25.6.4 and earlier are affected by an out-of-bounds write vulnerability that could r116d ago
CVE-2026-346387.8highpremiere proPremiere Pro versions 26.0.2, 25.6.4 and earlier are affected by a Use After Free vulnerability that could result 116d ago
CVE-2026-346397.8highmedia encoderMedia Encoder versions 26.0.2, 25.6.4 and earlier are affected by an out-of-bounds write vulnerability that could 116d ago
CVE-2026-346407.8highmedia encoderMedia Encoder versions 26.0.2, 25.6.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability 116d ago
CVE-2026-346427.8highafter effectsAfter Effects versions 26.0, 25.6.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that co116d ago
CVE-2026-346437.8highafter effectsAfter Effects versions 26.0, 25.6.4 and earlier are affected by an out-of-bounds write vulnerability that could re116d ago
CVE-2026-346447.8highafter effectsAfter Effects versions 26.0, 25.6.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability th116d ago
CVE-2026-346617.8highillustratorIllustrator versions 29.8.6, 30.3 and earlier are affected by an out-of-bounds write vulnerability that could resu116d ago
CVE-2026-346757.8highsubstance 3d painterSubstance3D - Painter versions 12.0.2 and earlier are affected by an out-of-bounds write vulnerability that could 116d ago
CVE-2026-346767.8highsubstance 3d painterSubstance3D - Painter versions 12.0.2 and earlier are affected by an out-of-bounds write vulnerability that could 116d ago

Filter the full tracker by Adobe

Our coverage of Adobe

vulnerability

Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early

CVE-2026-71362critical

Critical Adobe Commerce Flaw Exploited After Disclosure

Attackers are actively exploiting a critical vulnerability in Adobe Commerce, identified as CVE-2026-71362, shortly after its public disclosure. This flaw allows unauthenticated attackers to hijack customer accounts and access sensitive data by switching user sessions. Adobe has released an isolated patch to address this and other vulnerabilities.

CVE-2026-71362

Adobe Commerce Bug Targeted Immediately After Disclosure

The first exploitation attempts targeting CVE-2026-71362 were observed shortly after Adobe released patches. The post Adobe Commerce Bug Targeted Immediately After Disclosure appeared first on SecurityWeek.

CVE-2026-71362critical

Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

Attempts to exploit a critical vulnerability (CVE-2026-71362) in Adobe's Commerce and Magento e-commerce platforms have been detected, potentially allowing attackers to hijack customer accounts. [...]

adobecritical

Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws

Adobe has released urgent security updates for critical vulnerabilities affecting its ColdFusion and Campaign Classic products. Exploitation of these flaws could lead to arbitrary code execution or denial-of-service attacks.

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

CVE-2026-48449

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system. It has been described as a case of incorrect authorization that could result in

CVE-2026-48294

Adobe Acrobat Chrome extension bug enabled silent WhatsApp data theft

Adobe patched CVE-2026-48294, a flaw in Adobe Acrobat Chrome extension that could let attackers steal WhatsApp Web chats by luring users to a webpage. Guardio Labs researcher Shaked Biner disclosed HermeticReader, a vulnerability chain in the Adobe Acrobat Chrome extension that allowed any attacker-controlled webpage to silently steal a visitor’s WhatsApp chats, contacts, profile name, […]

CVE-2026-48282critical

U.S. CISA adds Adobe ColdFusion, Joomlack Page Builder, Langflow, and JoomShaper SP Page Builder flaws to its Known Exploited Vulnerabilities catalog

The U.S. CISA has added several vulnerabilities to its catalog of actively exploited flaws. These include a critical path traversal vulnerability in Adobe ColdFusion that allows for unauthenticated code execution, and multiple issues affecting Joomlack Page Builder and JoomShaper SP Page Builder that can lead to unauthorized access and malicious file uploads. Organizations are urged to update affected software immediately.

cisacritical

CISA orders feds to patch max severity ColdFusion flaw by Friday

The Cybersecurity and Infrastructure Security Agency (CISA) has mandated that federal agencies address a maximum-severity Adobe ColdFusion vulnerability. This flaw is currently being actively exploited and requires patching by Friday.

CVE-2026-48282high

CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV

CISA has incorporated four new vulnerabilities into its Known Exploited Vulnerabilities (KEV) catalog. These flaws, affecting products from Adobe, Joomla, and Langflow, are all currently under active exploitation.

CVE-2026-48282critical

Critical Adobe ColdFusion Vulnerability Exploited in Attacks

A critical Adobe ColdFusion vulnerability, CVE-2026-48282 with a maximum CVSS score of 10, is being actively exploited in attacks. The flaw poses a severe risk to affected systems.