Vendor

Adobe

82 known exploited

Adobe news

Severity: CriticalAction: Act nowExploitation: ExploitedCISA KEV

Adobe Commerce and Magento Incorrect Authorization Vulnerability (CVE-2026-71362) is being actively exploited, CISA warns

CISA added CVE-2026-71362 (Adobe Commerce and Magento ) to its Known Exploited Vulnerabilities catalog on September 24, 2026, which means there is reliable evidence of exploitation in the wild. Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction.

Why it matters

CISA lists this as exploited in the wild. Unpatched Commerce and Magento systems are exposed to active attacks now.

Act now

Treat this as an emergency.

Severity: CriticalAction: Act nowExploitation: ExploitedCISA KEV

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-7273 Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing…

Why it matters

CISA lists this as exploited in the wild. Unpatched BIG-IP and Multiple Products systems are exposed to active attacks now.

Act now

Treat this as an emergency.

Actively exploited

All 82 →

Adobe Commerce and Magento

Adobe Commerce and Magento Incorrect Authorization Vulnerability

Added Sep 24, 2026Fed. due Sep 27, 2026Coverage →

Adobe Commerce and Magento

Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability

Added Sep 8, 2026Fed. due Sep 11, 2026

Adobe ColdFusion

Adobe ColdFusion Path Traversal Vulnerability

Added Jul 7, 2026Fed. due Jul 10, 2026

Adobe Acrobat and Reader

Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability

Added May 20, 2026Fed. due Jun 3, 2026

Adobe Acrobat and Reader

Adobe Acrobat and Reader Prototype Pollution Vulnerability

Added Apr 13, 2026Fed. due Apr 27, 2026

Adobe Acrobat

Adobe Acrobat Use-After-Free Vulnerability

Added Apr 13, 2026Fed. due Apr 27, 2026

Adobe Commerce and Magento

Adobe Commerce and Magento Improper Input Validation Vulnerability

Added Oct 24, 2025Fed. due Nov 14, 2025

Adobe Experience Manager (AEM) Forms

Adobe Experience Manager Forms Code Execution Vulnerability

Added Oct 15, 2025Fed. due Nov 5, 2025

Adobe ColdFusion

Adobe ColdFusion Deserialization Vulnerability

Added Feb 24, 2025Fed. due Mar 17, 2025

Adobe ColdFusion

Adobe ColdFusion Improper Access Control Vulnerability

Added Dec 16, 2024Fed. due Jan 6, 2025

Adobe Flash Player

Adobe Flash Player Integer Underflow Vulnerablity

Added Sep 17, 2024Fed. due Oct 8, 2024

Adobe Flash Player

Adobe Flash Player Incorrect Default Permissions Vulnerability

Added Sep 17, 2024Fed. due Oct 8, 2024

Adobe Flash Player

Adobe Flash Player Code Execution Vulnerability

Added Sep 17, 2024Fed. due Oct 8, 2024

Adobe Flash Player

Adobe Flash Player Double Free Vulnerablity

Added Sep 17, 2024Fed. due Oct 8, 2024

Adobe Commerce and Magento Open Source

Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability

Added Jul 17, 2024Fed. due Aug 7, 2024
CVE-2023-29300RansomwareCVSS 9.8

Adobe ColdFusion

Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

Added Jan 8, 2024Fed. due Jan 29, 2024
CVE-2023-38203RansomwareCVSS 9.8

Adobe ColdFusion

Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

Added Jan 8, 2024Fed. due Jan 29, 2024

Adobe Acrobat and Reader

Adobe Acrobat and Reader Use-After-Free Vulnerability

Added Oct 10, 2023Fed. due Oct 31, 2023

Adobe Acrobat and Reader

Adobe Acrobat and Reader Out-of-Bounds Write Vulnerability

Added Sep 14, 2023Fed. due Oct 5, 2023

Adobe ColdFusion

Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

Added Aug 21, 2023Fed. due Sep 11, 2023

Products