PatchSiren

Adobe CVE debriefs · Page 10

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Adobe CVE published 2026-06-09

CVE-2026-47928

CVE-2026-47928 is a CRITICAL vulnerability with a CVSS score of 9.6. Affected ColdFusion versions include 2023.19, 2025.8, and earlier. The vulnerability is caused by Improper Input Validation, which could result in arbitrary code execution in the context of the current user. Exploitation does not require user interaction.

MEDIUM Adobe CVE published 2026-06-09

CVE-2026-47926

CVE-2026-47926 is a MEDIUM severity vulnerability in Adobe Acrobat Reader versions 24.001.30365, 26.001.21651, and earlier. The vulnerability is an out-of-bounds read issue that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information by tricking a victim into opening a malicious file. This vulnerability requires user interaction.

MEDIUM Adobe CVE published 2026-06-09

CVE-2026-47925

CVE-2026-47925 is an Integer Overflow or Wraparound vulnerability affecting Adobe Acrobat Reader versions 24.001.30365, 26.001.21651, and earlier. This vulnerability could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open [truncated]

MEDIUM Adobe CVE published 2026-06-09

CVE-2026-47923

CVE-2026-47923 is an out-of-bounds read vulnerability in Adobe Acrobat Reader versions 24.001.30365, 26.001.21651, and earlier. This vulnerability could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

HIGH Adobe CVE published 2026-06-09

CVE-2026-47921

CVE-2026-47921 is a HIGH severity Use After Free vulnerability in Adobe Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier. This vulnerability could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

HIGH Adobe CVE published 2026-06-09

CVE-2026-47919

CVE-2026-47919 is a Use After Free vulnerability affecting Adobe Acrobat Reader versions 24.001.30365, 26.001.21651, and earlier. This vulnerability could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction, as a victim must open a malicious file.

HIGH Adobe CVE published 2026-06-09

CVE-2026-47918

CVE-2026-47918 is a HIGH severity Use After Free vulnerability affecting Adobe Acrobat Reader versions 24.001.30365, 26.001.21651, and earlier. The vulnerability could result in arbitrary code execution in the context of the current user, requiring user interaction to open a malicious file. The CVSS score for this vulnerability is 7.8.

HIGH Adobe CVE published 2026-06-09

CVE-2026-47917

CVE-2026-47917 is a HIGH severity Use After Free vulnerability affecting Adobe Acrobat Reader versions 24.001.30365, 26.001.21651, and earlier. The vulnerability could result in arbitrary code execution in the context of the current user, requiring user interaction to open a malicious file. The CVSS score for this vulnerability is 7.8.

HIGH Adobe CVE published 2026-06-09

CVE-2026-47916

CVE-2026-47916 is a Use After Free vulnerability affecting Adobe Acrobat Reader versions 24.001.30365, 26.001.21651, and earlier. This vulnerability could result in arbitrary code execution in the context of the current user, requiring user interaction to open a malicious file.

HIGH Adobe CVE published 2026-06-09

CVE-2026-47915

CVE-2026-47915 is a HIGH severity Use After Free vulnerability affecting Adobe Acrobat Reader versions 24.001.30365, 26.001.21651, and earlier. The vulnerability could result in arbitrary code execution in the context of the current user, requiring user interaction to open a malicious file. The CVSS score for this vulnerability is 7.8.

HIGH Adobe CVE published 2026-06-09

CVE-2026-47914

CVE-2026-47914 is a HIGH severity Use After Free vulnerability in Adobe Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier. Exploitation could lead to arbitrary code execution in the context of the current user, requiring user interaction to open a malicious file.

HIGH Adobe CVE published 2026-06-09

CVE-2026-47913

CVE-2026-47913 is a Use After Free vulnerability affecting Adobe Acrobat Reader versions 24.001.30365, 26.001.21651, and earlier. This vulnerability could result in arbitrary code execution in the context of the current user, requiring user interaction to open a malicious file. The CVSS score for this vulnerability is 7.8, classified as HIGH severity.

HIGH Adobe CVE published 2026-06-09

CVE-2026-47912

CVE-2026-47912 is a HIGH severity vulnerability in Adobe Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier. This Use After Free vulnerability could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

HIGH Adobe CVE published 2026-06-09

CVE-2026-47911

CVE-2026-47911 is an out-of-bounds write vulnerability in Adobe Acrobat Reader versions 24.001.30365, 26.001.21651, and earlier. This vulnerability could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. The CVSS score for this vulnerability is 7.8, with a severity rating of HIGH.

HIGH Adobe CVE published 2026-06-09

CVE-2026-48306

CVE-2026-48306 is a HIGH-severity vulnerability in Adobe Substance 3D Sampler. Versions 6.0.0 and earlier are affected by an out-of-bounds write vulnerability, which could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction, as a victim must open a malicious file. The CVSS score for this vulnerability is 7.8.

HIGH Adobe CVE published 2026-06-09

CVE-2026-48305

CVE-2026-48305 is an out-of-bounds write vulnerability in Adobe Substance 3D Sampler versions 6.0.0 and earlier. This CVE has a CVSS score of 7.8 and can result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

MEDIUM Adobe CVE published 2026-06-09

CVE-2026-47910

CVE-2026-47910 is a MEDIUM-severity vulnerability in Adobe Dreamweaver Desktop versions 21.7 and earlier. The vulnerability is caused by an Incorrect Authorization issue, which could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction, as a victim m [truncated]

MEDIUM Adobe CVE published 2026-06-09

CVE-2026-47909

CVE-2026-47909 is an Improper Input Validation vulnerability in Adobe Dreamweaver Desktop versions 21.7 and earlier. This vulnerability could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

HIGH Adobe CVE published 2026-06-09

CVE-2026-47908

CVE-2026-47908 is an Access of Uninitialized Pointer vulnerability in Adobe Dreamweaver Desktop versions 21.7 and earlier. This vulnerability could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. The CVSS score for this vulnerability is 7.8, with a severity rating of HIGH.

HIGH Adobe CVE published 2026-06-09

CVE-2026-47907

CVE-2026-47907 is a HIGH-severity vulnerability in Adobe Dreamweaver Desktop versions 21.7 and earlier. The vulnerability is caused by an Improper Access Control issue, which could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction, as a victim mus [truncated]

HIGH Adobe CVE published 2026-06-09

CVE-2026-47906

CVE-2026-47906 is a Dependency on Vulnerable Third-Party Component vulnerability affecting Adobe Dreamweaver Desktop versions 21.7 and earlier. This vulnerability could result in arbitrary code execution in the context of the current user, with a CVSS score of 8.6 and a HIGH severity rating. Exploitation requires user interaction, as a victim must open a malicious file.

HIGH Adobe CVE published 2026-06-09

CVE-2026-34710

CVE-2026-34710 is a high-severity vulnerability in Adobe Substance 3D Sampler, a 3D modeling and texturing software. The vulnerability, rated 7.8 CVSS score, is caused by an out-of-bounds write issue that could result in arbitrary code execution in the context of the current user. To exploit this vulnerability, a victim must open a malicious file, indicating that user interaction is required.

HIGH Adobe CVE published 2026-06-09

CVE-2026-34709

CVE-2026-34709 is a HIGH-severity vulnerability in Adobe Substance 3D Sampler. Versions 6.0.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction, as a victim must open a malicious file.

HIGH Adobe CVE published 2026-06-09

CVE-2026-48293

CVE-2026-48293 is a HIGH-severity vulnerability (CVSS Score: 7.8) affecting Adobe InDesign versions 21.3, 20.5.3, and earlier. The vulnerability is an out-of-bounds write issue that could result in arbitrary code execution in the context of the current user. Exploitation requires user interaction, as a victim must open a malicious file.

HIGH Adobe CVE published 2026-06-09

CVE-2026-34708

CVE-2026-34708 is a Stack-based Buffer Overflow vulnerability affecting Adobe InCopy versions 21.3, 20.5.3, and earlier. This vulnerability could result in arbitrary code execution in the context of the current user. User interaction is required for exploitation, as a victim must open a malicious file.

HIGH Adobe CVE published 2026-06-09

CVE-2026-34707

A Heap-based Buffer Overflow vulnerability was discovered in Adobe InCopy versions 21.3, 20.5.3 and earlier. This vulnerability, tracked as CVE-2026-34707, could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction, as a victim must open a malicious file. The vulnerability has a CVSS score of 7.8 and is classified as HIGH severity.

HIGH Adobe CVE published 2026-06-09

CVE-2026-34706

CVE-2026-34706 is a HIGH-severity vulnerability in Adobe InCopy, a professional writing and editing software. The issue, reported as an out-of-bounds write vulnerability, affects InCopy versions 21.3, 20.5.3, and earlier. Successful exploitation could result in arbitrary code execution in the context of the current user, requiring user interaction to open a malicious file.

MEDIUM Adobe CVE published 2026-06-09

CVE-2026-34705

CVE-2026-34705 is a MEDIUM-severity vulnerability in Adobe InDesign, with a CVSS score of 5.5. The vulnerability is an out-of-bounds read issue that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information by tricking a victim into opening a malicious file. This issue requires user interaction.

MEDIUM Adobe CVE published 2026-06-09

CVE-2026-34704

CVE-2026-34704 is a NULL Pointer Dereference vulnerability affecting Adobe InDesign Desktop versions 21.3, 20.5.3, and earlier. This vulnerability could lead to an application denial-of-service. An attacker could exploit this issue by getting a victim to open a malicious file, resulting in a denial-of-service condition. The CVSS score for this vulnerability is 5.5, with a severity rating of MEDIUM.

MEDIUM Adobe CVE published 2026-06-09

CVE-2026-34703

CVE-2026-34703 is a NULL Pointer Dereference vulnerability affecting Adobe InDesign versions 21.3, 20.5.3, and earlier. This vulnerability could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.