boxscore/security
VENDOR · referenceVendors · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

Adobe

Vendor reference — Adobe · sector: Enterprise Applications. Cumulative disclosure record across the archive.

Follow Adobe — Atom feed

Career totals

Disclosures & known-exploited
All-timeYTD
CVEs386314
KEV entries754
Rate & severity
KEV/100Med CVSSMed EPSSCHML
19.47.8.0027391451235

KEV/100 = KEV entries ÷ CVEs × 100. Med CVSS / Med EPSS are medians over all disclosures. C/H/M/L = disclosures by CVSS severity band.

Monthly disclosures

Trend (by first-seen month, full archive): ▁▁▁▁▂▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁█▆▄

Last 12 months (new CVEs by first-seen day)
MonthNew CVEs
2025-090
2025-102
2025-110
2025-121
2026-010
2026-020
2026-030
2026-043
2026-051
2026-06142
2026-07108
2026-0860

Notable CVEs

Ranked by the published formula: KEV → EPSS → CVSS → CVE ID.

Notable (ranked)
CVECVSSEPSS %ileSeverityKEVFirst seen
CVE-2024-34102100.0YES2024-07-17
CVE-2023-29300100.0YES2024-01-08
CVE-2018-15961100.0YES2021-11-03
CVE-2015-3113100.0YES2022-04-13
CVE-2014-0497100.0YES2024-09-17
CVE-2023-29298100.0YES2023-07-20
CVE-2023-38205100.0YES2023-07-20
CVE-2015-511999.9YES2022-03-03
CVE-2026-4828210.099.9CRITICALYES2026-07-07
CVE-2022-2408699.9YES2022-02-15
CVE-2024-2076799.9YES2024-12-16
CVE-2008-299299.9YES2022-03-03
CVE-2023-2636099.9YES2023-03-15
CVE-2023-3820399.9YES2024-01-08
CVE-2009-092799.9YES2022-03-25

Recent CVEs

Most recently seen
CVECVSSEPSS %ileSeverityKEVFirst seen
CVE-2026-2730210.044.8CRITICAL2026-08-11
CVE-2026-7139810.047.9CRITICAL2026-08-11
CVE-2026-484167.540.5HIGH2026-08-11
CVE-2026-484157.628.1HIGH2026-08-11
CVE-2026-484116.540.4MEDIUM2026-08-11
CVE-2026-713878.819.4HIGH2026-08-11
CVE-2026-484418.69.3HIGH2026-08-11
CVE-2026-484122.724.3LOW2026-08-11
CVE-2026-484097.85.5HIGH2026-08-11
CVE-2026-484047.85.5HIGH2026-08-11
CVE-2026-4836210.079.9CRITICAL2026-08-11
CVE-2026-484477.74.2HIGH2026-08-11
CVE-2026-484408.146.9HIGH2026-08-11
CVE-2026-484107.85.5HIGH2026-08-11
CVE-2026-484087.85.5HIGH2026-08-11

Products

This vendor's products with a reference page (≥2 disclosures), by CVE count. A monolithic vendor total dilutes signal; product pages sharpen it.

Products (by CVE count)
ProductCVEsKEV
Adobe Experience Manager570
ColdFusion3515
Flash Player3131
ColdFusion 2023290
ColdFusion 2025290
Content Credentials Command-Line Tool270
Content Credentials JS SDK270
Content Credentials Rust SDK270
Acrobat Reader250
Adobe Commerce210
Adobe Commerce B2B210
Magento Open Source210
Adobe Bridge140
Adobe Commerce Webhooks Plugin140
Acrobat And Reader1313
Adobe Experience Manager 6.5130
Adobe Experience Manager 6.5 LTS130
Adobe Experience Manager As A Cloud Service130
Adobe Campaign Classic120
InDesign Desktop120
Lightroom Classic110
CAI Content Credentials80
Reader And Acrobat77
Adobe Animate 202360
Adobe Animate 202460
Audition60
DNG SDK60
Adobe Media Encoder50
Dreamweaver Desktop50
Illustrator Desktop 202550
Illustrator Desktop 202650
Premiere50
Substance3D - Sampler40
Adobe Campaign Classic (ACC)30
Adobe Experience Manager Forms JEE30
Format Plugins30
InCopy30
Adobe Photoshop Installer20
After Effects20
Commerce And Magento Open Source22
Creative Cloud Desktop20
Flash Player And AIR22

KEV entries

CISA Known Exploited Vulnerabilities (newest addition first)
CVEKEV addedCVSSEPSS %ileSeverity
CVE-2026-482822026-07-0710.099.9CRITICAL
CVE-2009-34592026-05-2099.7
CVE-2026-346212026-04-1393.7
CVE-2020-97152026-04-1398.8
CVE-2025-542362025-10-2499.8
CVE-2025-542532025-10-1599.7
CVE-2017-30662025-02-2499.8
CVE-2024-207672024-12-1699.9
CVE-2014-04972024-09-17100.0
CVE-2013-06432024-09-1795.4
CVE-2013-06482024-09-1795.6
CVE-2014-05022024-09-1797.7
CVE-2024-341022024-07-17100.0
CVE-2023-382032024-01-0899.9
CVE-2023-293002024-01-08100.0
CVE-2023-216082023-10-1099.1
CVE-2023-263692023-09-1493.7
CVE-2023-263592023-08-2196.9
CVE-2023-382052023-07-20100.0
CVE-2023-292982023-07-20100.0
CVE-2023-263602023-03-1599.9
CVE-2007-56592022-06-0899.8
CVE-2008-06552022-06-0898.4
CVE-2009-18622022-06-0897.7
CVE-2009-39532022-06-0899.7

KEV timing

Longest unpatched (KEV due date passed)
CVEDueDays over
CVE-2021-210172021-11-171736
CVE-2021-285502021-11-171736
CVE-2022-240862022-03-011632
CVE-2017-112922022-03-241609
CVE-2016-78552022-03-241609
CVE-2016-41172022-03-241609
CVE-2015-76452022-03-241609
CVE-2015-51192022-03-241609
CVE-2015-30432022-03-241609
CVE-2014-04962022-03-241609

Methodology

Rate statistics are arithmetic over published figures: KEV/100 = KEV entries ÷ CVEs × 100; medians are taken over this vendor's disclosures. Vendor names are normalized (case, punctuation, common aliases) before aggregation; monthly counts are keyed to first-seen day, the day this archive first observed the record, not the upstream publication date.

Raw counts are not comparable across vendors: disclosure practices, product breadth, and CNA conventions differ widely, so a larger number here does not mean less secure software. This is a reference page assembled from the public record — not a record of its own, and not a ranking of vendors by our judgment.

Sources. CVE records from the CVE Program (cvelistV5); enrichment from NVD (NIST); known-exploited status from the CISA KEV catalog; exploit probability from FIRST EPSS.