FAIL › dossier
Adobe
COMPANY FEDRAMP MARKETFedRAMP provider · · dossier confidence 40%
Adobe Inc. is a public technology company focused on digital media and content creation tools. Security posture is high-risk due to multiple critical RCE vulnerabilities in ColdFusion and Acrobat products, with recent CVEs added to CISA KEV in 2026.
PROFILE
CategorySoftware VendorWhat they doAdobe Inc. operates as a technology company worldwide, offering products and services that enable individuals, teams, and enterprises to create, publish, and promote content.OwnershipPublic
Websitehttps://stockanalysis.com/stocks/adbe/company/ ↗
SECURITY POSTURE
High-risk vendor with a history of critical RCE vulnerabilities in Adobe ColdFusion and Acrobat products, including multiple CVEs added to CISA KEV in 2026.
Notable failures
- CVE-2026-48282: Adobe ColdFusion path traversal RCE
- CVE-2026-34621: Adobe Acrobat prototype pollution RCE
- CVE-2020-9715: Adobe Acrobat use-after-free RCE
- CVE-2009-3459: Adobe Acrobat heap-based buffer overflow RCE
Patterns: Repeated high-severity RCE in Adobe ColdFusion and Acrobat; Active exploitation of Adobe ColdFusion vulnerabilities
FAILURE HISTORY · 60
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2022-03-03 | CVE-2015-7645 | critical | Adobe Flash Player vulnerabilities allowed attackers to execute arbitrary code via malicious SWF files, and no patches are available due to the product's end-of-life status. |
| 2022-03-03 | CVE-2008-2992 | critical | A critical, actively exploited vulnerability in Adobe Acrobat and Reader allows for potential remote code execution. |
| 2022-03-03 | CVE-2016-1019 | critical | Adobe Flash Player, now defunct, contained a critical, actively exploited remote code execution vulnerability, leaving systems perpetually exposed to attack. |
| 2021-11-03 | CVE-2018-4878 | critical | Adobe Flash Player's use-after-free vulnerability allows for code execution and is actively exploited, despite the product's end-of-life status and lack of updates. |
| 2026-04-13 | CVE-2026-34621 | high | Adobe Acrobat and Reader are actively exploited for arbitrary code execution via prototype pollution. |
| 2026-04-13 | CVE-2020-9715 | high | Adobe Acrobat use-after-free vulnerability (CVE-2020-9715) enables remote code execution and was actively exploited in the wild. |
| 2024-09-17 | CVE-2014-0502 | high | Adobe Flash Player's unpatched double-free RCE vulnerability (CVE-2014-0502) remains exploitable due to the product's EOL status. |
| 2024-09-17 | CVE-2014-0497 | high | Adobe Flash Player's integer underflow vulnerability enabled remote code execution and is actively exploited, posing a critical risk to legacy systems still in use. |
| 2024-09-17 | CVE-2013-0643 | high | Adobe Flash Player's discontinued status leaves unpatched RCE vulnerabilities exploitable in legacy systems. |
| 2024-09-17 | CVE-2013-0648 | high | Adobe Flash Player's unpatched EOL status leaves remote code execution vulnerabilities perpetually exploitable. |
| 2024-01-08 | CVE-2023-38203 | critical | Adobe ColdFusion suffered a critical deserialization vulnerability allowing remote code execution, linked to ransomware attacks. |
| 2024-01-08 | CVE-2023-29300 | critical | Adobe ColdFusion suffered a critical deserialization vulnerability allowing remote code execution, linked to ransomware attacks. |
| 2022-06-08 | CVE-2010-1297 | high | Adobe Flash Player's unpatched memory corruption vulnerability allowed remote attackers to execute code, a critical flaw in an end-of-life product that remains a perpetual security liability. |
| 2022-06-08 | CVE-2007-5659 | high | A buffer overflow in Adobe Acrobat and Reader allowed remote attackers to execute code via malicious PDF files. |
| 2022-05-23 | CVE-2018-5002 | high | Adobe Flash Player's unpatched stack-based buffer overflow allowed remote code execution, proving that end-of-life software remains a perpetual liability. |
| 2022-03-07 | CVE-2009-3960 | critical | A decade-old Adobe BlazeDS vulnerability is actively exploited, potentially exposing sensitive information in systems using LifeCycle and ColdFusion applications. |
| 2022-02-15 | CVE-2018-15982 | critical | Adobe Flash Player, now end-of-life, contained a critical use-after-free vulnerability actively exploited by ransomware actors, leaving systems perpetually exposed. |
| 2022-05-25 | CVE-2016-0984 | high | Adobe Flash Player and AIR contained a use-after-free vulnerability allowing remote code execution, which was actively exploited in the wild. |
| 2022-05-25 | CVE-2015-8651 | high | Adobe Flash Player's integer overflow vulnerability allowed remote code execution, and the product's end-of-life status left it perpetually unpatched and exploitable. |
| 2022-05-25 | CVE-2014-0546 | high | Adobe Reader and Acrobat allowed attackers to bypass sandbox protections and execute privileged native code via CVE-2014-0546. |
| 2022-05-25 | CVE-2016-1010 | high | An integer overflow vulnerability in Adobe Flash Player and AIR allowed attackers to execute arbitrary code. |
| 2022-05-25 | CVE-2015-0310 | high | Adobe Flash Player's ASLR bypass vulnerability allowed attackers to bypass memory randomization protections, enabling remote code execution. |
| 2025-10-24 | CVE-2025-54236 | high | Adobe's Magento suffered an unpatched input validation flaw exploited in the wild, allowing remote code execution and potential account takeover via the REST API. |
| 2025-10-15 | CVE-2025-54253 | high | Adobe AEM Forms JEE arbitrary code execution flaw actively exploited |
| 2023-10-10 | CVE-2023-21608 | high | Adobe Acrobat and Reader Use-After-Free Vulnerability |
| 2023-09-14 | CVE-2023-26369 | high | Adobe Acrobat and Reader out-of-bounds write vulnerability allows code execution. |
| 2023-08-21 | CVE-2023-26359 | high | Adobe ColdFusion's deserialization vulnerability (CVE-2023-26359) allows for code execution, and is currently being exploited in the wild. |
| 2023-03-15 | CVE-2023-26360 | high | Adobe ColdFusion RCE flaw exploited before patch |
| 2022-06-08 | CVE-2011-2462 | high | A memory corruption vulnerability in Adobe Reader and Acrobat allowed for potential remote code execution and denial-of-service attacks, and is currently being exploited in the wild. |
| 2022-06-08 | CVE-2009-3953 | high | A vulnerability in Adobe Acrobat and Reader allowed attackers to execute code remotely via malicious 3D files, actively exploited in the wild and impacting DIB organizations reliant on these tools for document handling. |
| 2022-06-08 | CVE-2008-0655 | high | A design flaw in Adobe Acrobat and Reader allowed silent, arbitrary printing of specially crafted files, marking it as an actively exploited vulnerability. |
| 2022-06-08 | CVE-2009-1862 | high | Unpatched Adobe Acrobat/Reader and Flash Player RCE vulnerabilities were actively exploited in the wild, enabling remote code execution. |
| 2022-06-08 | CVE-2010-2883 | high | A buffer overflow in Adobe Acrobat and Reader allowed attackers to execute code remotely, actively exploited in the wild and impacting DIB organizations using these products. |
| 2022-06-08 | CVE-2011-0609 | high | Adobe Flash Player, now end-of-life, contained an unspecified vulnerability allowing remote code execution and denial-of-service attacks, and is actively exploited in the wild. |
| 2022-06-08 | CVE-2012-0767 | high | Adobe Flash Player, now end-of-life, contains a cross-site scripting vulnerability actively exploited in the wild, posing a significant risk to systems still running it despite its discontinuation and lack of updates. |
| 2022-06-08 | CVE-2018-4990 | high | A double-free vulnerability in Adobe Acrobat and Reader allowed for potential remote code execution, actively exploited in the wild and impacting DIB organizations reliant on these products. |
| 2022-05-25 | CVE-2014-8439 | high | Adobe Flash Player's dereferenced pointer vulnerability allowed remote code execution, exploited in the wild despite the product's end-of-life status. |
| 2022-03-25 | CVE-2010-2861 | critical | Adobe ColdFusion's directory traversal vulnerability allowed attackers to read arbitrary files via the administrator console, and is currently being exploited in the wild, often linked to ransomware attacks. |
| 2022-03-03 | CVE-2010-0188 | critical | A critical Adobe Reader/Acrobat vulnerability (CVE-2010-0188) allowed arbitrary code execution and is actively exploited, often linked to ransomware attacks. |
| 2026-07-07 | CVE-2026-48282 | high | Adobe ColdFusion allows arbitrary code execution via path traversal, enabling attackers to run commands as the current user. |
| 2026-05-20 | CVE-2009-3459 | high | Adobe Acrobat and Reader exploited a heap-based buffer overflow vulnerability allowing remote code execution via crafted PDF files. |
| 2025-02-24 | CVE-2017-3066 | high | Adobe ColdFusion's deserialization vulnerability (CVE-2017-3066) enabled arbitrary code execution, actively exploited in the wild, demonstrating a recurring security weakness in the platform. |
| 2024-12-16 | CVE-2024-20767 | high | Adobe ColdFusion's unpatched improper access control flaw (CVE-2024-20767) lets attackers modify restricted files via exposed admin panels. |
| 2024-07-17 | CVE-2024-34102 | high | Adobe Commerce and Magento Open Source contain an XXE vulnerability that enables remote code execution. |
| 2022-04-13 | CVE-2015-0311 | high | Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute code. |
| 2022-03-28 | CVE-2012-2034 | high | Adobe Flash Player contains a memory corruption vulnerability that allows for remote code execution or denial-of-service (DoS). |
| 2022-03-25 | CVE-2016-4171 | high | Unspecified vulnerability in Adobe Flash Player allows for remote code execution. |
| 2022-03-25 | CVE-2009-0927 | high | Stack-based buffer overflow in Adobe Reader and Adobe Acrobat allows remote attackers to execute arbitrary code. |
| 2022-03-03 | CVE-2013-0641 | high | A buffer overflow vulnerability exists in Adobe Reader which allows an attacker to perform remote code execution. |
| 2022-03-03 | CVE-2015-3043 | high | A memory corruption vulnerability exists in Adobe Flash Player that allows an attacker to perform remote code execution. |
| 2022-03-03 | CVE-2013-0640 | high | An memory corruption vulnerability exists in the acroform.dll in Adobe Reader that allows an attacker to perform remote code execution. |
| 2022-03-03 | CVE-2015-5119 | high | A use-after-free vulnerability exists within the ActionScript 3 ByteArray class in Adobe Flash Player that allows an attacker to perform remote code execution. |
| 2022-03-03 | CVE-2012-1535 | high | Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute arbitrary code or cause a denial of service via crafted SWF content. |
| 2022-03-03 | CVE-2016-4117 | high | An access of resource using incompatible type vulnerability exists within Adobe Flash Player that allows an attacker to perform remote code execution. |
| 2022-03-03 | CVE-2011-0611 | high | Adobe Flash Player contains a vulnerability that allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content. |
| 2022-03-03 | CVE-2016-7855 | high | Use-after-free vulnerability in Adobe Flash Player Windows and OS and Linux allows remote attackers to execute arbitrary code. |
| 2022-03-03 | CVE-2014-0496 | high | Adobe Reader and Acrobat contain a use-after-free vulnerability which can allow for code execution. |
| 2022-03-03 | CVE-2013-3346 | high | Adobe Reader and Acrobat contain a memory corruption vulnerability which can allow attackers to execute arbitrary code or cause a denial of service. |
| 2022-03-03 | CVE-2017-11292 | high | Adobe Flash Player contains a type confusion vulnerability which can allow for remote code execution. |
| 2022-02-15 | CVE-2022-24086 | high | Adobe Commerce and Magento Open Source contain an improper input validation vulnerability which can allow for arbitrary code execution. |
SENTIMENT · TRUSTED SOURCES
synthesisneutral-0.20
No direct press or authority commentary on Adobe's handling of CVE-2018-15961 is present in the provided sources; only technical vulnerability descriptions and generic vendor/product listings are avai
synthesissevere-fallout-0.60
Adobe's Flash Player vulnerability was widely recognized as a critical flaw enabling code execution, reflecting severe fallout for the vendor.
synthesisneutral+0.00
No sentiment expressed; sources are technical databases or aggregators without commentary on Adobe's handling.
synthesisneutral+0.00
No sentiment expressed; sources are technical databases or vendor pages without commentary on Adobe's handling.
synthesissevere-fallout-0.60
Adobe's CVE-2018-4939 deserialization flaw allowing code execution was widely recognized as a critical vulnerability, though the provided sources lack specific press coverage or authority commentary o
No relevant content regarding Adobe or CVE-2018-4939.
No relevant content regarding Adobe or CVE-2018-4939.
Neutral technical description; no sentiment toward Adobe.
"Acrobat Acrobat and Reader contain a heap-based buffer overflow vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user."
Neutral database listing; no sentiment toward Adobe.
Neutral database listing; no sentiment toward Adobe.
Neutral database listing; no sentiment toward Adobe.
Neutral database listing; no sentiment toward Adobe.
Neutral; technical description only.
"Adobe Acrobat and Reader contains a use-after-free vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user."
Neutral; no commentary on Adobe.
Neutral; no commentary on Adobe.
Neutral; no commentary on Adobe.
Neutral; no commentary on Adobe.
No relevant content.
Severe vulnerability in Flash Player allowing code execution, widely condemned as a critical flaw.
"Adobe Flash Player contains a use-after-free vulnerability that could allow for code execution."
No substantive coverage of CVE-2018-4878; page is unauthorized frame with redirect warning.
Mentions multiple Adobe vulnerabilities including arbitrary code execution, but lacks specific focus on CVE-2018-4878.
"Multiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution."
No coverage of CVE-2018-4878; focuses on 2026 Firefox/Chrome/Adobe/VMware updates.
No coverage of CVE-2018-4878; generic CVE database page.
Neutral technical description only.
"Adobe ColdFusion contains an unrestricted file upload vulnerability that could allow for code execution."
Neutral product listing.
"Adobe ColdFusion is a commercial rapid web application development platform used to build and deploy dynamic web and mobile applications."
No relevant content.
No relevant content.
Critical vulnerability acknowledged but no specific praise or condemnation of Adobe's handling is present in the source text.
"Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could allow for code execution."
No relevant content regarding Adobe or CVE-2018-4939.
No relevant content regarding Adobe or CVE-2018-4939.
FEDRAMP CATALOG PRODUCTS · 8
| PRODUCT | STATUS | IMPACT |
|---|---|---|
| Adobe Acrobat Sign for Government | Authorized | Moderate |
| Adobe Analytics | Authorized | LI-SaaS |
| Adobe Campaign | Authorized | LI-SaaS |
| Adobe Connect Managed Services (ACMS-GC) | Authorized | Moderate |
| Adobe Creative Cloud for Enterprise | Authorized | LI-SaaS |
| Adobe Document Cloud (PDF Services & Adobe Sign) | Authorized | LI-SaaS |
| Adobe Experience Manager Managed Services (AEMMS-GC) | Authorized | Moderate |
| Adobe Learning Manager | Authorized | LI-SaaS |
DOSSIER SOURCES
- Adobe (ADBE) Company Profile & Description - Stock Analysis · stockanalysis.com
- Patch Adobe ColdFusion CVE-2026-48282 & Others - CISA Warning · cvedaily.io
- CVE-2026-48282 Adobe ColdFusion Security Strategic Brief · thecybermind.co
- CISA Warns Adobe ColdFusion Flaw Enables Arbitrary Code Execution · cyberpress.org
Open questions: Adobe's remediation timeline for CVE-2026-48282 · Impact of CVE-2026-34621 on enterprise deployments
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-13 14:11:10.421049+00:00