FAIL › dossier
Adobe
COMPANY FEDRAMP MARKETFedRAMP provider · · dossier confidence 40%
Adobe Inc. is a public technology company focused on digital media and content creation tools. Security posture is high-risk due to multiple critical RCE vulnerabilities in ColdFusion and Acrobat products, with recent CVEs added to CISA KEV in 2026.
PROFILE
CategorySoftware VendorWhat they doAdobe Inc. operates as a technology company worldwide, offering products and services that enable individuals, teams, and enterprises to create, publish, and promote content.OwnershipPublic
Websitehttps://stockanalysis.com/stocks/adbe/company/ ↗
SECURITY POSTURE
High-risk vendor with a history of critical RCE vulnerabilities in Adobe ColdFusion and Acrobat products, including multiple CVEs added to CISA KEV in 2026.
Notable failures
- CVE-2026-48282: Adobe ColdFusion path traversal RCE
- CVE-2026-34621: Adobe Acrobat prototype pollution RCE
- CVE-2020-9715: Adobe Acrobat use-after-free RCE
- CVE-2009-3459: Adobe Acrobat heap-based buffer overflow RCE
Patterns: Repeated high-severity RCE in Adobe ColdFusion and Acrobat; Active exploitation of Adobe ColdFusion vulnerabilities
FAILURE HISTORY · 60
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2022-03-03 | CVE-2016-1019 | critical | Adobe Flash Player, now defunct, contained a critical, actively exploited remote code execution vulnerability, leaving systems perpetually exposed to attack. |
| 2022-03-03 | CVE-2008-2992 | critical | A critical, actively exploited vulnerability in Adobe Acrobat and Reader allows for potential remote code execution. |
| 2022-03-03 | CVE-2015-7645 | critical | Adobe Flash Player vulnerabilities allowed attackers to execute arbitrary code via malicious SWF files, and no patches are available due to the product's end-of-life status. |
| 2021-11-03 | CVE-2018-4878 | critical | Adobe Flash Player's use-after-free vulnerability allows for code execution and is actively exploited, despite the product's end-of-life status and lack of updates. |
| 2026-04-13 | CVE-2020-9715 | high | Adobe Acrobat use-after-free vulnerability (CVE-2020-9715) enables remote code execution and was actively exploited in the wild. |
| 2026-04-13 | CVE-2026-34621 | high | Adobe Acrobat and Reader are actively exploited for arbitrary code execution via prototype pollution. |
| 2024-09-17 | CVE-2013-0643 | high | Adobe Flash Player's discontinued status leaves unpatched RCE vulnerabilities exploitable in legacy systems. |
| 2024-09-17 | CVE-2014-0502 | high | Adobe Flash Player's unpatched double-free RCE vulnerability (CVE-2014-0502) remains exploitable due to the product's EOL status. |
| 2024-09-17 | CVE-2013-0648 | high | Adobe Flash Player's unpatched EOL status leaves remote code execution vulnerabilities perpetually exploitable. |
| 2024-09-17 | CVE-2014-0497 | high | Adobe Flash Player's integer underflow vulnerability enabled remote code execution and is actively exploited, posing a critical risk to legacy systems still in use. |
| 2024-01-08 | CVE-2023-38203 | critical | Adobe ColdFusion suffered a critical deserialization vulnerability allowing remote code execution, linked to ransomware attacks. |
| 2024-01-08 | CVE-2023-29300 | critical | Adobe ColdFusion suffered a critical deserialization vulnerability allowing remote code execution, linked to ransomware attacks. |
| 2022-06-08 | CVE-2010-1297 | high | Adobe Flash Player's unpatched memory corruption vulnerability allowed remote attackers to execute code, a critical flaw in an end-of-life product that remains a perpetual security liability. |
| 2022-06-08 | CVE-2007-5659 | high | A buffer overflow in Adobe Acrobat and Reader allowed remote attackers to execute code via malicious PDF files. |
| 2022-05-23 | CVE-2018-5002 | high | Adobe Flash Player's unpatched stack-based buffer overflow allowed remote code execution, proving that end-of-life software remains a perpetual liability. |
| 2022-04-13 | CVE-2015-0311 | high | Adobe Flash Player's unpatched RCE vulnerability remains a perpetual liability after its December 2020 end-of-life. |
| 2022-04-13 | CVE-2015-5123 | high | Adobe Flash Player's use-after-free vulnerability allowed remote attackers to execute arbitrary code, and the product's end-of-life status left it perpetually unpatched. |
| 2022-04-13 | CVE-2015-0313 | high | Adobe Flash Player's use-after-free vulnerability allowed remote attackers to execute arbitrary code, a flaw that persisted after the product's end-of-life in 2020. |
| 2022-04-13 | CVE-2014-9163 | high | Adobe Flash Player's unpatched stack-based buffer overflow allowed remote code execution, proving that end-of-life software remains a perpetual liability. |
| 2022-03-25 | CVE-2016-4171 | high | Adobe Flash Player's end-of-life status left unpatched RCE vulnerabilities perpetually exploitable, exemplifying the catastrophic risk of shipping and maintaining obsolete software. |
| 2022-03-07 | CVE-2013-0625 | high | An authentication bypass in Adobe ColdFusion allowed unauthorized administrative access, later linked to CVSS 10.0 command and eval injection flaws. |
| 2022-03-07 | CVE-2013-0631 | high | Adobe ColdFusion suffered from critical unpatched command injection and eval injection flaws enabling remote code execution and privilege escalation. |
| 2022-03-03 | CVE-2012-1535 | high | Adobe Flash Player's unpatched arbitrary code execution vulnerability remains a perpetual liability after its December 2020 end-of-life. |
| 2022-03-03 | CVE-2015-3043 | high | Adobe Flash Player's unpatched memory corruption flaw allowed remote code execution, proving that end-of-life software remains a perpetual security liability. |
| 2022-03-03 | CVE-2011-0611 | high | Adobe Flash Player's unpatched remote code execution vulnerability (CVE-2011-0611) remains actively exploited in the wild despite the product's end-of-life in 2020. |
| 2022-03-03 | CVE-2013-0632 | high | An authentication bypass in Adobe ColdFusion allowed unauthorized administrative access, later linked to CVSS 10.0 command and eval injection flaws. |
| 2022-03-03 | CVE-2016-4117 | high | Adobe Flash Player's end-of-life status left unpatched RCE vulnerabilities perpetually exploitable, exemplifying the catastrophic risk of shipping and maintaining obsolete software. |
| 2021-11-03 | CVE-2021-21017 | high | Adobe Acrobat and Reader suffered a heap-based buffer overflow allowing unauthenticated remote code execution, a known critical flaw repeatedly exploited in the wild. |
| 2021-11-03 | CVE-2018-4939 | high | Adobe ColdFusion suffered a deserialization of untrusted data vulnerability allowing remote code execution. |
| 2022-03-07 | CVE-2009-3960 | critical | A decade-old Adobe BlazeDS vulnerability is actively exploited, potentially exposing sensitive information in systems using LifeCycle and ColdFusion applications. |
| 2022-02-15 | CVE-2018-15982 | critical | Adobe Flash Player, now end-of-life, contained a critical use-after-free vulnerability actively exploited by ransomware actors, leaving systems perpetually exposed. |
| 2022-05-25 | CVE-2015-8651 | high | Adobe Flash Player's integer overflow vulnerability allowed remote code execution, and the product's end-of-life status left it perpetually unpatched and exploitable. |
| 2022-05-25 | CVE-2014-0546 | high | Adobe Reader and Acrobat allowed attackers to bypass sandbox protections and execute privileged native code via CVE-2014-0546. |
| 2022-05-25 | CVE-2016-0984 | high | Adobe Flash Player and AIR contained a use-after-free vulnerability allowing remote code execution, which was actively exploited in the wild. |
| 2022-05-25 | CVE-2016-1010 | high | An integer overflow vulnerability in Adobe Flash Player and AIR allowed attackers to execute arbitrary code. |
| 2022-04-13 | CVE-2015-5122 | high | Adobe Flash Player's use-after-free vulnerability allowed remote attackers to execute arbitrary code, and the product's end-of-life status meant it remained perpetually unpatched and exploitable. |
| 2022-04-13 | CVE-2015-3113 | high | Adobe Flash Player's unpatched heap-based buffer overflow allowed remote attackers to execute code, proving that end-of-life software remains a perpetual security liability. |
| 2022-03-25 | CVE-2016-7892 | high | An unpatched use-after-free vulnerability in Adobe Flash Player allowed remote code execution, exploited in the wild after Flash reached end-of-life in 2020. |
| 2022-03-03 | CVE-2013-0640 | high | Adobe Reader and Acrobat contained a memory corruption vulnerability in acroform.dll enabling remote code execution. |
| 2022-03-03 | CVE-2015-5119 | high | Adobe Flash Player's use-after-free vulnerability allowed remote code execution, and the product's end-of-life status meant it remained perpetually unpatched and exploitable. |
| 2022-03-03 | CVE-2013-0641 | high | Adobe Reader's unpatched buffer overflow vulnerability allowed remote code execution and was actively exploited in the wild. |
| 2022-03-03 | CVE-2016-7855 | high | Adobe Flash Player's use-after-free vulnerability allowed remote attackers to execute arbitrary code, and the product's end-of-life status left it perpetually unpatched. |
| 2022-03-03 | CVE-2017-11292 | high | Adobe Flash Player's unpatched type confusion vulnerability allowed remote code execution, proving that end-of-life software remains a perpetual security liability. |
| 2021-11-03 | CVE-2018-15961 | high | Adobe ColdFusion's unrestricted file upload flaw allowed remote code execution, enabling attackers to upload and execute malicious files on vulnerable systems. |
| 2022-05-25 | CVE-2015-0310 | high | Adobe Flash Player's ASLR bypass vulnerability allowed attackers to bypass memory randomization protections, enabling remote code execution. |
| 2022-03-25 | CVE-2009-0927 | high | Adobe Reader and Acrobat contained a stack-based buffer overflow allowing remote attackers to execute arbitrary code. |
| 2022-02-15 | CVE-2022-24086 | high | Improper input validation in Adobe Commerce and Magento Open Source allowed arbitrary code execution. |
| 2021-11-03 | CVE-2021-28550 | high | Adobe Acrobat and Reader suffered a use-after-free vulnerability allowing unauthenticated remote code execution. |
| 2025-10-24 | CVE-2025-54236 | high | Adobe's Magento suffered an unpatched input validation flaw exploited in the wild, allowing remote code execution and potential account takeover via the REST API. |
| 2025-10-15 | CVE-2025-54253 | high | Adobe AEM Forms JEE arbitrary code execution flaw actively exploited |
| 2023-10-10 | CVE-2023-21608 | high | Adobe Acrobat and Reader Use-After-Free Vulnerability |
| 2023-09-14 | CVE-2023-26369 | high | Adobe Acrobat and Reader out-of-bounds write vulnerability allows code execution. |
| 2023-08-21 | CVE-2023-26359 | high | Adobe ColdFusion's deserialization vulnerability (CVE-2023-26359) allows for code execution, and is currently being exploited in the wild. |
| 2023-03-15 | CVE-2023-26360 | high | Adobe ColdFusion RCE flaw exploited before patch |
| 2022-06-08 | CVE-2018-4990 | high | A double-free vulnerability in Adobe Acrobat and Reader allowed for potential remote code execution, actively exploited in the wild and impacting DIB organizations reliant on these products. |
| 2022-06-08 | CVE-2012-0767 | high | Adobe Flash Player, now end-of-life, contains a cross-site scripting vulnerability actively exploited in the wild, posing a significant risk to systems still running it despite its discontinuation and lack of updates. |
| 2022-06-08 | CVE-2011-2462 | high | A memory corruption vulnerability in Adobe Reader and Acrobat allowed for potential remote code execution and denial-of-service attacks, and is currently being exploited in the wild. |
| 2022-06-08 | CVE-2011-0609 | high | Adobe Flash Player, now end-of-life, contained an unspecified vulnerability allowing remote code execution and denial-of-service attacks, and is actively exploited in the wild. |
| 2022-06-08 | CVE-2010-2883 | high | A buffer overflow in Adobe Acrobat and Reader allowed attackers to execute code remotely, actively exploited in the wild and impacting DIB organizations using these products. |
| 2022-06-08 | CVE-2009-1862 | high | Unpatched Adobe Acrobat/Reader and Flash Player RCE vulnerabilities were actively exploited in the wild, enabling remote code execution. |
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.60
Adobe's Flash Player vulnerability was widely recognized as a critical flaw enabling code execution, reflecting severe fallout for the vendor.
synthesissevere-fallout-0.60
Adobe's CVE-2018-4939 deserialization flaw allowing code execution was widely recognized as a critical vulnerability, though the provided sources lack specific press coverage or authority commentary o
synthesisneutral+0.00
No sentiment expressed; sources are technical databases or vendor pages without commentary on Adobe's handling.
synthesisneutral-0.20
No direct press or authority commentary on Adobe's handling of CVE-2018-15961 is present in the provided sources; only technical vulnerability descriptions and generic vendor/product listings are avai
synthesisneutral+0.00
No sentiment expressed; sources are technical databases or aggregators without commentary on Adobe's handling.
synthesissevere-fallout-0.60
Adobe faced severe fallout for CVE-2016-1019, with the vulnerability being actively exploited in the wild, though provided sources lack direct commentary on Adobe's response or reputation impact, focu
synthesissevere-fallout-0.60
CVE-2010-2861 is a critical directory traversal flaw in Adobe ColdFusion's admin console allowing arbitrary file reads; NVD confirms severity, though provided sources lack direct commentary on Adobe's
Neutral technical description; no sentiment toward Adobe.
"Acrobat Acrobat and Reader contain a heap-based buffer overflow vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user."
Neutral database listing; no sentiment toward Adobe.
Neutral database listing; no sentiment toward Adobe.
Neutral database listing; no sentiment toward Adobe.
Neutral; technical description only.
"Adobe Acrobat and Reader contains a use-after-free vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user."
Neutral; no commentary on Adobe.
Neutral; no commentary on Adobe.
Neutral; no commentary on Adobe.
Neutral; no commentary on Adobe.
No relevant content.
Severe vulnerability in Flash Player allowing code execution, widely condemned as a critical flaw.
"Adobe Flash Player contains a use-after-free vulnerability that could allow for code execution."
No substantive coverage of CVE-2018-4878; page is unauthorized frame with redirect warning.
Mentions multiple Adobe vulnerabilities including arbitrary code execution, but lacks specific focus on CVE-2018-4878.
"Multiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution."
No coverage of CVE-2018-4878; focuses on 2026 Firefox/Chrome/Adobe/VMware updates.
No coverage of CVE-2018-4878; generic CVE database page.
Neutral technical description only.
"Adobe ColdFusion contains an unrestricted file upload vulnerability that could allow for code execution."
Neutral product listing.
"Adobe ColdFusion is a commercial rapid web application development platform used to build and deploy dynamic web and mobile applications."
No relevant content.
No relevant content.
Neutral database listing; no sentiment toward Adobe.
Critical vulnerability acknowledged but no specific praise or condemnation of Adobe's handling is present in the source text.
"Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could allow for code execution."
No relevant content regarding Adobe or CVE-2018-4939.
No relevant content regarding Adobe or CVE-2018-4939.
FEDRAMP CATALOG PRODUCTS · 8
| PRODUCT | STATUS | IMPACT |
|---|---|---|
| Adobe Acrobat Sign for Government | Authorized | Moderate |
| Adobe Analytics | Authorized | LI-SaaS |
| Adobe Campaign | Authorized | LI-SaaS |
| Adobe Connect Managed Services (ACMS-GC) | Authorized | Moderate |
| Adobe Creative Cloud for Enterprise | Authorized | LI-SaaS |
| Adobe Document Cloud (PDF Services & Adobe Sign) | Authorized | LI-SaaS |
| Adobe Experience Manager Managed Services (AEMMS-GC) | Authorized | Moderate |
| Adobe Learning Manager | Authorized | LI-SaaS |
DOSSIER SOURCES
- Adobe (ADBE) Company Profile & Description - Stock Analysis · stockanalysis.com
- Patch Adobe ColdFusion CVE-2026-48282 & Others - CISA Warning · cvedaily.io
- CVE-2026-48282 Adobe ColdFusion Security Strategic Brief · thecybermind.co
- CISA Warns Adobe ColdFusion Flaw Enables Arbitrary Code Execution · cyberpress.org
Open questions: Adobe's remediation timeline for CVE-2026-48282 · Impact of CVE-2026-34621 on enterprise deployments
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-13 14:11:10.421049+00:00