CVE Tools

Adobe

7,320 CVEs tracked since 1999. Since Aug 2021, 14 of them reached CISA KEV.

Adobe CVEs per month

Aug 2021 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Adobe CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2021-08790
2021-091491
2021-10140
2021-11450
2021-12290
2022-01480
2022-02221
2022-03540
2022-0460
2022-05970
2022-06470
2022-07340
2022-08270
2022-09660
2022-10340
2022-11null or fewer
2022-12390
2023-01311
2023-02280
2023-03null or fewer
2023-04570
2023-05140
2023-06180
2023-07223
2023-08370
2023-09652
2023-10130
2023-11770
2023-122200
2024-01100
2024-02310
2024-03561
2024-04290
2024-05450
2024-061671
2024-07130
2024-08900
2024-09290
2024-10540
2024-11570
2024-121770
2025-01160
2025-02510
2025-03430
2025-04520
2025-05400
2025-062600
2025-07730
2025-08791
2025-09241
2025-10360
2025-11290
2025-121370
2026-01250
2026-02440
2026-03820
2026-04571
2026-05520
2026-061450
2026-071070
2026-081010
2026-091711

Products

The products that kept showing up in Adobe's monthly top three, with their CVEs summed over those months.

  1. Experience Manager97312 months
  2. Adobe Experience Manager96811 months
  3. Acrobat Dc28512 months
  4. Acrobat Reader22911 months
  5. Acrobat2018 months
  6. Acrobat Reader Dc1818 months
  7. Experience Manager Cloud Service1472 months
  8. Adobe Experience Manager 6.51051 month
  9. Adobe Experience Manager 6.5 Lts1051 month
  10. Adobe Experience Manager As A Cloud Service1051 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Adobe.

  1. CVE-2026-84395Premiere Pro | Server-Side Request Forgery (SSRF) (CWE-918)7.1
  2. CVE-2026-83963Substance3D - Modeler | Out-of-bounds Write (CWE-787)7.8
  3. CVE-2026-81998Substance3D - Modeler | Out-of-bounds Write (CWE-787)7.8
  4. CVE-2026-83962Substance3D - Modeler | Stack-based Buffer Overflow (CWE-121)7.8
  5. CVE-2026-79906Substance3D - Modeler | Out-of-bounds Write (CWE-787)7.8
  6. CVE-2026-75743Adobe Experience Manager Forms JEE | Cross-Site Request Forgery (CSRF) (CWE-352)7.1
  7. CVE-2026-75745Adobe Experience Manager Forms JEE | Incorrect Authorization (CWE-863)10.0
  8. CVE-2026-82000Adobe Experience Manager Forms JEE | Server-Side Request Forgery (SSRF) (CWE-918)9.6
  9. CVE-2026-75744Adobe Experience Manager Forms JEE | Cross-site Scripting (Stored XSS) (CWE-79)8.1
  10. CVE-2026-81995Adobe Experience Manager Forms JEE | Improper Input Validation (CWE-20)9.1
  11. CVE-2026-81999Adobe Experience Manager Forms JEE | Server-Side Request Forgery (SSRF) (CWE-918)8.7
  12. CVE-2026-75689Adobe Connect | Cross-site Scripting (Stored XSS) (CWE-79)9.3
  13. CVE-2026-83964Adobe Connect | Improper Certificate Validation (CWE-295)6.2
  14. CVE-2026-34689Adobe Connect | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)8.6
  15. CVE-2026-75682Adobe Connect | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)9.9

The record

Peak rank
#1 in Dec 2023
Busiest month shown
Jun 2025, 260 CVEs
Months with a KEV entry
11 since Aug 2021
Monthly snapshots
230 since 1999
Adobe's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store