Adobe
CPE vendor key: adobe ·
1,747 CVEs published in the last 24 months.
CVEs (365 d)
813
▼ -14 vs prior 30d
Avg CVSS (365 d)
6.77
over 813 CVEs
Avg EPSS pct (365 d)
0.20
higher = more likely exploited
KEV hit rate (365 d)
0.4%
3 of 813 added to CISA KEV
LLM-credited CVEs
0
none detected
Monthly CVE volume — last 24 months
Each point is one calendar month. Bars in the
severity card to the right slice the same volume by CVSS band.
Severity mix
Stacked by CVSS band (Critical / High / Medium /
Low) using the best available metric per CVE.
Top affected products (24 mo)
593
125
116
116
108
98
73
69
69
63
Distinct CVEs that include each product in their
CPE configuration.
Top CWEs (24 mo)
640
262
169
106
88
68
62
49
37
32
Distinct CVEs assigned each weakness.
Recent CISA KEV adds (last 12 months)
| Added | CVE | Product | KEV name |
|---|---|---|---|
| 2026-07-07 | CVE-2026-48282 | ColdFusion | Adobe ColdFusion Path Traversal Vulnerability |
| 2026-05-20 | CVE-2009-3459 | Acrobat and Reader | Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability |
| 2026-04-13 | CVE-2026-34621 | Acrobat and Reader | Adobe Acrobat and Reader Prototype Pollution Vulnerability |
| 2026-04-13 | CVE-2020-9715 | Acrobat | Adobe Acrobat Use-After-Free Vulnerability |
| 2025-10-24 | CVE-2025-54236 | Commerce and Magento | Adobe Commerce and Magento Improper Input Validation Vulnerability |
| 2025-10-15 | CVE-2025-54253 | Experience Manager (AEM) Forms | Adobe Experience Manager Forms Code Execution Vulnerability |
Filtered to KEV entries whose CISA vendor or product name matches this
vendor exactly, to drop cross-OS noise (e.g. third-party Windows apps
that CPE-map to Microsoft).
Generated 23 August 2026 00:24 UTC .