Exploitation timeline
Threadlinqs has recorded 17 Adobe CVEs published between and . The busiest month was 2026-08 (7 new CVEs). 3 of them (18%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.
Most exploited vulnerabilities
Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 17 of 17 tracked Adobe CVEs.
- CVE-2009-3459high 8.8KEVRansomwareEPSS 88.1%
- CVE-2026-48282critical 10KEVEPSS 28.6%
- CVE-2026-34621critical 9.8KEVEPSS 9.8%
- CVE-2026-48318critical 9.9EPSS 6.7%
- CVE-2026-48276critical 10EPSS 0.9%
- CVE-2026-48277critical 10EPSS 0.9%
- CVE-2026-48281critical 10EPSS 0.9%
- CVE-2026-48449critical 10EPSS 0.5%
- CVE-2026-48448high 8.6EPSS 0.4%
- CVE-2026-48323critical 10
- CVE-2026-48330critical 10
- CVE-2026-48331critical 10
- CVE-2026-82004critical 10
- CVE-2026-48326critical 9.9
- CVE-2026-48333critical 9.8
- CVE-2026-48317critical 9.6
- CVE-2026-48399high 7.5
Products affected
Threadlinqs normalises CPE and CNA product records across all 17 CVEs; 10 distinct Adobe products are affected. The most frequently affected:
- Campaign Classic 10 CVEs
- ColdFusion 4 CVEs
- Acrobat 1 CVE
- Acrobat 2020 (Classic) 1 CVE
- Acrobat DC (Continuous) 1 CVE
- Acrobat Reader 1 CVE
- Acrobat Reader 2020 (Classic) 1 CVE
- Acrobat Reader DC (Continuous) 1 CVE
- ColdFusion 2023 1 CVE
- ColdFusion 2025 1 CVE
Threat activity
34 tracked threat campaigns reference Adobe products or exploit Adobe CVEs; the 25 most recent are listed.
- CISA Adds Actively Exploited WSO2 API Manager and Adobe Commerce Flaws to KEV Catalog, Warns on SharePoint Code InjectionCRITICAL
- CISA KEV Additions (2026-09-24): WSO2 JWT Authentication Bypass (CVE-2026-5430, CVSS 10.0) and Adobe Commerce/Magento Incorrect Authorization (CVE-2026-71362, CVSS 9.1) Actively ExploitedCRITICAL
- Autonomous AI Agent Operation (Strix, Cairn, Hermes) Steals 600K+ Payment Cards and Injects Skimmers into 100+ E-Commerce SitesCRITICAL
- Adobe Campaign Classic Critical OS Command Injection (CVE-2026-82004, APSB26-142, CVSS 10.0)CRITICAL
- StyleSmuggler — Magento Open Source and Adobe Commerce Unauthenticated RCE 0-Day Under Active ExploitationCRITICAL
- StyleSmuggler — Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online StoresCRITICAL
- HexMage Magecart Campaign Uses Ethereum Smart Contracts for Resilient Card-Skimmer C2HIGH
- Adobe and Nvidia Patch Dozens of Vulnerabilities Across Multiple Products, Including Two Critical Flaws in Nvidia's NemoClaw AI Agent Stack and a CVSS 10.0 Adobe Campaign Classic ChainCRITICAL
- Adobe Patches Critical RCE Flaws in ColdFusion, Campaign Classic, and Commerce (CVE-2026-48362, CVSS 10.0)CRITICAL
- Fake CCleaner Installer Delivers GhostDesk Chrome Spyware with Keylogging, Credential Theft, and Crypto Clipboard HijackingHIGH
- LogoKit Phishing-as-a-Service Evolves to Real-Time "Environment Impersonation"MEDIUM
- Adobe Campaign Classic Critical Incorrect Authorization Flaw Enables Unauthenticated Remote Code Execution (CVE-2026-48449) Paired With SQL Injection Memory/File Disclosure (CVE-2026-48448)CRITICAL
- German-US-Indonesian Law Enforcement Dismantle Kratos (aka SneakyLog / Sneaky 2FA) Phishing-as-a-Service Kit Targeting Microsoft 365 Sessions and MFAHIGH
- Kratos Phishing-as-a-Service Platform Dismantled in Operation Olympus Blade — BKA/FBI/Indonesian Police Takedown of AiTM Microsoft 365 Credential Theft KitMEDIUM
- CVE-2026-48294 ("HermeticReader"): Adobe Acrobat Chrome Extension Flaw Chain Enables Silent WhatsApp Web Data TheftHIGH
- Infostealer-Enabled ClickFix Campaign Compromises Artlist via EtherHiding C2 and DLL Side-Loaded RATHIGH
- Multi-Vendor Critical Patch Roundup: Firefox 152.0.6, Chrome 150, Adobe ColdFusion/Commerce/AEM (APSB26-68/73/74), and VMware Avi Load Balancer (VMSA-2026-0005)CRITICAL
- Kratos Phishing-as-a-Service Platform Targeting Microsoft 365 Users Across US and EuropeHIGH
- Microsoft July 2026 Patch Tuesday: 570 Flaws Fixed, 3 Zero-Days Including AD FS and SharePoint Privilege EscalationCRITICAL
- Adobe ColdFusion Critical Path Traversal in RDS FILEIO Handler Enables Unauthenticated RCE (CVE-2026-48282)CRITICAL
- Multiple Critical Adobe ColdFusion Vulnerabilities (CVE-2026-48276 et al., APSB26-68) Enable Unauthenticated Remote Code ExecutionCRITICAL
- Adobe ColdFusion & Campaign Classic Priority 1 Patches for 12 Vulnerabilities Including Six Maximum-Severity RCE Flaws (APSB26-68, APSB26-69)CRITICAL
- Adobe Patches Seven Priority-1 ColdFusion and Campaign Classic Flaws (CVE-2026-48276, CVE-2026-48277, CVE-2026-48281, CVE-2026-48282, CVE-2026-48316, CVE-2026-48286)CRITICAL
- Adobe Patches Nine CVSS 10.0/9.3 Flaws in ColdFusion and Campaign Classic Enabling Arbitrary Code Execution (APSB26-68, APSB26-69)CRITICAL
- Cross-Platform Phishing Campaigns Auto-Adapt Payloads to Victim Device/OS via FingerprintingHIGH
Threat actors targeting Adobe
Named threat actors attributed to campaigns that involve Adobe products or CVEs, with the number of linked campaigns:
How to prioritise Adobe patching
This order follows the data Threadlinqs holds for Adobe, not a generic severity checklist:
- 3 of 17 Adobe CVEs (18%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with CVE-2009-3459, CVE-2026-48282, CVE-2026-34621.
- 1 CVE is known to be used in ransomware campaigns; patch these ahead of other KEV entries on internet-facing systems.
- Outside KEV, the highest EPSS scores are CVE-2026-48318 (6.7%), CVE-2026-48276 (0.9%), CVE-2026-48277 (0.9%).
- 14 CVEs score Critical and 3 High on CVSS v3 (maximum 10, average 9.6); sequence these after KEV and high-EPSS items.
- 1 CVE has a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.
About this data
Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.