Third Party Index

Adobe

adobe.com

Includes: Marketo

FedRAMP Marketplace: Adobe Acrobat Sign for Government Authorized Moderate · 10 agency authorizations · since evidence

FedRAMP Marketplace: Adobe Analytics Authorized LI-SaaS · 2 agency authorizations · since evidence

FedRAMP Marketplace: Adobe Campaign Authorized LI-SaaS · 4 agency authorizations · since evidence

FedRAMP Marketplace: Adobe Connect Managed Services (ACMS-GC) Authorized Moderate · 4 agency authorizations · since evidence

FedRAMP Marketplace: Adobe Creative Cloud for Enterprise Authorized LI-SaaS · 10 agency authorizations · since evidence

FedRAMP Marketplace: Adobe Document Cloud including Adobe Acrobat, Adobe Acrobat Sign, Adobe Acrobat AI Assistant, Adobe Acrobat Analyzer, and Adobe Acrobat Services (APIs) Authorized LI-SaaS · 9 agency authorizations · since evidence

FedRAMP Marketplace: Adobe Experience Manager Managed Services (AEMMS-GC) Authorized Moderate · 6 agency authorizations · since evidence

FedRAMP Marketplace: Adobe Learning Manager Authorized LI-SaaS · 2 agency authorizations · since evidence

Transparency

Strong

Breakdown
Subprocessor list30 / 30
Processing locations8 / 8
Purposespartial6 / 7
Data processing addendumnot found0 / 12
Trust center8 / 8
Privacy policy6 / 6
security.txt6 / 6
Security page5 / 5
Status pageunreachable0 / 5
Vulnerability disclosure5 / 5
Pages still reachablesome unreachable this week0 / 8
Total74 / 100

Only documents we can retrieve count: a page behind a login or a broken link scores nothing.

Badge

Adobe transparency rating

For Adobe's own site; it updates with the rating.

<a href="https://thirdpartyindex.com/vendors/adobe"><img src="https://thirdpartyindex.com/badge/adobe.svg" alt="Adobe transparency rating on Third Party Index" height="20"></a>
[![Adobe transparency rating on Third Party Index](https://thirdpartyindex.com/badge/adobe.svg)](https://thirdpartyindex.com/vendors/adobe)

Documents

DocumentVerifiedChangedEvidence
Trust center snapshot
Subprocessor list snapshot
Privacy policy snapshot
Terms snapshot
Security page snapshot
security.txt snapshot
Status page failingsnapshot
Security advisories snapshot

Subprocessors

57 third parties, 18 affiliates. CSV · Atom

NamePurposeLocationListed since
Aiven Ltd Workfront leverages Aiven’s PostgreSQL cloud service as a database to store structured content for all Workfront customers that have selected to run Workfront on Azure. Aiven PostgreSQL is the primary data store of Workfront for customer data.EU; USA
Akamai Technologies Inc. Akamai provides Adobe with content delivery network services.EU; India; Switzerland; UK; USA
Amazon Inc. (Connect) Amazon Connect assists with phone and chat support by providing a set of digital, cloud-based tools to routing customer issues. This can include call recordings, screen recordings, and chat transcripts along with phone numbers.USA
Amazon Web Services, Inc Amazon Web Services (“AWS”) provides cloud hosting services for Adobe to host applications (including Experience Cloud, Creative Cloud and Document Cloud). AWS provides a broad suite of web service architecture to enable Adobe to manage its cloud-based products and services. For certain Adobe products, customer may have the ability to choose their primary hosting location subject to data center availability. For more information on available hosting locations for each product, please refer to the Security Whitepapers available on the Adobe Trust Center.Australia; EU; Japan; Singapore; USA
Appcues Inc. Appcues provides in-app messaging (tooltips, user guidance, and tutorials) to help customers understand how to use Adobe Frame. Data is passed to Appcues to assist with user activation and provide a more personalized onboarding experience. Users are provided with pop-ups, checklists, and options for how to explore product features. Appcues potentially processes marketing sales data (meaning details of pricing subscription data and transaction data) alongside limited personal data (such as name, email and location, user ID and, if users choose to, details of feedback).USA
BellSystem 24 Inc. BellSystem 24 assists Adobe by providing customer care support services for the Adobe Creative Cloud and Document Cloud products in Japanese. They assist with providing self-service resources that allow Adobe’s customer care staff to manage customer requests quickly. Like our other customer care support services, they may process some limited personal data (such as name, age and date of birth) and details relating to business activities (e.g., the context of the support issue they are helping to route).Japan
Black Forest Labs (BFL GmbH) Germany; USA
Box, Inc. Box assists with the secure exchange of uploading and downloading files from user accounts for Adobe Learning Manager by providing a file transfer protocol service (known as FTP). To do so it processes the following data categories: name, username, email address, transactional information (e.g., information about data storage preferences), employment details, and technical usage information.EU; UK; USA
Brave Software, Inc. Adobe Document Cloud utilizes the Brave Search web search API. Brave processes queries constructed based on user inputs. URLs are returned to Adobe services from Brave’s own web index. Brave does not retain any data, but does process queries on Adobe’s behalf in customer facing workflows. Brave will process the queries constructed by Adobe services from customer inputs. IP addresses of the Adobe’s servers are known to the Brave service.France; Germany; USA
Brightcove As part of the Workfront Proof feature, Customers can upload videos to adjust viewer settings and add time-stamped comments. To facilitate this uploading, Brightcove provides Adobe transcoding services via their Zencoder product. This is used to return the video in a format suitable for preview display within Workfront. Brightcove has limited access to customer audio or video recordings when the service is requested.UK; USA
BytePlus Pte. Ltd Indonesia; Malaysia; Singapore
Cloudflare, Inc. For Adobe Developer App Builder, Cloudflare allows Adobe customers to query and modify their data across multiple APIs using a unified schema through a single endpoint. This endpoint is served by Cloudflare, and uses Cloudflare’s security products such as Firewalls, DDos mitigation tools, and rate limiting.; IP addresses and limited login credential data are required for internet communications, and so Cloudflare server logs may contain the IP address of incoming requests, but there would be no other identifying data tied to such requests (as Adobe does not route user information through Cloudflare).; Marketo leverages Cloudflare’s global content delivery network to assist providing high availability and performance by distributing the service spatially relative to end users.USA
Concentrix Corporation Concentrix assists Adobe by providing customer care and technical support services for Adobe products, including translation services in Korean and Japanese (through Concentrix’s Korean entity, Concentrix Service Korea Limited). They assist with providing self-service resources that allow Adobe’s customer care staff to manage customer requests quickly. Like our other customer care support services, they may process some limited personal data (such as name, age and date of birth) and details relating to business activities (e.g., the context of the support issue they are helping to route). However, Adobe remains in control of all customer data processed by Concentrix, and they are bound to act only within our specific instructions.EU; India; Korea; USA
Crowdstrike Holdings, Inc. Crowdstrike provides endpoint threat detection as part of the Adobe Operational Security Stack (OSS). This is a monitoring solution that examines relevant devices to detect and respond to cyber threats (like ransomware and malware). It works by recording limited data points (binaries, devices, files, systems, software inventory statuses, and other data) to monitor particular sequences of events that may indicate a malicious action. Some of the information collected could potentially identify a unique user. However, this is only a remote possibility - it is extremely unlikely that customer personal data will be processed by Crowdstrike as part of this monitoring solution.USA
Databricks Adobe uses Databricks as an orchestration and compute layer for big data processing on AWS.USA
Datadog Inc Adobe uses Datadog for real-time user monitoring and logging. Datadog assists Adobe in providing insight into the front-end performance of applications from the perspective of users so that the product can quickly detect poor user experience and resolve issues with context from across the stack. Through Datadog, Adobe can view visualizations of metrics that can indicate issues like slow load times. The information collected is primarily collated metrics, rather than breakdowns of individual’s experiences.USA
Elastic N.V. Elastic N.V. provides managed services that support some optional (customer initiated) features within Adobe's Document Cloud, Experience Manager and Express products. When customers upload content and decide to use the assessment tools, their content can be extracted, processed, and stored within Elasticsearch indices. No Adobe user account data (such as Adobe usernames, emails, or job titles) is directly stored in Elasticsearch. Personal data is only processed to the extent it exists within customer-uploaded content that customer chooses to share.USA
ElevenLabs Ltd. UK; USA
Fastly, Inc. Fastly assists in providing a subset of Adobe Experience Cloud products content delivery network services to help provide high availability and performance to Adobe customers by distributing the service spatially relative to end user locations. Fastly does not have access to Adobe customer personal data outright, outside of the limited scope of its content delivery network services (and therefore is limited to email address, IP address, username, and technical and system data such as browser or device information).EU; UK; USA
Features and Labels Inc (“fal.ai”). Malaysia; Singapore; USA
Frame.io All provide technical and customer support services depending on region of customer.USA
Google (Alphabet) USA
Hoodoo Digital LLC Hoodoo Digital assists Adobe by establishing platform connection services between Adobe Workfront and Adobe Experience Manager for our customers. Hoodoo Digital is essentially a consultancy that specializes in Adobe solutions, offering services with A/B testing and personalization, analytics, and asset workflow management. As a sub-processor, they potentially may process some limited Adobe customer data (such as customer user details including name, location, or email address along with technical information such as IP address and unique user identifier codes) in the course setting up a connection to the Workfront and Adobe Experience Manager products.USA
Intercom Inc. Intercom helps Adobe provide a platform for community-based support, where users can reach out to ask questions or address issues by supplying in-app messaging software to allow for the handling of complaints and issues raised by customers related to Frame.io and Adobe Express products. Intercom may access personal data contained in customer-initiated support messages as well as email addresses, IP addresses, and other technical information.Australia; EU; UK; USA
Khoros LLC Khoros helps Adobe provide a platform for community-based support, where users can reach out to ask questions or address issues. Khoros provides customer engagement software to support messaging, chat, online communities and social media management (e.g., handling complaints and issues raised through these channels). Adobe remains in control of all customer data processed by Khoros and they are bound to act only within our specific instructions. The personal data that is in scope is details of users (such as name, email address, job title and location) and their internal communications (e.g., what individual users submit as part of community-based support).UK; USA
Kuaishou Technology Singapore
LexisNexis Risk Solutions Group LexisNexis Risk Solutions assists Adobe by providing ID verification and authentication services related to our Adobe Acrobat Sign product for our customers based in the USA. The solution works by using rule-based and machine-learning algorithms to differentiate between fraudulent actors and legitimate users. It does this by generating an identity score using personal data such as name, email, IP address, phone number, shipping address, billing address, or date of birth.USA
Luma AI Inc. USA
Marketo, Inc. All provide technical and customer support services depending on region of customer.USA
Marketo EMEA Ltd. All provide technical and customer support services depending on region of customer.United Kingdom
Merkle, Inc. Merkle is an Adobe solution partner that provides customer care expertise. Specifically, they help customers get more tailored services from the Adobe Experience Cloud product by providing an integration with their Merkury Identity Solution product (that allows customers to get their own insights, optimized segmentation and breakdowns of profiles in accordance with what they want the Adobe Experience Cloud to deliver). Like our other customer care support services, they may process some limited personal data (such as name, age and date of birth) and details relating to business activities (e.g., the context of the support issue they are helping to route).India; USA
Microsoft Corporation Microsoft Azure (Azure) provides cloud hosting services for Adobe Cloud Services (Experience Cloud, Creative Cloud, and Document Cloud). Adobe also offers the use of the Azure OpenAI service to provide features within Adobe Apps/Services where customers decide to use such features (e.g., AI Assistant in Adobe Acrobat). Azure is a full-service cloud platform. Data resides in Microsoft data centers but is managed day-to-day by Adobe (including strict access control protocols). For the limited categories where Microsoft Azure can access Adobe customer data, there are strict controls applied, and all processing is subject to a range of technical and organizational measures. For certain Adobe products, customer may have the ability to choose their primary hosting location subject to data center availability. For more information on available hosting locations for each product, please refer to the Security Whitepapers available on the Adobe Trust Center.; Microsoft Dynamics 365 Customer Service is a solution that Adobe deploys to assist with customer engagement management. Dynamics allows Adobe to track the progress of tickets in an organized fashion designed to ensure that service level agreements with our customers are met. Customers often have different preferences for tracking the progress of issues (particularly when it comes to assessing whether Adobe is delivering on support obligations it has been contracted for). For this reason, Dynamics is deployed to provide insights into support operations by generating reports and analytics on key metrics (like ticket volume, response times and customer satisfaction). As a result, they may process some limited personal data (such as name, age and date of birth) and details relating to business activities (e.g., the context of the support issue they are helping to route). However, Adobe remains in control of all customer data processed by Microsoft Dynamics, and they are bound to act only within our specific instructions.Australia; Canada; EU; India; UK; USA
Mitek Systems Inc. Mitek powers the Government ID Verification service in Adobe Sign. It provides the ability to authenticate signers by retrieving their identity information from a physical ID document and checking the likeness of the person by matching the photo ID with a live photo. Mitek may process names, national ID information (including taxpayer IDs and passport information), and images.EU; USA
Mitto AG Adobe may send SMS messages to its customers for authentication, authorization and commerce flows. Mitto helps Adobe by providing SMS delivery services. To do this Mitto would have access to names, addresses, and phone numbers.EU; Serbia; UK; USA
MongoDB, Inc. Adobe leverages MongoDB’s “Atlas” cloud service. This service is used (1) to store the structured content in customer’s content repository (e.g., for Workfront and Commerce customers) and (2) for the processing of metadata required to support data processing and reporting (e.g., for Adobe Analytics, Customer Journey Analytics, and Customer Journey Analytics B2B Edition).EU; USA
New Relic Inc. New Relic provides Adobe tools to help monitor overall software infrastructure and provide alerts as to telemetry data to help Adobe identify critical issues. New Relic primarily only processes technical telemetry data for Adobe (namely metrics, events, logs and traces). New Relic processes minimal personal data of customer users (e.g., IP addresses in CDN logs are used in New Relic to detect BOT traffic and bad actors in order to update firewall rules and maintain site performance).EU; USA
Okta, Inc. Adobe uses Okta to authenticate secure access to Adobe Cloud Services. It is integrated with Adobe’s cloud functions and provides provisioning, single sign-on, active directory and lightweight directory access protocol integration, centralized deprovisioning of users, multifactor authentication, and mobile identity management. Okta may process contact information (such as name, email address, and phone number), additional multi-factor authentication factor setup details, content a customer upload (such as identification or other documentation), and information regarding the websites and applications that a specific user visits when using the Okta authentication service. Okta may also receive ancillary data such as device data, usage data, and metadata. Okta’s endpoint threat detection occurs on the Adobe solution stack (meaning their access to raw customer personal data is prevented).EU; UK; USA
OpenAI EU; USA
Platform.sh Platform.sh provide “platform-as-a-service” hosting services for Adobe Commerce. This means they allow customers to develop commerce solutions via Adobe Commerce by providing fully automated cloud infrastructure. This is done on a single instance approach, meaning customer data is not comingled.EU; USA
Red Hat, Inc. Adobe leverages OpenShift on top of its cloud infrastructure to orchestrate, scale, and manage its services. OpenShift is an implementation of Kubernetes, which enables container orchestration, scaling, and service management.USA
Redis Cloud Redis Cloud stores and processes probabilistic data structures to provide enhanced computing capabilities. Redis Cloud also provides caching services for customer reports.USA
Runway AI Inc. USA
SCSK Serviceware Corporation SCSK Serviceware provides Adobe Experience Cloud’s customer support services, including call center functions, as the Tier1 service desk and customer care for professional services for Marketo in Japanese. To provide these services, they may process some limited personal data (such as name, phone number and email address) and details relating to business activities (e.g., the context of the support issue they are engaging with Adobe on).Japan
SendGrid, Inc. SendGrid is used to send transactional emails from Adobe Commerce (such as receipts to customers, login emails, and other administration information) if a customer chooses to use this option. When enabled, SendGrid will process certain details (including email address, IP address, and subject line of emails).EU; USA
Sinch AB Adobe uses Sinch to provide SMS, MMS, and RCS capabilities within the product, if Sinch is licensed by customer. Note that Sinch only acts as Adobe’s sub-processor for these messaging services in the U.S. and Canada; for messaging in other countries, customers enter into terms directly with Sinch.USA
Sisense Ltd. Sisense provides a data analytics query and visualization software tool with particular plug-ins for Marketo that allow customers to generate specific data visualization analysis. Customers decide on the parameters of the visualization, and in doing so can choose to input user level information such as name, contact details (email, phone number), and engagement data (such as web browsing information such as clicks and open rate).France; USA
Slack Technologies Slack assists Adobe with resolving service requests (e.g., customer calls or partner requests on bugs, fixes and other issues). It allows Adobe to track tickets by assigning case numbers to every service inquiry we receive and track the issue to the resolution. It can distribute tickets according to priority and subject matter while giving top-level dashboards and reports on things like overall resolution time and productivity spikes. Adobe customers tend to seek support in a variety of ways (e.g., by phone, email, text, social media messaging or via community platforms). Slack also helps Adobe with omni-channel routing which allows Adobe to filter requests that come in through the different channels and get them to the right customer care support function. To provide these services, Slack may process some limited personal data (such as name, age and date of birth) and details relating to business activities (e.g., the context of the support issue they are helping to route).EU; USA
Snowflake Computing Inc. Adobe uses Snowflake for data warehousing and database storage services across a subset of Experience Cloud products. This includes business intelligence on campaign performance, various KPI tracking tools, and sales report features.EU; USA
Speechmatics Speechmatics provides automatic speech recognition software to allow for speech to text within Adobe products. To do this, Speechmatics has limited ability to process personal data contained in voice details, names, and personal data.UK; USA
Splunk, Inc. Splunk assists with security event logging and monitoring via the collection of system data. Logs are generated through Adobe’s software applications and are analyzed and inspected for bugs or system failures in an Adobe-managed Splunk environment. Splunk may process data about Adobe’s operating environment and configuration. This in turn can include user interactions, and sessions related to Adobe’s use of Splunk in which information and related metadata about Adobe’s network and systems architecture configurations is accessible. From a customer data perspective, Splunk may process the number and types of searches, errors, and number of active and licensed users. Additionally, Splunk offers support services to Adobe for troubleshooting which may involve access to user/customer identifiable information. Finally, there is also a possibility of certain customer data (such as IP addresses, names, contact information,) being processed as part of a security investigation, threat detection, or incident monitoring.EU; UK; USA
Stream Adobe uses Stream's enterprise chat offering for facilitating livestreaming chat functions with Behance. Currently, chat functionality is only available while streamers are live and is an optional service customers may choose to deploy. If deployed, Stream will have access to the personal data submitted to the chat and video in question along with names, email addresses, and user account information.EU; USA
Teleperformance Teleperformance supports Adobe’s customer care support services by providing technical support functions (including call center functions) and professional services for the Japan, Hong Kong and Taiwan markets (through Teleperformance Japan Co. Ltd and Beijing Interactive CRM Technology Limited). To provide these services, they may process some limited personal data (such as name, age and date of birth) and details relating to business activities (e.g., the context of the support issue they are engaging with Adobe on). Adobe remains in control of all customer data processed by Teleperformance and they are bound to act only within our specific instructions.China; EU; India; Japan; USA
Telesign Corporation Telesign provides mobile communication services to Adobe by relaying SMS messages with links to Adobe customers and placing automated phone voice calls that read aloud predefined messages (complementing the SMS messages service). These services are run to support functions in the Adobe Sign and Behance products. In providing these services, Telesign may access first name, last name, address, e-mail address, telephone number, location data, contact information, and device information.EU; Serbia; UK; USA
Topaz Labs LLC USA
Twilio, Inc. Twilio provides multi-factor authentication services allowing users to receive SMS messages and phone calls to verify their login information. Twilio’s Segment product is used to collect and transform customer data across the Adobe Frame platform. To do this, Twilio may process name, contact details (email and work number), work details (e.g., title) along with technical information such as device data, referring URL, and web browsing information associated with the authentication being verified.USA
Workfront Inc. All provide technical and customer support services depending on region of customer.USA; United Kingdom
Zendesk Inc. Zendesk supports Adobe’s customer care support services by providing scalable customer service solutions (including messaging, help center coordination, agent workspaces, ticketing integration, issue routing, integrations, and analytics and reporting). To provide these services, they may process some limited personal data (such as name, age and date of birth) and details relating to business activities (e.g., the context of the support issue they are engaging with Adobe on).EU; USA
Adobe affiliates (18)
NamePurposeLocationListed since
Adobe Inc. All provide technical and customer support services depending on region of customer.Japan; USA
Adobe Development ARM, LLC All provide technical and customer support services depending on region of customer.Armenia
Adobe Research Schweiz AG All provide technical and customer support services depending on region of customer.Switzerland
Adobe Systems s.r.o. All provide technical and customer support services depending on region of customer.Australia; Czech Republic; Germany
Adobe Systems Belgium BV All provide technical and customer support services depending on region of customer.Belgium
Adobe Systems Benelux BV All provide technical and customer support services depending on region of customer.Netherlands
Adobe Systems Canada Inc. All provide technical and customer support services depending on region of customer.Canada
Adobe Systems Danmark ApS All provide technical and customer support services depending on region of customer.Denmark
Adobe Systems Engineering GmbH All provide technical and customer support services depending on region of customer.Germany
Adobe Systems Europe Limited All provide technical and customer support services depending on region of customer.United Kingdom
Adobe Systems France SAS All provide technical and customer support services depending on region of customer.France
Adobe Systems Iberica, S.L. All provide technical and customer support services depending on region of customer.Spain
Adobe Systems India Pvt. Ltd. All provide technical and customer support services depending on region of customer.India
Adobe Systems Italia Srl. All provide technical and customer support services depending on region of customer.Italy
Adobe Systems Nordic AB All provide technical and customer support services depending on region of customer.Sweden
Adobe Systems Norge AS All provide technical and customer support services depending on region of customer.Norway
Adobe Systems Romania SRL All provide technical and customer support services depending on region of customer.Romania
Adobe Systems Schweiz GmbH All provide technical and customer support services depending on region of customer.Switzerland

Listed as a subprocessor by (13)

Purposes as each company states them.

Security record

What public security catalogs list for Adobe, in their words.

Known exploited vulnerabilities

82 vulnerabilities in Adobe's software that CISA lists as exploited in the wild.

CVEProductVulnerabilityListed
CVE-2026-71362Commerce and Magento Adobe Commerce and Magento Incorrect Authorization Vulnerability evidence
CVE-2026-75650Commerce and MagentoAdobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability evidence
CVE-2026-48282ColdFusionAdobe ColdFusion Path Traversal Vulnerability evidence
CVE-2009-3459Acrobat and ReaderAdobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability evidence
CVE-2020-9715AcrobatAdobe Acrobat Use-After-Free Vulnerability evidence
CVE-2026-34621Acrobat and ReaderAdobe Acrobat and Reader Prototype Pollution Vulnerability evidence
CVE-2025-54236Commerce and MagentoAdobe Commerce and Magento Improper Input Validation Vulnerability evidence
CVE-2025-54253Experience Manager (AEM) FormsAdobe Experience Manager Forms Code Execution Vulnerability evidence
CVE-2017-3066ColdFusionAdobe ColdFusion Deserialization Vulnerability evidence
CVE-2024-20767ColdFusionAdobe ColdFusion Improper Access Control Vulnerability evidence
72 more
CVEProductVulnerabilityListed
CVE-2013-0643Flash PlayerAdobe Flash Player Incorrect Default Permissions Vulnerability evidence
CVE-2013-0648Flash PlayerAdobe Flash Player Code Execution Vulnerability evidence
CVE-2014-0497Flash PlayerAdobe Flash Player Integer Underflow Vulnerablity evidence
CVE-2014-0502Flash PlayerAdobe Flash Player Double Free Vulnerablity evidence
CVE-2024-34102Commerce and Magento Open SourceAdobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability evidence
CVE-2023-29300ColdFusionAdobe ColdFusion Deserialization of Untrusted Data Vulnerability used by ransomware evidence
CVE-2023-38203ColdFusionAdobe ColdFusion Deserialization of Untrusted Data Vulnerability used by ransomware evidence
CVE-2023-21608Acrobat and ReaderAdobe Acrobat and Reader Use-After-Free Vulnerability evidence
CVE-2023-26369Acrobat and ReaderAdobe Acrobat and Reader Out-of-Bounds Write Vulnerability evidence
CVE-2023-26359ColdFusionAdobe ColdFusion Deserialization of Untrusted Data Vulnerability evidence
CVE-2023-29298ColdFusionAdobe ColdFusion Improper Access Control Vulnerability evidence
CVE-2023-38205ColdFusionAdobe ColdFusion Improper Access Control Vulnerability evidence
CVE-2023-26360ColdFusionAdobe ColdFusion Deserialization of Untrusted Data Vulnerability evidence
CVE-2007-5659Acrobat and ReaderAdobe Acrobat and Reader Buffer Overflow Vulnerability evidence
CVE-2008-0655Acrobat and ReaderAdobe Acrobat and Reader Unspecified Vulnerability evidence
CVE-2009-1862Acrobat and Reader, Flash PlayerAdobe Acrobat and Reader, Flash Player Unspecified Vulnerability evidence
CVE-2009-3953Acrobat and ReaderAdobe Acrobat and Reader Universal 3D Remote Code Execution Vulnerability evidence
CVE-2009-4324Acrobat and ReaderAdobe Acrobat and Reader Use-After-Free Vulnerability evidence
CVE-2010-1297Flash PlayerAdobe Flash Player Memory Corruption Vulnerability evidence
CVE-2010-2883Acrobat and ReaderAdobe Acrobat and Reader Stack-Based Buffer Overflow Vulnerability evidence
CVE-2011-0609Flash PlayerAdobe Flash Player Unspecified Vulnerability evidence
CVE-2011-2462Reader and AcrobatAdobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability evidence
CVE-2012-0754Flash PlayerAdobe Flash Player Memory Corruption Vulnerability evidence
CVE-2012-0767Flash PlayerAdobe Flash Player Cross-Site Scripting (XSS) Vulnerability evidence
CVE-2012-5054Flash PlayerAdobe Flash Player Integer Overflow Vulnerability evidence
CVE-2018-4990Acrobat and ReaderAdobe Acrobat and Reader Double Free Vulnerability evidence
CVE-2014-0546Reader and AcrobatAdobe Reader and Acrobat Sandbox Bypass Vulnerability evidence
CVE-2014-8439Flash PlayerAdobe Flash Player Dereferenced Pointer Vulnerability evidence
CVE-2015-0310Flash PlayerAdobe Flash Player ASLR Bypass Vulnerability evidence
CVE-2015-8651Flash PlayerAdobe Flash Player Integer Overflow Vulnerability evidence
CVE-2016-0984Flash Player and AIRAdobe Flash Player and AIR Use-After-Free Vulnerability evidence
CVE-2016-1010Flash Player and AIRAdobe Flash Player and AIR Integer Overflow Vulnerability evidence
CVE-2018-5002Flash PlayerAdobe Flash Player Stack-based Buffer Overflow Vulnerability evidence
CVE-2014-9163Flash PlayerAdobe Flash Player Stack-Based Buffer Overflow Vulnerability evidence
CVE-2015-0311Flash PlayerAdobe Flash Player Remote Code Execution Vulnerability evidence
CVE-2015-0313Flash PlayerAdobe Flash Player Use-After-Free Vulnerability evidence
CVE-2015-3113Flash PlayerAdobe Flash Player Heap-Based Buffer Overflow Vulnerability evidence
CVE-2015-5122Flash PlayerAdobe Flash Player Use-After-Free Vulnerability evidence
CVE-2015-5123Flash PlayerAdobe Flash Player Use-After-Free Vulnerability evidence
CVE-2012-2034Flash PlayerAdobe Flash Player Memory Corruption Vulnerability evidence
CVE-2013-2729Reader and AcrobatAdobe Reader and Acrobat Arbitrary Integer Overflow Vulnerability evidence
CVE-2009-0927Reader and AcrobatAdobe Reader and Adobe Acrobat Stack-Based Buffer Overflow Vulnerability evidence
CVE-2010-2861ColdFusionAdobe ColdFusion Directory Traversal Vulnerability used by ransomware evidence
CVE-2016-4171Flash PlayerAdobe Flash Player Remote Code Execution Vulnerability evidence
CVE-2016-7892Flash PlayerAdobe Flash Player Use-After-Free Vulnerability evidence
CVE-2009-3960BlazeDSAdobe BlazeDS Information Disclosure Vulnerability used by ransomware evidence
CVE-2013-0625ColdFusionAdobe ColdFusion Authentication Bypass Vulnerability evidence
CVE-2013-0629ColdFusionAdobe ColdFusion Directory Traversal Vulnerability evidence
CVE-2013-0631ColdFusionAdobe ColdFusion Information Disclosure Vulnerability evidence
CVE-2008-2992Acrobat and ReaderAdobe Reader and Acrobat Input Validation Vulnerability used by ransomware evidence
CVE-2010-0188Reader and AcrobatAdobe Reader and Acrobat Arbitrary Code Execution Vulnerability used by ransomware evidence
CVE-2011-0611Flash PlayerAdobe Flash Player Remote Code Execution Vulnerability evidence
CVE-2012-1535Flash PlayerAdobe Flash Player Arbitrary Code Execution Vulnerability evidence
CVE-2013-0632ColdFusionAdobe ColdFusion Authentication Bypass Vulnerability evidence
CVE-2013-0640Reader and AcrobatAdobe Reader and Acrobat Memory Corruption Vulnerability evidence
CVE-2013-0641ReaderAdobe Reader Buffer Overflow Vulnerability evidence
CVE-2013-3346Reader and AcrobatAdobe Reader and Acrobat Memory Corruption Vulnerability evidence
CVE-2014-0496Reader and AcrobatAdobe Reader and Acrobat Use-After-Free Vulnerability evidence
CVE-2015-3043Flash PlayerAdobe Flash Player Memory Corruption Vulnerability evidence
CVE-2015-5119Flash PlayerAdobe Flash Player Use-After-Free Vulnerability evidence
CVE-2015-7645Flash PlayerAdobe Flash Player Arbitrary Code Execution Vulnerability used by ransomware evidence
CVE-2016-1019Flash PlayerAdobe Flash Player Arbitrary Code Execution Vulnerability used by ransomware evidence
CVE-2016-4117Flash PlayerAdobe Flash Player Arbitrary Code Execution Vulnerability used by ransomware evidence
CVE-2016-7855Flash PlayerAdobe Flash Player Use-After-Free Vulnerability evidence
CVE-2017-11292Flash PlayerAdobe Flash Player Type Confusion Vulnerability evidence
CVE-2018-15982Flash PlayerAdobe Flash Player Use-After-Free Vulnerability used by ransomware evidence
CVE-2022-24086Commerce and Magento Open SourceAdobe Commerce and Magento Open Source Improper Input Validation Vulnerability evidence
CVE-2018-15961ColdFusionAdobe ColdFusion Unrestricted File Upload Vulnerability evidence
CVE-2018-4878Flash PlayerAdobe Flash Player Use-After-Free Vulnerability used by ransomware evidence
CVE-2018-4939ColdFusionAdobe ColdFusion Deserialization of Untrusted Data Vulnerability evidence
CVE-2021-21017Acrobat and ReaderAdobe Acrobat and Reader Heap-based Buffer Overflow Vulnerability evidence
CVE-2021-28550Acrobat and ReaderAdobe Acrobat and Reader Use-After-Free Vulnerability evidence

Data breaches

Source: CISA Known Exploited Vulnerabilities catalog. Breach data from Have I Been Pwned (CC BY 4.0), which calls every entry a breach, including data scraped from public pages.

Changes

None since tracking began.