Skip to content
COOEY

FAIL › dossier

Adobe

COMPANY FEDRAMP MARKET

FedRAMP provider · · dossier confidence 40%

Adobe Inc. is a public technology company focused on digital media and content creation tools. Security posture is high-risk due to multiple critical RCE vulnerabilities in ColdFusion and Acrobat products, with recent CVEs added to CISA KEV in 2026.

PROFILE
CategorySoftware VendorWhat they doAdobe Inc. operates as a technology company worldwide, offering products and services that enable individuals, teams, and enterprises to create, publish, and promote content.OwnershipPublic Websitehttps://stockanalysis.com/stocks/adbe/company/ ↗
SECURITY POSTURE

High-risk vendor with a history of critical RCE vulnerabilities in Adobe ColdFusion and Acrobat products, including multiple CVEs added to CISA KEV in 2026.

Notable failures
  • CVE-2026-48282: Adobe ColdFusion path traversal RCE
  • CVE-2026-34621: Adobe Acrobat prototype pollution RCE
  • CVE-2020-9715: Adobe Acrobat use-after-free RCE
  • CVE-2009-3459: Adobe Acrobat heap-based buffer overflow RCE
Patterns: Repeated high-severity RCE in Adobe ColdFusion and Acrobat; Active exploitation of Adobe ColdFusion vulnerabilities
FAILURE HISTORY · 60
DATEEVENTSEVSUMMARY
2022-03-03 CVE-2016-1019 critical Adobe Flash Player, now defunct, contained a critical, actively exploited remote code execution vulnerability, leaving systems perpetually exposed to attack.
2022-03-03 CVE-2008-2992 critical A critical, actively exploited vulnerability in Adobe Acrobat and Reader allows for potential remote code execution.
2022-03-03 CVE-2015-7645 critical Adobe Flash Player vulnerabilities allowed attackers to execute arbitrary code via malicious SWF files, and no patches are available due to the product's end-of-life status.
2021-11-03 CVE-2018-4878 critical Adobe Flash Player's use-after-free vulnerability allows for code execution and is actively exploited, despite the product's end-of-life status and lack of updates.
2026-04-13 CVE-2020-9715 high Adobe Acrobat use-after-free vulnerability (CVE-2020-9715) enables remote code execution and was actively exploited in the wild.
2026-04-13 CVE-2026-34621 high Adobe Acrobat and Reader are actively exploited for arbitrary code execution via prototype pollution.
2024-09-17 CVE-2013-0643 high Adobe Flash Player's discontinued status leaves unpatched RCE vulnerabilities exploitable in legacy systems.
2024-09-17 CVE-2014-0502 high Adobe Flash Player's unpatched double-free RCE vulnerability (CVE-2014-0502) remains exploitable due to the product's EOL status.
2024-09-17 CVE-2013-0648 high Adobe Flash Player's unpatched EOL status leaves remote code execution vulnerabilities perpetually exploitable.
2024-09-17 CVE-2014-0497 high Adobe Flash Player's integer underflow vulnerability enabled remote code execution and is actively exploited, posing a critical risk to legacy systems still in use.
2024-01-08 CVE-2023-38203 critical Adobe ColdFusion suffered a critical deserialization vulnerability allowing remote code execution, linked to ransomware attacks.
2024-01-08 CVE-2023-29300 critical Adobe ColdFusion suffered a critical deserialization vulnerability allowing remote code execution, linked to ransomware attacks.
2022-06-08 CVE-2010-1297 high Adobe Flash Player's unpatched memory corruption vulnerability allowed remote attackers to execute code, a critical flaw in an end-of-life product that remains a perpetual security liability.
2022-06-08 CVE-2007-5659 high A buffer overflow in Adobe Acrobat and Reader allowed remote attackers to execute code via malicious PDF files.
2022-05-23 CVE-2018-5002 high Adobe Flash Player's unpatched stack-based buffer overflow allowed remote code execution, proving that end-of-life software remains a perpetual liability.
2022-04-13 CVE-2015-0311 high Adobe Flash Player's unpatched RCE vulnerability remains a perpetual liability after its December 2020 end-of-life.
2022-04-13 CVE-2015-5123 high Adobe Flash Player's use-after-free vulnerability allowed remote attackers to execute arbitrary code, and the product's end-of-life status left it perpetually unpatched.
2022-04-13 CVE-2015-0313 high Adobe Flash Player's use-after-free vulnerability allowed remote attackers to execute arbitrary code, a flaw that persisted after the product's end-of-life in 2020.
2022-04-13 CVE-2014-9163 high Adobe Flash Player's unpatched stack-based buffer overflow allowed remote code execution, proving that end-of-life software remains a perpetual liability.
2022-03-25 CVE-2016-4171 high Adobe Flash Player's end-of-life status left unpatched RCE vulnerabilities perpetually exploitable, exemplifying the catastrophic risk of shipping and maintaining obsolete software.
2022-03-07 CVE-2013-0625 high An authentication bypass in Adobe ColdFusion allowed unauthorized administrative access, later linked to CVSS 10.0 command and eval injection flaws.
2022-03-07 CVE-2013-0631 high Adobe ColdFusion suffered from critical unpatched command injection and eval injection flaws enabling remote code execution and privilege escalation.
2022-03-03 CVE-2012-1535 high Adobe Flash Player's unpatched arbitrary code execution vulnerability remains a perpetual liability after its December 2020 end-of-life.
2022-03-03 CVE-2015-3043 high Adobe Flash Player's unpatched memory corruption flaw allowed remote code execution, proving that end-of-life software remains a perpetual security liability.
2022-03-03 CVE-2011-0611 high Adobe Flash Player's unpatched remote code execution vulnerability (CVE-2011-0611) remains actively exploited in the wild despite the product's end-of-life in 2020.
2022-03-03 CVE-2013-0632 high An authentication bypass in Adobe ColdFusion allowed unauthorized administrative access, later linked to CVSS 10.0 command and eval injection flaws.
2022-03-03 CVE-2016-4117 high Adobe Flash Player's end-of-life status left unpatched RCE vulnerabilities perpetually exploitable, exemplifying the catastrophic risk of shipping and maintaining obsolete software.
2021-11-03 CVE-2021-21017 high Adobe Acrobat and Reader suffered a heap-based buffer overflow allowing unauthenticated remote code execution, a known critical flaw repeatedly exploited in the wild.
2021-11-03 CVE-2018-4939 high Adobe ColdFusion suffered a deserialization of untrusted data vulnerability allowing remote code execution.
2022-03-07 CVE-2009-3960 critical A decade-old Adobe BlazeDS vulnerability is actively exploited, potentially exposing sensitive information in systems using LifeCycle and ColdFusion applications.
2022-02-15 CVE-2018-15982 critical Adobe Flash Player, now end-of-life, contained a critical use-after-free vulnerability actively exploited by ransomware actors, leaving systems perpetually exposed.
2022-05-25 CVE-2015-8651 high Adobe Flash Player's integer overflow vulnerability allowed remote code execution, and the product's end-of-life status left it perpetually unpatched and exploitable.
2022-05-25 CVE-2014-0546 high Adobe Reader and Acrobat allowed attackers to bypass sandbox protections and execute privileged native code via CVE-2014-0546.
2022-05-25 CVE-2016-0984 high Adobe Flash Player and AIR contained a use-after-free vulnerability allowing remote code execution, which was actively exploited in the wild.
2022-05-25 CVE-2016-1010 high An integer overflow vulnerability in Adobe Flash Player and AIR allowed attackers to execute arbitrary code.
2022-04-13 CVE-2015-5122 high Adobe Flash Player's use-after-free vulnerability allowed remote attackers to execute arbitrary code, and the product's end-of-life status meant it remained perpetually unpatched and exploitable.
2022-04-13 CVE-2015-3113 high Adobe Flash Player's unpatched heap-based buffer overflow allowed remote attackers to execute code, proving that end-of-life software remains a perpetual security liability.
2022-03-25 CVE-2016-7892 high An unpatched use-after-free vulnerability in Adobe Flash Player allowed remote code execution, exploited in the wild after Flash reached end-of-life in 2020.
2022-03-03 CVE-2013-0640 high Adobe Reader and Acrobat contained a memory corruption vulnerability in acroform.dll enabling remote code execution.
2022-03-03 CVE-2015-5119 high Adobe Flash Player's use-after-free vulnerability allowed remote code execution, and the product's end-of-life status meant it remained perpetually unpatched and exploitable.
2022-03-03 CVE-2013-0641 high Adobe Reader's unpatched buffer overflow vulnerability allowed remote code execution and was actively exploited in the wild.
2022-03-03 CVE-2016-7855 high Adobe Flash Player's use-after-free vulnerability allowed remote attackers to execute arbitrary code, and the product's end-of-life status left it perpetually unpatched.
2022-03-03 CVE-2017-11292 high Adobe Flash Player's unpatched type confusion vulnerability allowed remote code execution, proving that end-of-life software remains a perpetual security liability.
2021-11-03 CVE-2018-15961 high Adobe ColdFusion's unrestricted file upload flaw allowed remote code execution, enabling attackers to upload and execute malicious files on vulnerable systems.
2022-05-25 CVE-2015-0310 high Adobe Flash Player's ASLR bypass vulnerability allowed attackers to bypass memory randomization protections, enabling remote code execution.
2022-03-25 CVE-2009-0927 high Adobe Reader and Acrobat contained a stack-based buffer overflow allowing remote attackers to execute arbitrary code.
2022-02-15 CVE-2022-24086 high Improper input validation in Adobe Commerce and Magento Open Source allowed arbitrary code execution.
2021-11-03 CVE-2021-28550 high Adobe Acrobat and Reader suffered a use-after-free vulnerability allowing unauthenticated remote code execution.
2025-10-24 CVE-2025-54236 high Adobe's Magento suffered an unpatched input validation flaw exploited in the wild, allowing remote code execution and potential account takeover via the REST API.
2025-10-15 CVE-2025-54253 high Adobe AEM Forms JEE arbitrary code execution flaw actively exploited
2023-10-10 CVE-2023-21608 high Adobe Acrobat and Reader Use-After-Free Vulnerability
2023-09-14 CVE-2023-26369 high Adobe Acrobat and Reader out-of-bounds write vulnerability allows code execution.
2023-08-21 CVE-2023-26359 high Adobe ColdFusion's deserialization vulnerability (CVE-2023-26359) allows for code execution, and is currently being exploited in the wild.
2023-03-15 CVE-2023-26360 high Adobe ColdFusion RCE flaw exploited before patch
2022-06-08 CVE-2018-4990 high A double-free vulnerability in Adobe Acrobat and Reader allowed for potential remote code execution, actively exploited in the wild and impacting DIB organizations reliant on these products.
2022-06-08 CVE-2012-0767 high Adobe Flash Player, now end-of-life, contains a cross-site scripting vulnerability actively exploited in the wild, posing a significant risk to systems still running it despite its discontinuation and lack of updates.
2022-06-08 CVE-2011-2462 high A memory corruption vulnerability in Adobe Reader and Acrobat allowed for potential remote code execution and denial-of-service attacks, and is currently being exploited in the wild.
2022-06-08 CVE-2011-0609 high Adobe Flash Player, now end-of-life, contained an unspecified vulnerability allowing remote code execution and denial-of-service attacks, and is actively exploited in the wild.
2022-06-08 CVE-2010-2883 high A buffer overflow in Adobe Acrobat and Reader allowed attackers to execute code remotely, actively exploited in the wild and impacting DIB organizations using these products.
2022-06-08 CVE-2009-1862 high Unpatched Adobe Acrobat/Reader and Flash Player RCE vulnerabilities were actively exploited in the wild, enabling remote code execution.
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.60
Adobe's Flash Player vulnerability was widely recognized as a critical flaw enabling code execution, reflecting severe fallout for the vendor.
synthesissevere-fallout-0.60
Adobe's CVE-2018-4939 deserialization flaw allowing code execution was widely recognized as a critical vulnerability, though the provided sources lack specific press coverage or authority commentary o
synthesisneutral+0.00
No sentiment expressed; sources are technical databases or vendor pages without commentary on Adobe's handling.
synthesisneutral-0.20
No direct press or authority commentary on Adobe's handling of CVE-2018-15961 is present in the provided sources; only technical vulnerability descriptions and generic vendor/product listings are avai
synthesisneutral+0.00
No sentiment expressed; sources are technical databases or aggregators without commentary on Adobe's handling.
synthesissevere-fallout-0.60
Adobe faced severe fallout for CVE-2016-1019, with the vulnerability being actively exploited in the wild, though provided sources lack direct commentary on Adobe's response or reputation impact, focu
synthesissevere-fallout-0.60
CVE-2010-2861 is a critical directory traversal flaw in Adobe ColdFusion's admin console allowing arbitrary file reads; NVD confirms severity, though provided sources lack direct commentary on Adobe's
cooey ↗neutral+0.00
Neutral technical description; no sentiment toward Adobe.
"Acrobat Acrobat and Reader contain a heap-based buffer overflow vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user."
Neutral database listing; no sentiment toward Adobe.
SentinelOne ↗neutral+0.00
Neutral database listing; no sentiment toward Adobe.
cvefeed.io ↗neutral+0.00
Neutral database listing; no sentiment toward Adobe.
cooey ↗neutral+0.00
Neutral; technical description only.
"Adobe Acrobat and Reader contains a use-after-free vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user."
Neutral; no commentary on Adobe.
app.opencve.io ↗neutral+0.00
Neutral; no commentary on Adobe.
cvefeed.io ↗neutral+0.00
Neutral; no commentary on Adobe.
SentinelOne ↗neutral+0.00
Neutral; no commentary on Adobe.
No relevant content.
cooey ↗severe-fallout-0.80
Severe vulnerability in Flash Player allowing code execution, widely condemned as a critical flaw.
"Adobe Flash Player contains a use-after-free vulnerability that could allow for code execution."
NVD ↗severe-fallout+0.00
No substantive coverage of CVE-2018-4878; page is unauthorized frame with redirect warning.
www.cisecurity.org ↗severe-fallout-0.50
Mentions multiple Adobe vulnerabilities including arbitrary code execution, but lacks specific focus on CVE-2018-4878.
"Multiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution."
The Hacker News ↗severe-fallout+0.00
No coverage of CVE-2018-4878; focuses on 2026 Firefox/Chrome/Adobe/VMware updates.
www.cvefind.com ↗severe-fallout+0.00
No coverage of CVE-2018-4878; generic CVE database page.
cooey ↗neutral+0.00
Neutral technical description only.
"Adobe ColdFusion contains an unrestricted file upload vulnerability that could allow for code execution."
Neutral product listing.
"Adobe ColdFusion is a commercial rapid web application development platform used to build and deploy dynamic web and mobile applications."
CISA ↗neutral+0.00
No relevant content.
app.opencve.io ↗neutral+0.00
No relevant content.
app.opencve.io ↗neutral+0.00
Neutral database listing; no sentiment toward Adobe.
cooey ↗severe-fallout-0.60
Critical vulnerability acknowledged but no specific praise or condemnation of Adobe's handling is present in the source text.
"Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could allow for code execution."
app.opencve.io ↗severe-fallout+0.00
No relevant content regarding Adobe or CVE-2018-4939.
SentinelOne ↗severe-fallout+0.00
No relevant content regarding Adobe or CVE-2018-4939.
FEDRAMP CATALOG PRODUCTS · 8
Open questions: Adobe's remediation timeline for CVE-2026-48282 · Impact of CVE-2026-34621 on enterprise deployments
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-13 14:11:10.421049+00:00