These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-47928 is a CRITICAL vulnerability with a CVSS score of 9.6. Affected ColdFusion versions include 2023.19, 2025.8, and earlier. The vulnerability is caused by Improper Input Validation, which could result in arbitrary code execution in the context of the current user. Exploitation does not require user interaction.
CVE-2026-47926 is a MEDIUM severity vulnerability in Adobe Acrobat Reader versions 24.001.30365, 26.001.21651, and earlier. The vulnerability is an out-of-bounds read issue that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information by tricking a victim into opening a malicious file. This vulnerability requires user interaction.
CVE-2026-47925 is an Integer Overflow or Wraparound vulnerability affecting Adobe Acrobat Reader versions 24.001.30365, 26.001.21651, and earlier. This vulnerability could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open [truncated]
CVE-2026-47923 is an out-of-bounds read vulnerability in Adobe Acrobat Reader versions 24.001.30365, 26.001.21651, and earlier. This vulnerability could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2026-47921 is a HIGH severity Use After Free vulnerability in Adobe Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier. This vulnerability could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2026-47919 is a Use After Free vulnerability affecting Adobe Acrobat Reader versions 24.001.30365, 26.001.21651, and earlier. This vulnerability could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction, as a victim must open a malicious file.
CVE-2026-47918 is a HIGH severity Use After Free vulnerability affecting Adobe Acrobat Reader versions 24.001.30365, 26.001.21651, and earlier. The vulnerability could result in arbitrary code execution in the context of the current user, requiring user interaction to open a malicious file. The CVSS score for this vulnerability is 7.8.
CVE-2026-47917 is a HIGH severity Use After Free vulnerability affecting Adobe Acrobat Reader versions 24.001.30365, 26.001.21651, and earlier. The vulnerability could result in arbitrary code execution in the context of the current user, requiring user interaction to open a malicious file. The CVSS score for this vulnerability is 7.8.
CVE-2026-47916 is a Use After Free vulnerability affecting Adobe Acrobat Reader versions 24.001.30365, 26.001.21651, and earlier. This vulnerability could result in arbitrary code execution in the context of the current user, requiring user interaction to open a malicious file.
CVE-2026-47915 is a HIGH severity Use After Free vulnerability affecting Adobe Acrobat Reader versions 24.001.30365, 26.001.21651, and earlier. The vulnerability could result in arbitrary code execution in the context of the current user, requiring user interaction to open a malicious file. The CVSS score for this vulnerability is 7.8.
CVE-2026-47914 is a HIGH severity Use After Free vulnerability in Adobe Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier. Exploitation could lead to arbitrary code execution in the context of the current user, requiring user interaction to open a malicious file.
CVE-2026-47913 is a Use After Free vulnerability affecting Adobe Acrobat Reader versions 24.001.30365, 26.001.21651, and earlier. This vulnerability could result in arbitrary code execution in the context of the current user, requiring user interaction to open a malicious file. The CVSS score for this vulnerability is 7.8, classified as HIGH severity.
CVE-2026-47912 is a HIGH severity vulnerability in Adobe Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier. This Use After Free vulnerability could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2026-47911 is an out-of-bounds write vulnerability in Adobe Acrobat Reader versions 24.001.30365, 26.001.21651, and earlier. This vulnerability could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. The CVSS score for this vulnerability is 7.8, with a severity rating of HIGH.
CVE-2026-48306 is a HIGH-severity vulnerability in Adobe Substance 3D Sampler. Versions 6.0.0 and earlier are affected by an out-of-bounds write vulnerability, which could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction, as a victim must open a malicious file. The CVSS score for this vulnerability is 7.8.
CVE-2026-48305 is an out-of-bounds write vulnerability in Adobe Substance 3D Sampler versions 6.0.0 and earlier. This CVE has a CVSS score of 7.8 and can result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2026-47910 is a MEDIUM-severity vulnerability in Adobe Dreamweaver Desktop versions 21.7 and earlier. The vulnerability is caused by an Incorrect Authorization issue, which could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction, as a victim m [truncated]
CVE-2026-47909 is an Improper Input Validation vulnerability in Adobe Dreamweaver Desktop versions 21.7 and earlier. This vulnerability could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
CVE-2026-47908 is an Access of Uninitialized Pointer vulnerability in Adobe Dreamweaver Desktop versions 21.7 and earlier. This vulnerability could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. The CVSS score for this vulnerability is 7.8, with a severity rating of HIGH.
CVE-2026-47907 is a HIGH-severity vulnerability in Adobe Dreamweaver Desktop versions 21.7 and earlier. The vulnerability is caused by an Improper Access Control issue, which could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction, as a victim mus [truncated]
CVE-2026-47906 is a Dependency on Vulnerable Third-Party Component vulnerability affecting Adobe Dreamweaver Desktop versions 21.7 and earlier. This vulnerability could result in arbitrary code execution in the context of the current user, with a CVSS score of 8.6 and a HIGH severity rating. Exploitation requires user interaction, as a victim must open a malicious file.
CVE-2026-34710 is a high-severity vulnerability in Adobe Substance 3D Sampler, a 3D modeling and texturing software. The vulnerability, rated 7.8 CVSS score, is caused by an out-of-bounds write issue that could result in arbitrary code execution in the context of the current user. To exploit this vulnerability, a victim must open a malicious file, indicating that user interaction is required.
CVE-2026-34709 is a HIGH-severity vulnerability in Adobe Substance 3D Sampler. Versions 6.0.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction, as a victim must open a malicious file.
CVE-2026-48293 is a HIGH-severity vulnerability (CVSS Score: 7.8) affecting Adobe InDesign versions 21.3, 20.5.3, and earlier. The vulnerability is an out-of-bounds write issue that could result in arbitrary code execution in the context of the current user. Exploitation requires user interaction, as a victim must open a malicious file.
CVE-2026-34708 is a Stack-based Buffer Overflow vulnerability affecting Adobe InCopy versions 21.3, 20.5.3, and earlier. This vulnerability could result in arbitrary code execution in the context of the current user. User interaction is required for exploitation, as a victim must open a malicious file.
A Heap-based Buffer Overflow vulnerability was discovered in Adobe InCopy versions 21.3, 20.5.3 and earlier. This vulnerability, tracked as CVE-2026-34707, could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction, as a victim must open a malicious file. The vulnerability has a CVSS score of 7.8 and is classified as HIGH severity.
CVE-2026-34706 is a HIGH-severity vulnerability in Adobe InCopy, a professional writing and editing software. The issue, reported as an out-of-bounds write vulnerability, affects InCopy versions 21.3, 20.5.3, and earlier. Successful exploitation could result in arbitrary code execution in the context of the current user, requiring user interaction to open a malicious file.
CVE-2026-34705 is a MEDIUM-severity vulnerability in Adobe InDesign, with a CVSS score of 5.5. The vulnerability is an out-of-bounds read issue that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information by tricking a victim into opening a malicious file. This issue requires user interaction.
CVE-2026-34704 is a NULL Pointer Dereference vulnerability affecting Adobe InDesign Desktop versions 21.3, 20.5.3, and earlier. This vulnerability could lead to an application denial-of-service. An attacker could exploit this issue by getting a victim to open a malicious file, resulting in a denial-of-service condition. The CVSS score for this vulnerability is 5.5, with a severity rating of MEDIUM.
CVE-2026-34703 is a NULL Pointer Dereference vulnerability affecting Adobe InDesign versions 21.3, 20.5.3, and earlier. This vulnerability could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.