Adobe
Includes: Marketo
FedRAMP Marketplace: Adobe Acrobat Sign for Government Authorized Moderate · 10 agency authorizations · since evidence
FedRAMP Marketplace: Adobe Analytics Authorized LI-SaaS · 2 agency authorizations · since evidence
FedRAMP Marketplace: Adobe Campaign Authorized LI-SaaS · 4 agency authorizations · since evidence
FedRAMP Marketplace: Adobe Connect Managed Services (ACMS-GC) Authorized Moderate · 4 agency authorizations · since evidence
FedRAMP Marketplace: Adobe Creative Cloud for Enterprise Authorized LI-SaaS · 10 agency authorizations · since evidence
FedRAMP Marketplace: Adobe Document Cloud including Adobe Acrobat, Adobe Acrobat Sign, Adobe Acrobat AI Assistant, Adobe Acrobat Analyzer, and Adobe Acrobat Services (APIs) Authorized LI-SaaS · 9 agency authorizations · since evidence
FedRAMP Marketplace: Adobe Experience Manager Managed Services (AEMMS-GC) Authorized Moderate · 6 agency authorizations · since evidence
FedRAMP Marketplace: Adobe Learning Manager Authorized LI-SaaS · 2 agency authorizations · since evidence
Documents
| Document | Verified | Changed | Evidence |
|---|---|---|---|
| Trust center | snapshot | ||
| Subprocessor list | snapshot | ||
| Privacy policy | snapshot | ||
| Terms | snapshot | ||
| Security page | snapshot | ||
| security.txt | snapshot | ||
| Status page failing | snapshot | ||
| Security advisories | snapshot |
Subprocessors
57 third parties, 18 affiliates. CSV · Atom
| Name | Purpose | Location | Listed since |
|---|---|---|---|
| Aiven Ltd | Workfront leverages Aiven’s PostgreSQL cloud service as a database to store structured content for all Workfront customers that have selected to run Workfront on Azure. Aiven PostgreSQL is the primary data store of Workfront for customer data. | EU; USA | |
| Akamai Technologies Inc. | Akamai provides Adobe with content delivery network services. | EU; India; Switzerland; UK; USA | |
| Amazon Inc. (Connect) | Amazon Connect assists with phone and chat support by providing a set of digital, cloud-based tools to routing customer issues. This can include call recordings, screen recordings, and chat transcripts along with phone numbers. | USA | |
| Amazon Web Services, Inc | Amazon Web Services (“AWS”) provides cloud hosting services for Adobe to host applications (including Experience Cloud, Creative Cloud and Document Cloud). AWS provides a broad suite of web service architecture to enable Adobe to manage its cloud-based products and services. For certain Adobe products, customer may have the ability to choose their primary hosting location subject to data center availability. For more information on available hosting locations for each product, please refer to the Security Whitepapers available on the Adobe Trust Center. | Australia; EU; Japan; Singapore; USA | |
| Appcues Inc. | Appcues provides in-app messaging (tooltips, user guidance, and tutorials) to help customers understand how to use Adobe Frame. Data is passed to Appcues to assist with user activation and provide a more personalized onboarding experience. Users are provided with pop-ups, checklists, and options for how to explore product features. Appcues potentially processes marketing sales data (meaning details of pricing subscription data and transaction data) alongside limited personal data (such as name, email and location, user ID and, if users choose to, details of feedback). | USA | |
| BellSystem 24 Inc. | BellSystem 24 assists Adobe by providing customer care support services for the Adobe Creative Cloud and Document Cloud products in Japanese. They assist with providing self-service resources that allow Adobe’s customer care staff to manage customer requests quickly. Like our other customer care support services, they may process some limited personal data (such as name, age and date of birth) and details relating to business activities (e.g., the context of the support issue they are helping to route). | Japan | |
| Black Forest Labs (BFL GmbH) | Germany; USA | ||
| Box, Inc. | Box assists with the secure exchange of uploading and downloading files from user accounts for Adobe Learning Manager by providing a file transfer protocol service (known as FTP). To do so it processes the following data categories: name, username, email address, transactional information (e.g., information about data storage preferences), employment details, and technical usage information. | EU; UK; USA | |
| Brave Software, Inc. | Adobe Document Cloud utilizes the Brave Search web search API. Brave processes queries constructed based on user inputs. URLs are returned to Adobe services from Brave’s own web index. Brave does not retain any data, but does process queries on Adobe’s behalf in customer facing workflows. Brave will process the queries constructed by Adobe services from customer inputs. IP addresses of the Adobe’s servers are known to the Brave service. | France; Germany; USA | |
| Brightcove | As part of the Workfront Proof feature, Customers can upload videos to adjust viewer settings and add time-stamped comments. To facilitate this uploading, Brightcove provides Adobe transcoding services via their Zencoder product. This is used to return the video in a format suitable for preview display within Workfront. Brightcove has limited access to customer audio or video recordings when the service is requested. | UK; USA | |
| BytePlus Pte. Ltd | Indonesia; Malaysia; Singapore | ||
| Cloudflare, Inc. | For Adobe Developer App Builder, Cloudflare allows Adobe customers to query and modify their data across multiple APIs using a unified schema through a single endpoint. This endpoint is served by Cloudflare, and uses Cloudflare’s security products such as Firewalls, DDos mitigation tools, and rate limiting.; IP addresses and limited login credential data are required for internet communications, and so Cloudflare server logs may contain the IP address of incoming requests, but there would be no other identifying data tied to such requests (as Adobe does not route user information through Cloudflare).; Marketo leverages Cloudflare’s global content delivery network to assist providing high availability and performance by distributing the service spatially relative to end users. | USA | |
| Concentrix Corporation | Concentrix assists Adobe by providing customer care and technical support services for Adobe products, including translation services in Korean and Japanese (through Concentrix’s Korean entity, Concentrix Service Korea Limited). They assist with providing self-service resources that allow Adobe’s customer care staff to manage customer requests quickly. Like our other customer care support services, they may process some limited personal data (such as name, age and date of birth) and details relating to business activities (e.g., the context of the support issue they are helping to route). However, Adobe remains in control of all customer data processed by Concentrix, and they are bound to act only within our specific instructions. | EU; India; Korea; USA | |
| Crowdstrike Holdings, Inc. | Crowdstrike provides endpoint threat detection as part of the Adobe Operational Security Stack (OSS). This is a monitoring solution that examines relevant devices to detect and respond to cyber threats (like ransomware and malware). It works by recording limited data points (binaries, devices, files, systems, software inventory statuses, and other data) to monitor particular sequences of events that may indicate a malicious action. Some of the information collected could potentially identify a unique user. However, this is only a remote possibility - it is extremely unlikely that customer personal data will be processed by Crowdstrike as part of this monitoring solution. | USA | |
| Databricks | Adobe uses Databricks as an orchestration and compute layer for big data processing on AWS. | USA | |
| Datadog Inc | Adobe uses Datadog for real-time user monitoring and logging. Datadog assists Adobe in providing insight into the front-end performance of applications from the perspective of users so that the product can quickly detect poor user experience and resolve issues with context from across the stack. Through Datadog, Adobe can view visualizations of metrics that can indicate issues like slow load times. The information collected is primarily collated metrics, rather than breakdowns of individual’s experiences. | USA | |
| Elastic N.V. | Elastic N.V. provides managed services that support some optional (customer initiated) features within Adobe's Document Cloud, Experience Manager and Express products. When customers upload content and decide to use the assessment tools, their content can be extracted, processed, and stored within Elasticsearch indices. No Adobe user account data (such as Adobe usernames, emails, or job titles) is directly stored in Elasticsearch. Personal data is only processed to the extent it exists within customer-uploaded content that customer chooses to share. | USA | |
| ElevenLabs Ltd. | UK; USA | ||
| Fastly, Inc. | Fastly assists in providing a subset of Adobe Experience Cloud products content delivery network services to help provide high availability and performance to Adobe customers by distributing the service spatially relative to end user locations. Fastly does not have access to Adobe customer personal data outright, outside of the limited scope of its content delivery network services (and therefore is limited to email address, IP address, username, and technical and system data such as browser or device information). | EU; UK; USA | |
| Features and Labels Inc (“fal.ai”). | Malaysia; Singapore; USA | ||
| Frame.io | All provide technical and customer support services depending on region of customer. | USA | |
| Google (Alphabet) | USA | ||
| Hoodoo Digital LLC | Hoodoo Digital assists Adobe by establishing platform connection services between Adobe Workfront and Adobe Experience Manager for our customers. Hoodoo Digital is essentially a consultancy that specializes in Adobe solutions, offering services with A/B testing and personalization, analytics, and asset workflow management. As a sub-processor, they potentially may process some limited Adobe customer data (such as customer user details including name, location, or email address along with technical information such as IP address and unique user identifier codes) in the course setting up a connection to the Workfront and Adobe Experience Manager products. | USA | |
| Intercom Inc. | Intercom helps Adobe provide a platform for community-based support, where users can reach out to ask questions or address issues by supplying in-app messaging software to allow for the handling of complaints and issues raised by customers related to Frame.io and Adobe Express products. Intercom may access personal data contained in customer-initiated support messages as well as email addresses, IP addresses, and other technical information. | Australia; EU; UK; USA | |
| Khoros LLC | Khoros helps Adobe provide a platform for community-based support, where users can reach out to ask questions or address issues. Khoros provides customer engagement software to support messaging, chat, online communities and social media management (e.g., handling complaints and issues raised through these channels). Adobe remains in control of all customer data processed by Khoros and they are bound to act only within our specific instructions. The personal data that is in scope is details of users (such as name, email address, job title and location) and their internal communications (e.g., what individual users submit as part of community-based support). | UK; USA | |
| Kuaishou Technology | Singapore | ||
| LexisNexis Risk Solutions Group | LexisNexis Risk Solutions assists Adobe by providing ID verification and authentication services related to our Adobe Acrobat Sign product for our customers based in the USA. The solution works by using rule-based and machine-learning algorithms to differentiate between fraudulent actors and legitimate users. It does this by generating an identity score using personal data such as name, email, IP address, phone number, shipping address, billing address, or date of birth. | USA | |
| Luma AI Inc. | USA | ||
| Marketo, Inc. | All provide technical and customer support services depending on region of customer. | USA | |
| Marketo EMEA Ltd. | All provide technical and customer support services depending on region of customer. | United Kingdom | |
| Merkle, Inc. | Merkle is an Adobe solution partner that provides customer care expertise. Specifically, they help customers get more tailored services from the Adobe Experience Cloud product by providing an integration with their Merkury Identity Solution product (that allows customers to get their own insights, optimized segmentation and breakdowns of profiles in accordance with what they want the Adobe Experience Cloud to deliver). Like our other customer care support services, they may process some limited personal data (such as name, age and date of birth) and details relating to business activities (e.g., the context of the support issue they are helping to route). | India; USA | |
| Microsoft Corporation | Microsoft Azure (Azure) provides cloud hosting services for Adobe Cloud Services (Experience Cloud, Creative Cloud, and Document Cloud). Adobe also offers the use of the Azure OpenAI service to provide features within Adobe Apps/Services where customers decide to use such features (e.g., AI Assistant in Adobe Acrobat). Azure is a full-service cloud platform. Data resides in Microsoft data centers but is managed day-to-day by Adobe (including strict access control protocols). For the limited categories where Microsoft Azure can access Adobe customer data, there are strict controls applied, and all processing is subject to a range of technical and organizational measures. For certain Adobe products, customer may have the ability to choose their primary hosting location subject to data center availability. For more information on available hosting locations for each product, please refer to the Security Whitepapers available on the Adobe Trust Center.; Microsoft Dynamics 365 Customer Service is a solution that Adobe deploys to assist with customer engagement management. Dynamics allows Adobe to track the progress of tickets in an organized fashion designed to ensure that service level agreements with our customers are met. Customers often have different preferences for tracking the progress of issues (particularly when it comes to assessing whether Adobe is delivering on support obligations it has been contracted for). For this reason, Dynamics is deployed to provide insights into support operations by generating reports and analytics on key metrics (like ticket volume, response times and customer satisfaction). As a result, they may process some limited personal data (such as name, age and date of birth) and details relating to business activities (e.g., the context of the support issue they are helping to route). However, Adobe remains in control of all customer data processed by Microsoft Dynamics, and they are bound to act only within our specific instructions. | Australia; Canada; EU; India; UK; USA | |
| Mitek Systems Inc. | Mitek powers the Government ID Verification service in Adobe Sign. It provides the ability to authenticate signers by retrieving their identity information from a physical ID document and checking the likeness of the person by matching the photo ID with a live photo. Mitek may process names, national ID information (including taxpayer IDs and passport information), and images. | EU; USA | |
| Mitto AG | Adobe may send SMS messages to its customers for authentication, authorization and commerce flows. Mitto helps Adobe by providing SMS delivery services. To do this Mitto would have access to names, addresses, and phone numbers. | EU; Serbia; UK; USA | |
| MongoDB, Inc. | Adobe leverages MongoDB’s “Atlas” cloud service. This service is used (1) to store the structured content in customer’s content repository (e.g., for Workfront and Commerce customers) and (2) for the processing of metadata required to support data processing and reporting (e.g., for Adobe Analytics, Customer Journey Analytics, and Customer Journey Analytics B2B Edition). | EU; USA | |
| New Relic Inc. | New Relic provides Adobe tools to help monitor overall software infrastructure and provide alerts as to telemetry data to help Adobe identify critical issues. New Relic primarily only processes technical telemetry data for Adobe (namely metrics, events, logs and traces). New Relic processes minimal personal data of customer users (e.g., IP addresses in CDN logs are used in New Relic to detect BOT traffic and bad actors in order to update firewall rules and maintain site performance). | EU; USA | |
| Okta, Inc. | Adobe uses Okta to authenticate secure access to Adobe Cloud Services. It is integrated with Adobe’s cloud functions and provides provisioning, single sign-on, active directory and lightweight directory access protocol integration, centralized deprovisioning of users, multifactor authentication, and mobile identity management. Okta may process contact information (such as name, email address, and phone number), additional multi-factor authentication factor setup details, content a customer upload (such as identification or other documentation), and information regarding the websites and applications that a specific user visits when using the Okta authentication service. Okta may also receive ancillary data such as device data, usage data, and metadata. Okta’s endpoint threat detection occurs on the Adobe solution stack (meaning their access to raw customer personal data is prevented). | EU; UK; USA | |
| OpenAI | EU; USA | ||
| Platform.sh | Platform.sh provide “platform-as-a-service” hosting services for Adobe Commerce. This means they allow customers to develop commerce solutions via Adobe Commerce by providing fully automated cloud infrastructure. This is done on a single instance approach, meaning customer data is not comingled. | EU; USA | |
| Red Hat, Inc. | Adobe leverages OpenShift on top of its cloud infrastructure to orchestrate, scale, and manage its services. OpenShift is an implementation of Kubernetes, which enables container orchestration, scaling, and service management. | USA | |
| Redis Cloud | Redis Cloud stores and processes probabilistic data structures to provide enhanced computing capabilities. Redis Cloud also provides caching services for customer reports. | USA | |
| Runway AI Inc. | USA | ||
| SCSK Serviceware Corporation | SCSK Serviceware provides Adobe Experience Cloud’s customer support services, including call center functions, as the Tier1 service desk and customer care for professional services for Marketo in Japanese. To provide these services, they may process some limited personal data (such as name, phone number and email address) and details relating to business activities (e.g., the context of the support issue they are engaging with Adobe on). | Japan | |
| SendGrid, Inc. | SendGrid is used to send transactional emails from Adobe Commerce (such as receipts to customers, login emails, and other administration information) if a customer chooses to use this option. When enabled, SendGrid will process certain details (including email address, IP address, and subject line of emails). | EU; USA | |
| Sinch AB | Adobe uses Sinch to provide SMS, MMS, and RCS capabilities within the product, if Sinch is licensed by customer. Note that Sinch only acts as Adobe’s sub-processor for these messaging services in the U.S. and Canada; for messaging in other countries, customers enter into terms directly with Sinch. | USA | |
| Sisense Ltd. | Sisense provides a data analytics query and visualization software tool with particular plug-ins for Marketo that allow customers to generate specific data visualization analysis. Customers decide on the parameters of the visualization, and in doing so can choose to input user level information such as name, contact details (email, phone number), and engagement data (such as web browsing information such as clicks and open rate). | France; USA | |
| Slack Technologies | Slack assists Adobe with resolving service requests (e.g., customer calls or partner requests on bugs, fixes and other issues). It allows Adobe to track tickets by assigning case numbers to every service inquiry we receive and track the issue to the resolution. It can distribute tickets according to priority and subject matter while giving top-level dashboards and reports on things like overall resolution time and productivity spikes. Adobe customers tend to seek support in a variety of ways (e.g., by phone, email, text, social media messaging or via community platforms). Slack also helps Adobe with omni-channel routing which allows Adobe to filter requests that come in through the different channels and get them to the right customer care support function. To provide these services, Slack may process some limited personal data (such as name, age and date of birth) and details relating to business activities (e.g., the context of the support issue they are helping to route). | EU; USA | |
| Snowflake Computing Inc. | Adobe uses Snowflake for data warehousing and database storage services across a subset of Experience Cloud products. This includes business intelligence on campaign performance, various KPI tracking tools, and sales report features. | EU; USA | |
| Speechmatics | Speechmatics provides automatic speech recognition software to allow for speech to text within Adobe products. To do this, Speechmatics has limited ability to process personal data contained in voice details, names, and personal data. | UK; USA | |
| Splunk, Inc. | Splunk assists with security event logging and monitoring via the collection of system data. Logs are generated through Adobe’s software applications and are analyzed and inspected for bugs or system failures in an Adobe-managed Splunk environment. Splunk may process data about Adobe’s operating environment and configuration. This in turn can include user interactions, and sessions related to Adobe’s use of Splunk in which information and related metadata about Adobe’s network and systems architecture configurations is accessible. From a customer data perspective, Splunk may process the number and types of searches, errors, and number of active and licensed users. Additionally, Splunk offers support services to Adobe for troubleshooting which may involve access to user/customer identifiable information. Finally, there is also a possibility of certain customer data (such as IP addresses, names, contact information,) being processed as part of a security investigation, threat detection, or incident monitoring. | EU; UK; USA | |
| Stream | Adobe uses Stream's enterprise chat offering for facilitating livestreaming chat functions with Behance. Currently, chat functionality is only available while streamers are live and is an optional service customers may choose to deploy. If deployed, Stream will have access to the personal data submitted to the chat and video in question along with names, email addresses, and user account information. | EU; USA | |
| Teleperformance | Teleperformance supports Adobe’s customer care support services by providing technical support functions (including call center functions) and professional services for the Japan, Hong Kong and Taiwan markets (through Teleperformance Japan Co. Ltd and Beijing Interactive CRM Technology Limited). To provide these services, they may process some limited personal data (such as name, age and date of birth) and details relating to business activities (e.g., the context of the support issue they are engaging with Adobe on). Adobe remains in control of all customer data processed by Teleperformance and they are bound to act only within our specific instructions. | China; EU; India; Japan; USA | |
| Telesign Corporation | Telesign provides mobile communication services to Adobe by relaying SMS messages with links to Adobe customers and placing automated phone voice calls that read aloud predefined messages (complementing the SMS messages service). These services are run to support functions in the Adobe Sign and Behance products. In providing these services, Telesign may access first name, last name, address, e-mail address, telephone number, location data, contact information, and device information. | EU; Serbia; UK; USA | |
| Topaz Labs LLC | USA | ||
| Twilio, Inc. | Twilio provides multi-factor authentication services allowing users to receive SMS messages and phone calls to verify their login information. Twilio’s Segment product is used to collect and transform customer data across the Adobe Frame platform. To do this, Twilio may process name, contact details (email and work number), work details (e.g., title) along with technical information such as device data, referring URL, and web browsing information associated with the authentication being verified. | USA | |
| Workfront Inc. | All provide technical and customer support services depending on region of customer. | USA; United Kingdom | |
| Zendesk Inc. | Zendesk supports Adobe’s customer care support services by providing scalable customer service solutions (including messaging, help center coordination, agent workspaces, ticketing integration, issue routing, integrations, and analytics and reporting). To provide these services, they may process some limited personal data (such as name, age and date of birth) and details relating to business activities (e.g., the context of the support issue they are engaging with Adobe on). | EU; USA |
Adobe affiliates (18)
Listed as a subprocessor by (13)
Purposes as each company states them.
1Password 1password.com Communications
Adswerve adswerve.com
Digicert digicert.com Execute contracts; Manage marketing automation, campaigns, and communication preferences; Provide website analytics, personalization, reporting, and website content management
Great Question greatquestion.com Extracts text and content from uploaded PDF files.; PDF content extraction
InEvent inevent.com Data syncronization with Adobe Analytics
Keap keap.com
Nextiva nextiva.com eSignatures
People Data Labs peopledatalabs.com Adobe Software - Marketo
Pluralsight pluralsight.com Website Analytics and Communication Management
Teleport goteleport.com Marketing Automation and Tracking
XING xing.com
Xero xero.com Electronic signing service provider
inFeedo AI infeedo.ai
Security record
What public security catalogs list for Adobe, in their words.
Known exploited vulnerabilities
82 vulnerabilities in Adobe's software that CISA lists as exploited in the wild.
| CVE | Product | Vulnerability | Listed |
|---|---|---|---|
| CVE-2026-71362 | Commerce and Magento | Adobe Commerce and Magento Incorrect Authorization Vulnerability | evidence |
| CVE-2026-75650 | Commerce and Magento | Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability | evidence |
| CVE-2026-48282 | ColdFusion | Adobe ColdFusion Path Traversal Vulnerability | evidence |
| CVE-2009-3459 | Acrobat and Reader | Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability | evidence |
| CVE-2020-9715 | Acrobat | Adobe Acrobat Use-After-Free Vulnerability | evidence |
| CVE-2026-34621 | Acrobat and Reader | Adobe Acrobat and Reader Prototype Pollution Vulnerability | evidence |
| CVE-2025-54236 | Commerce and Magento | Adobe Commerce and Magento Improper Input Validation Vulnerability | evidence |
| CVE-2025-54253 | Experience Manager (AEM) Forms | Adobe Experience Manager Forms Code Execution Vulnerability | evidence |
| CVE-2017-3066 | ColdFusion | Adobe ColdFusion Deserialization Vulnerability | evidence |
| CVE-2024-20767 | ColdFusion | Adobe ColdFusion Improper Access Control Vulnerability | evidence |
72 more
| CVE | Product | Vulnerability | Listed |
|---|---|---|---|
| CVE-2013-0643 | Flash Player | Adobe Flash Player Incorrect Default Permissions Vulnerability | evidence |
| CVE-2013-0648 | Flash Player | Adobe Flash Player Code Execution Vulnerability | evidence |
| CVE-2014-0497 | Flash Player | Adobe Flash Player Integer Underflow Vulnerablity | evidence |
| CVE-2014-0502 | Flash Player | Adobe Flash Player Double Free Vulnerablity | evidence |
| CVE-2024-34102 | Commerce and Magento Open Source | Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability | evidence |
| CVE-2023-29300 | ColdFusion | Adobe ColdFusion Deserialization of Untrusted Data Vulnerability used by ransomware | evidence |
| CVE-2023-38203 | ColdFusion | Adobe ColdFusion Deserialization of Untrusted Data Vulnerability used by ransomware | evidence |
| CVE-2023-21608 | Acrobat and Reader | Adobe Acrobat and Reader Use-After-Free Vulnerability | evidence |
| CVE-2023-26369 | Acrobat and Reader | Adobe Acrobat and Reader Out-of-Bounds Write Vulnerability | evidence |
| CVE-2023-26359 | ColdFusion | Adobe ColdFusion Deserialization of Untrusted Data Vulnerability | evidence |
| CVE-2023-29298 | ColdFusion | Adobe ColdFusion Improper Access Control Vulnerability | evidence |
| CVE-2023-38205 | ColdFusion | Adobe ColdFusion Improper Access Control Vulnerability | evidence |
| CVE-2023-26360 | ColdFusion | Adobe ColdFusion Deserialization of Untrusted Data Vulnerability | evidence |
| CVE-2007-5659 | Acrobat and Reader | Adobe Acrobat and Reader Buffer Overflow Vulnerability | evidence |
| CVE-2008-0655 | Acrobat and Reader | Adobe Acrobat and Reader Unspecified Vulnerability | evidence |
| CVE-2009-1862 | Acrobat and Reader, Flash Player | Adobe Acrobat and Reader, Flash Player Unspecified Vulnerability | evidence |
| CVE-2009-3953 | Acrobat and Reader | Adobe Acrobat and Reader Universal 3D Remote Code Execution Vulnerability | evidence |
| CVE-2009-4324 | Acrobat and Reader | Adobe Acrobat and Reader Use-After-Free Vulnerability | evidence |
| CVE-2010-1297 | Flash Player | Adobe Flash Player Memory Corruption Vulnerability | evidence |
| CVE-2010-2883 | Acrobat and Reader | Adobe Acrobat and Reader Stack-Based Buffer Overflow Vulnerability | evidence |
| CVE-2011-0609 | Flash Player | Adobe Flash Player Unspecified Vulnerability | evidence |
| CVE-2011-2462 | Reader and Acrobat | Adobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability | evidence |
| CVE-2012-0754 | Flash Player | Adobe Flash Player Memory Corruption Vulnerability | evidence |
| CVE-2012-0767 | Flash Player | Adobe Flash Player Cross-Site Scripting (XSS) Vulnerability | evidence |
| CVE-2012-5054 | Flash Player | Adobe Flash Player Integer Overflow Vulnerability | evidence |
| CVE-2018-4990 | Acrobat and Reader | Adobe Acrobat and Reader Double Free Vulnerability | evidence |
| CVE-2014-0546 | Reader and Acrobat | Adobe Reader and Acrobat Sandbox Bypass Vulnerability | evidence |
| CVE-2014-8439 | Flash Player | Adobe Flash Player Dereferenced Pointer Vulnerability | evidence |
| CVE-2015-0310 | Flash Player | Adobe Flash Player ASLR Bypass Vulnerability | evidence |
| CVE-2015-8651 | Flash Player | Adobe Flash Player Integer Overflow Vulnerability | evidence |
| CVE-2016-0984 | Flash Player and AIR | Adobe Flash Player and AIR Use-After-Free Vulnerability | evidence |
| CVE-2016-1010 | Flash Player and AIR | Adobe Flash Player and AIR Integer Overflow Vulnerability | evidence |
| CVE-2018-5002 | Flash Player | Adobe Flash Player Stack-based Buffer Overflow Vulnerability | evidence |
| CVE-2014-9163 | Flash Player | Adobe Flash Player Stack-Based Buffer Overflow Vulnerability | evidence |
| CVE-2015-0311 | Flash Player | Adobe Flash Player Remote Code Execution Vulnerability | evidence |
| CVE-2015-0313 | Flash Player | Adobe Flash Player Use-After-Free Vulnerability | evidence |
| CVE-2015-3113 | Flash Player | Adobe Flash Player Heap-Based Buffer Overflow Vulnerability | evidence |
| CVE-2015-5122 | Flash Player | Adobe Flash Player Use-After-Free Vulnerability | evidence |
| CVE-2015-5123 | Flash Player | Adobe Flash Player Use-After-Free Vulnerability | evidence |
| CVE-2012-2034 | Flash Player | Adobe Flash Player Memory Corruption Vulnerability | evidence |
| CVE-2013-2729 | Reader and Acrobat | Adobe Reader and Acrobat Arbitrary Integer Overflow Vulnerability | evidence |
| CVE-2009-0927 | Reader and Acrobat | Adobe Reader and Adobe Acrobat Stack-Based Buffer Overflow Vulnerability | evidence |
| CVE-2010-2861 | ColdFusion | Adobe ColdFusion Directory Traversal Vulnerability used by ransomware | evidence |
| CVE-2016-4171 | Flash Player | Adobe Flash Player Remote Code Execution Vulnerability | evidence |
| CVE-2016-7892 | Flash Player | Adobe Flash Player Use-After-Free Vulnerability | evidence |
| CVE-2009-3960 | BlazeDS | Adobe BlazeDS Information Disclosure Vulnerability used by ransomware | evidence |
| CVE-2013-0625 | ColdFusion | Adobe ColdFusion Authentication Bypass Vulnerability | evidence |
| CVE-2013-0629 | ColdFusion | Adobe ColdFusion Directory Traversal Vulnerability | evidence |
| CVE-2013-0631 | ColdFusion | Adobe ColdFusion Information Disclosure Vulnerability | evidence |
| CVE-2008-2992 | Acrobat and Reader | Adobe Reader and Acrobat Input Validation Vulnerability used by ransomware | evidence |
| CVE-2010-0188 | Reader and Acrobat | Adobe Reader and Acrobat Arbitrary Code Execution Vulnerability used by ransomware | evidence |
| CVE-2011-0611 | Flash Player | Adobe Flash Player Remote Code Execution Vulnerability | evidence |
| CVE-2012-1535 | Flash Player | Adobe Flash Player Arbitrary Code Execution Vulnerability | evidence |
| CVE-2013-0632 | ColdFusion | Adobe ColdFusion Authentication Bypass Vulnerability | evidence |
| CVE-2013-0640 | Reader and Acrobat | Adobe Reader and Acrobat Memory Corruption Vulnerability | evidence |
| CVE-2013-0641 | Reader | Adobe Reader Buffer Overflow Vulnerability | evidence |
| CVE-2013-3346 | Reader and Acrobat | Adobe Reader and Acrobat Memory Corruption Vulnerability | evidence |
| CVE-2014-0496 | Reader and Acrobat | Adobe Reader and Acrobat Use-After-Free Vulnerability | evidence |
| CVE-2015-3043 | Flash Player | Adobe Flash Player Memory Corruption Vulnerability | evidence |
| CVE-2015-5119 | Flash Player | Adobe Flash Player Use-After-Free Vulnerability | evidence |
| CVE-2015-7645 | Flash Player | Adobe Flash Player Arbitrary Code Execution Vulnerability used by ransomware | evidence |
| CVE-2016-1019 | Flash Player | Adobe Flash Player Arbitrary Code Execution Vulnerability used by ransomware | evidence |
| CVE-2016-4117 | Flash Player | Adobe Flash Player Arbitrary Code Execution Vulnerability used by ransomware | evidence |
| CVE-2016-7855 | Flash Player | Adobe Flash Player Use-After-Free Vulnerability | evidence |
| CVE-2017-11292 | Flash Player | Adobe Flash Player Type Confusion Vulnerability | evidence |
| CVE-2018-15982 | Flash Player | Adobe Flash Player Use-After-Free Vulnerability used by ransomware | evidence |
| CVE-2022-24086 | Commerce and Magento Open Source | Adobe Commerce and Magento Open Source Improper Input Validation Vulnerability | evidence |
| CVE-2018-15961 | ColdFusion | Adobe ColdFusion Unrestricted File Upload Vulnerability | evidence |
| CVE-2018-4878 | Flash Player | Adobe Flash Player Use-After-Free Vulnerability used by ransomware | evidence |
| CVE-2018-4939 | ColdFusion | Adobe ColdFusion Deserialization of Untrusted Data Vulnerability | evidence |
| CVE-2021-21017 | Acrobat and Reader | Adobe Acrobat and Reader Heap-based Buffer Overflow Vulnerability | evidence |
| CVE-2021-28550 | Acrobat and Reader | Adobe Acrobat and Reader Use-After-Free Vulnerability | evidence |
Data breaches
- Adobe 152,445,165 accounts Email addresses; Password hints; Passwords; Usernames
In October 2013, 153 million Adobe accounts were breached with each containing an internal ID, username, email, encrypted password and a password hint in plain text. The password cryptography was poorly done and many were quickly resolved back to plain text. The unencrypted hints also disclosed much about the passwords adding further to the risk that hundreds of millions of Adobe customers already faced.
Have I Been Pwned · evidence
Source: CISA Known Exploited Vulnerabilities catalog. Breach data from Have I Been Pwned (CC BY 4.0), which calls every entry a breach, including data scraped from public pages.
Changes
None since tracking began.