Skip to content
COOEY

FAIL › dossier

Adobe

COMPANY FEDRAMP MARKET

FedRAMP provider · · dossier confidence 40%

Adobe Inc. is a public technology company focused on digital media and content creation tools. Security posture is high-risk due to multiple critical RCE vulnerabilities in ColdFusion and Acrobat products, with recent CVEs added to CISA KEV in 2026.

PROFILE
CategorySoftware VendorWhat they doAdobe Inc. operates as a technology company worldwide, offering products and services that enable individuals, teams, and enterprises to create, publish, and promote content.OwnershipPublic Websitehttps://stockanalysis.com/stocks/adbe/company/ ↗
SECURITY POSTURE

High-risk vendor with a history of critical RCE vulnerabilities in Adobe ColdFusion and Acrobat products, including multiple CVEs added to CISA KEV in 2026.

Notable failures
  • CVE-2026-48282: Adobe ColdFusion path traversal RCE
  • CVE-2026-34621: Adobe Acrobat prototype pollution RCE
  • CVE-2020-9715: Adobe Acrobat use-after-free RCE
  • CVE-2009-3459: Adobe Acrobat heap-based buffer overflow RCE
Patterns: Repeated high-severity RCE in Adobe ColdFusion and Acrobat; Active exploitation of Adobe ColdFusion vulnerabilities
FAILURE HISTORY · 60
DATEEVENTSEVSUMMARY
2022-03-03 CVE-2015-7645 critical Adobe Flash Player vulnerabilities allowed attackers to execute arbitrary code via malicious SWF files, and no patches are available due to the product's end-of-life status.
2022-03-03 CVE-2008-2992 critical A critical, actively exploited vulnerability in Adobe Acrobat and Reader allows for potential remote code execution.
2022-03-03 CVE-2016-1019 critical Adobe Flash Player, now defunct, contained a critical, actively exploited remote code execution vulnerability, leaving systems perpetually exposed to attack.
2021-11-03 CVE-2018-4878 critical Adobe Flash Player's use-after-free vulnerability allows for code execution and is actively exploited, despite the product's end-of-life status and lack of updates.
2026-04-13 CVE-2026-34621 high Adobe Acrobat and Reader are actively exploited for arbitrary code execution via prototype pollution.
2026-04-13 CVE-2020-9715 high Adobe Acrobat use-after-free vulnerability (CVE-2020-9715) enables remote code execution and was actively exploited in the wild.
2024-09-17 CVE-2014-0502 high Adobe Flash Player's unpatched double-free RCE vulnerability (CVE-2014-0502) remains exploitable due to the product's EOL status.
2024-09-17 CVE-2014-0497 high Adobe Flash Player's integer underflow vulnerability enabled remote code execution and is actively exploited, posing a critical risk to legacy systems still in use.
2024-09-17 CVE-2013-0643 high Adobe Flash Player's discontinued status leaves unpatched RCE vulnerabilities exploitable in legacy systems.
2024-09-17 CVE-2013-0648 high Adobe Flash Player's unpatched EOL status leaves remote code execution vulnerabilities perpetually exploitable.
2024-01-08 CVE-2023-38203 critical Adobe ColdFusion suffered a critical deserialization vulnerability allowing remote code execution, linked to ransomware attacks.
2024-01-08 CVE-2023-29300 critical Adobe ColdFusion suffered a critical deserialization vulnerability allowing remote code execution, linked to ransomware attacks.
2022-06-08 CVE-2010-1297 high Adobe Flash Player's unpatched memory corruption vulnerability allowed remote attackers to execute code, a critical flaw in an end-of-life product that remains a perpetual security liability.
2022-06-08 CVE-2007-5659 high A buffer overflow in Adobe Acrobat and Reader allowed remote attackers to execute code via malicious PDF files.
2022-05-23 CVE-2018-5002 high Adobe Flash Player's unpatched stack-based buffer overflow allowed remote code execution, proving that end-of-life software remains a perpetual liability.
2022-03-07 CVE-2009-3960 critical A decade-old Adobe BlazeDS vulnerability is actively exploited, potentially exposing sensitive information in systems using LifeCycle and ColdFusion applications.
2022-02-15 CVE-2018-15982 critical Adobe Flash Player, now end-of-life, contained a critical use-after-free vulnerability actively exploited by ransomware actors, leaving systems perpetually exposed.
2022-05-25 CVE-2016-0984 high Adobe Flash Player and AIR contained a use-after-free vulnerability allowing remote code execution, which was actively exploited in the wild.
2022-05-25 CVE-2015-8651 high Adobe Flash Player's integer overflow vulnerability allowed remote code execution, and the product's end-of-life status left it perpetually unpatched and exploitable.
2022-05-25 CVE-2014-0546 high Adobe Reader and Acrobat allowed attackers to bypass sandbox protections and execute privileged native code via CVE-2014-0546.
2022-05-25 CVE-2016-1010 high An integer overflow vulnerability in Adobe Flash Player and AIR allowed attackers to execute arbitrary code.
2022-05-25 CVE-2015-0310 high Adobe Flash Player's ASLR bypass vulnerability allowed attackers to bypass memory randomization protections, enabling remote code execution.
2025-10-24 CVE-2025-54236 high Adobe's Magento suffered an unpatched input validation flaw exploited in the wild, allowing remote code execution and potential account takeover via the REST API.
2025-10-15 CVE-2025-54253 high Adobe AEM Forms JEE arbitrary code execution flaw actively exploited
2023-10-10 CVE-2023-21608 high Adobe Acrobat and Reader Use-After-Free Vulnerability
2023-09-14 CVE-2023-26369 high Adobe Acrobat and Reader out-of-bounds write vulnerability allows code execution.
2023-08-21 CVE-2023-26359 high Adobe ColdFusion's deserialization vulnerability (CVE-2023-26359) allows for code execution, and is currently being exploited in the wild.
2023-03-15 CVE-2023-26360 high Adobe ColdFusion RCE flaw exploited before patch
2022-06-08 CVE-2011-2462 high A memory corruption vulnerability in Adobe Reader and Acrobat allowed for potential remote code execution and denial-of-service attacks, and is currently being exploited in the wild.
2022-06-08 CVE-2009-3953 high A vulnerability in Adobe Acrobat and Reader allowed attackers to execute code remotely via malicious 3D files, actively exploited in the wild and impacting DIB organizations reliant on these tools for document handling.
2022-06-08 CVE-2008-0655 high A design flaw in Adobe Acrobat and Reader allowed silent, arbitrary printing of specially crafted files, marking it as an actively exploited vulnerability.
2022-06-08 CVE-2009-1862 high Unpatched Adobe Acrobat/Reader and Flash Player RCE vulnerabilities were actively exploited in the wild, enabling remote code execution.
2022-06-08 CVE-2010-2883 high A buffer overflow in Adobe Acrobat and Reader allowed attackers to execute code remotely, actively exploited in the wild and impacting DIB organizations using these products.
2022-06-08 CVE-2011-0609 high Adobe Flash Player, now end-of-life, contained an unspecified vulnerability allowing remote code execution and denial-of-service attacks, and is actively exploited in the wild.
2022-06-08 CVE-2012-0767 high Adobe Flash Player, now end-of-life, contains a cross-site scripting vulnerability actively exploited in the wild, posing a significant risk to systems still running it despite its discontinuation and lack of updates.
2022-06-08 CVE-2018-4990 high A double-free vulnerability in Adobe Acrobat and Reader allowed for potential remote code execution, actively exploited in the wild and impacting DIB organizations reliant on these products.
2022-05-25 CVE-2014-8439 high Adobe Flash Player's dereferenced pointer vulnerability allowed remote code execution, exploited in the wild despite the product's end-of-life status.
2022-03-25 CVE-2010-2861 critical Adobe ColdFusion's directory traversal vulnerability allowed attackers to read arbitrary files via the administrator console, and is currently being exploited in the wild, often linked to ransomware attacks.
2022-03-03 CVE-2010-0188 critical A critical Adobe Reader/Acrobat vulnerability (CVE-2010-0188) allowed arbitrary code execution and is actively exploited, often linked to ransomware attacks.
2026-07-07 CVE-2026-48282 high Adobe ColdFusion allows arbitrary code execution via path traversal, enabling attackers to run commands as the current user.
2026-05-20 CVE-2009-3459 high Adobe Acrobat and Reader exploited a heap-based buffer overflow vulnerability allowing remote code execution via crafted PDF files.
2025-02-24 CVE-2017-3066 high Adobe ColdFusion's deserialization vulnerability (CVE-2017-3066) enabled arbitrary code execution, actively exploited in the wild, demonstrating a recurring security weakness in the platform.
2024-12-16 CVE-2024-20767 high Adobe ColdFusion's unpatched improper access control flaw (CVE-2024-20767) lets attackers modify restricted files via exposed admin panels.
2024-07-17 CVE-2024-34102 high Adobe Commerce and Magento Open Source contain an XXE vulnerability that enables remote code execution.
2022-04-13 CVE-2015-0311 high Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute code.
2022-03-28 CVE-2012-2034 high Adobe Flash Player contains a memory corruption vulnerability that allows for remote code execution or denial-of-service (DoS).
2022-03-25 CVE-2016-4171 high Unspecified vulnerability in Adobe Flash Player allows for remote code execution.
2022-03-25 CVE-2009-0927 high Stack-based buffer overflow in Adobe Reader and Adobe Acrobat allows remote attackers to execute arbitrary code.
2022-03-03 CVE-2013-0641 high A buffer overflow vulnerability exists in Adobe Reader which allows an attacker to perform remote code execution.
2022-03-03 CVE-2015-3043 high A memory corruption vulnerability exists in Adobe Flash Player that allows an attacker to perform remote code execution.
2022-03-03 CVE-2013-0640 high An memory corruption vulnerability exists in the acroform.dll in Adobe Reader that allows an attacker to perform remote code execution.
2022-03-03 CVE-2015-5119 high A use-after-free vulnerability exists within the ActionScript 3 ByteArray class in Adobe Flash Player that allows an attacker to perform remote code execution.
2022-03-03 CVE-2012-1535 high Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute arbitrary code or cause a denial of service via crafted SWF content.
2022-03-03 CVE-2016-4117 high An access of resource using incompatible type vulnerability exists within Adobe Flash Player that allows an attacker to perform remote code execution.
2022-03-03 CVE-2011-0611 high Adobe Flash Player contains a vulnerability that allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content.
2022-03-03 CVE-2016-7855 high Use-after-free vulnerability in Adobe Flash Player Windows and OS and Linux allows remote attackers to execute arbitrary code.
2022-03-03 CVE-2014-0496 high Adobe Reader and Acrobat contain a use-after-free vulnerability which can allow for code execution.
2022-03-03 CVE-2013-3346 high Adobe Reader and Acrobat contain a memory corruption vulnerability which can allow attackers to execute arbitrary code or cause a denial of service.
2022-03-03 CVE-2017-11292 high Adobe Flash Player contains a type confusion vulnerability which can allow for remote code execution.
2022-02-15 CVE-2022-24086 high Adobe Commerce and Magento Open Source contain an improper input validation vulnerability which can allow for arbitrary code execution.
SENTIMENT · TRUSTED SOURCES
synthesisneutral-0.20
No direct press or authority commentary on Adobe's handling of CVE-2018-15961 is present in the provided sources; only technical vulnerability descriptions and generic vendor/product listings are avai
synthesissevere-fallout-0.60
Adobe's Flash Player vulnerability was widely recognized as a critical flaw enabling code execution, reflecting severe fallout for the vendor.
synthesisneutral+0.00
No sentiment expressed; sources are technical databases or aggregators without commentary on Adobe's handling.
synthesisneutral+0.00
No sentiment expressed; sources are technical databases or vendor pages without commentary on Adobe's handling.
synthesissevere-fallout-0.60
Adobe's CVE-2018-4939 deserialization flaw allowing code execution was widely recognized as a critical vulnerability, though the provided sources lack specific press coverage or authority commentary o
www.vulncheck.com ↗severe-fallout+0.00
No relevant content regarding Adobe or CVE-2018-4939.
cvefeed.io ↗severe-fallout+0.00
No relevant content regarding Adobe or CVE-2018-4939.
cooey ↗neutral+0.00
Neutral technical description; no sentiment toward Adobe.
"Acrobat Acrobat and Reader contain a heap-based buffer overflow vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user."
Neutral database listing; no sentiment toward Adobe.
app.opencve.io ↗neutral+0.00
Neutral database listing; no sentiment toward Adobe.
SentinelOne ↗neutral+0.00
Neutral database listing; no sentiment toward Adobe.
cvefeed.io ↗neutral+0.00
Neutral database listing; no sentiment toward Adobe.
cooey ↗neutral+0.00
Neutral; technical description only.
"Adobe Acrobat and Reader contains a use-after-free vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user."
Neutral; no commentary on Adobe.
app.opencve.io ↗neutral+0.00
Neutral; no commentary on Adobe.
cvefeed.io ↗neutral+0.00
Neutral; no commentary on Adobe.
SentinelOne ↗neutral+0.00
Neutral; no commentary on Adobe.
No relevant content.
cooey ↗severe-fallout-0.80
Severe vulnerability in Flash Player allowing code execution, widely condemned as a critical flaw.
"Adobe Flash Player contains a use-after-free vulnerability that could allow for code execution."
NVD ↗severe-fallout+0.00
No substantive coverage of CVE-2018-4878; page is unauthorized frame with redirect warning.
www.cisecurity.org ↗severe-fallout-0.50
Mentions multiple Adobe vulnerabilities including arbitrary code execution, but lacks specific focus on CVE-2018-4878.
"Multiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution."
The Hacker News ↗severe-fallout+0.00
No coverage of CVE-2018-4878; focuses on 2026 Firefox/Chrome/Adobe/VMware updates.
www.cvefind.com ↗severe-fallout+0.00
No coverage of CVE-2018-4878; generic CVE database page.
cooey ↗neutral+0.00
Neutral technical description only.
"Adobe ColdFusion contains an unrestricted file upload vulnerability that could allow for code execution."
Neutral product listing.
"Adobe ColdFusion is a commercial rapid web application development platform used to build and deploy dynamic web and mobile applications."
CISA ↗neutral+0.00
No relevant content.
app.opencve.io ↗neutral+0.00
No relevant content.
cooey ↗severe-fallout-0.60
Critical vulnerability acknowledged but no specific praise or condemnation of Adobe's handling is present in the source text.
"Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could allow for code execution."
app.opencve.io ↗severe-fallout+0.00
No relevant content regarding Adobe or CVE-2018-4939.
SentinelOne ↗severe-fallout+0.00
No relevant content regarding Adobe or CVE-2018-4939.
FEDRAMP CATALOG PRODUCTS · 8
Open questions: Adobe's remediation timeline for CVE-2026-48282 · Impact of CVE-2026-34621 on enterprise deployments
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-13 14:11:10.421049+00:00