Cyber Resilience

← All vendors

Adobe

CPE vendor key: adobe · 1,747 CVEs published in the last 24 months.

CVEs (365 d)
813
▼ -14 vs prior 30d
Avg CVSS (365 d)
6.77
over 813 CVEs
Avg EPSS pct (365 d)
0.20
higher = more likely exploited
KEV hit rate (365 d)
0.4%
3 of 813 added to CISA KEV
LLM-credited CVEs
0
none detected

Monthly CVE volume — last 24 months

2024202520260257
Each point is one calendar month. Bars in the severity card to the right slice the same volume by CVSS band.

Severity mix

CritHighMedLow
Stacked by CVSS band (Critical / High / Medium / Low) using the best available metric per CVE.

Top affected products (24 mo)

experience_manager
593
commerce_b2b
125
magento
116
commerce
116
coldfusion
108
indesign
98
acrobat
73
acrobat_dc
69
acrobat_reader_dc
69
illustrator
63
Distinct CVEs that include each product in their CPE configuration.

Top CWEs (24 mo)

CWE-79
640
CWE-787
262
CWE-125
169
CWE-122
106
CWE-416
88
CWE-863
68
CWE-20
62
CWE-476
49
CWE-191
37
CWE-190
32
Distinct CVEs assigned each weakness.

Recent CISA KEV adds (last 12 months)

AddedCVEProductKEV name
2026-07-07CVE-2026-48282ColdFusionAdobe ColdFusion Path Traversal Vulnerability
2026-05-20CVE-2009-3459Acrobat and ReaderAdobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability
2026-04-13CVE-2026-34621Acrobat and ReaderAdobe Acrobat and Reader Prototype Pollution Vulnerability
2026-04-13CVE-2020-9715AcrobatAdobe Acrobat Use-After-Free Vulnerability
2025-10-24CVE-2025-54236Commerce and MagentoAdobe Commerce and Magento Improper Input Validation Vulnerability
2025-10-15CVE-2025-54253Experience Manager (AEM) FormsAdobe Experience Manager Forms Code Execution Vulnerability
Filtered to KEV entries whose CISA vendor or product name matches this vendor exactly, to drop cross-OS noise (e.g. third-party Windows apps that CPE-map to Microsoft).

Generated 23 August 2026 00:24 UTC .