# Adobe vulnerabilities & exploitation

**CISA KEV** · **Ransomware**

> As of 2026-10-05, Threadlinqs tracks 17 Adobe CVEs, 3 in the CISA Known Exploited Vulnerabilities catalog, 1 used in ransomware campaigns, linked to 34 tracked threat campaigns and 9 named threat actors.

**Data as of:** 2026-10-05

## Exploitation timeline

Threadlinqs has recorded 17 Adobe CVEs published between 2009-10-15 and 2026-09-15. The busiest month was 2026-08 (7 new CVEs). 3 of them (18%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.

## Most exploited vulnerabilities

Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 17 of 17 tracked Adobe CVEs.

- [CVE-2009-3459](https://intel.threadlinqs.com/cve/CVE-2009-3459) — HIGH 8.8 · KEV · Ransomware · EPSS 88.1% · 2009-10-13
- [CVE-2026-48282](https://intel.threadlinqs.com/cve/CVE-2026-48282) — CRITICAL 10 · KEV · EPSS 28.6% · 2026-06-30
- [CVE-2026-34621](https://intel.threadlinqs.com/cve/CVE-2026-34621) — CRITICAL 9.8 · KEV · EPSS 9.8% · 2026-04-13
- [CVE-2026-48318](https://intel.threadlinqs.com/cve/CVE-2026-48318) — CRITICAL 9.9 · EPSS 6.7% · 2026-07-14
- [CVE-2026-48276](https://intel.threadlinqs.com/cve/CVE-2026-48276) — CRITICAL 10 · EPSS 0.9% · 2026-06-30
- [CVE-2026-48277](https://intel.threadlinqs.com/cve/CVE-2026-48277) — CRITICAL 10 · EPSS 0.9% · 2026-06-30
- [CVE-2026-48281](https://intel.threadlinqs.com/cve/CVE-2026-48281) — CRITICAL 10 · EPSS 0.9% · 2026-06-30
- [CVE-2026-48449](https://intel.threadlinqs.com/cve/CVE-2026-48449) — CRITICAL 10 · EPSS 0.5% · 2026-07-30
- [CVE-2026-48448](https://intel.threadlinqs.com/cve/CVE-2026-48448) — HIGH 8.6 · EPSS 0.4% · 2026-07-30
- [CVE-2026-48323](https://intel.threadlinqs.com/cve/CVE-2026-48323) — CRITICAL 10 · 2026-08-03
- [CVE-2026-48330](https://intel.threadlinqs.com/cve/CVE-2026-48330) — CRITICAL 10 · 2026-08-03
- [CVE-2026-48331](https://intel.threadlinqs.com/cve/CVE-2026-48331) — CRITICAL 10 · 2026-08-03
- [CVE-2026-82004](https://intel.threadlinqs.com/cve/CVE-2026-82004) — CRITICAL 10 · 2026-09-08
- [CVE-2026-48326](https://intel.threadlinqs.com/cve/CVE-2026-48326) — CRITICAL 9.9 · 2026-08-03
- [CVE-2026-48333](https://intel.threadlinqs.com/cve/CVE-2026-48333) — CRITICAL 9.8 · 2026-08-03
- [CVE-2026-48317](https://intel.threadlinqs.com/cve/CVE-2026-48317) — CRITICAL 9.6 · 2026-08-03
- [CVE-2026-48399](https://intel.threadlinqs.com/cve/CVE-2026-48399) — HIGH 7.5 · 2026-08-03

## Products affected

Threadlinqs normalises CPE and CNA product records across all 17 CVEs; 10 distinct Adobe products are affected. The most frequently affected:

- Campaign Classic — 10 CVEs
- ColdFusion — 4 CVEs
- Acrobat — 1 CVE
- Acrobat 2020 (Classic) — 1 CVE
- Acrobat DC (Continuous) — 1 CVE
- Acrobat Reader — 1 CVE
- Acrobat Reader 2020 (Classic) — 1 CVE
- Acrobat Reader DC (Continuous) — 1 CVE
- ColdFusion 2023 — 1 CVE
- ColdFusion 2025 — 1 CVE

## Threat activity

34 tracked threat campaigns reference Adobe products or exploit Adobe CVEs; the 25 most recent are listed.

- [CISA Adds Actively Exploited WSO2 API Manager and Adobe Commerce Flaws to KEV Catalog, Warns on SharePoint Code Injection](https://intel.threadlinqs.com/threat/TL-2026-2680) — CRITICAL — 2026-09-25
- [CISA KEV Additions (2026-09-24): WSO2 JWT Authentication Bypass (CVE-2026-5430, CVSS 10.0) and Adobe Commerce/Magento Incorrect Authorization (CVE-2026-71362, CVSS 9.1) Actively Exploited](https://intel.threadlinqs.com/threat/TL-2026-2640) — CRITICAL — 2026-09-24
- [Autonomous AI Agent Operation (Strix, Cairn, Hermes) Steals 600K+ Payment Cards and Injects Skimmers into 100+ E-Commerce Sites](https://intel.threadlinqs.com/threat/TL-2026-2633) — CRITICAL — 2026-09-23
- [Adobe Campaign Classic Critical OS Command Injection (CVE-2026-82004, APSB26-142, CVSS 10.0)](https://intel.threadlinqs.com/threat/TL-2026-2408) — CRITICAL — 2026-09-08
- [StyleSmuggler — Magento Open Source and Adobe Commerce Unauthenticated RCE 0-Day Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2356) — CRITICAL — 2026-09-06
- [StyleSmuggler — Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores](https://intel.threadlinqs.com/threat/TL-2026-2358) — CRITICAL — 2026-09-06
- [HexMage Magecart Campaign Uses Ethereum Smart Contracts for Resilient Card-Skimmer C2](https://intel.threadlinqs.com/threat/TL-2026-2251) — HIGH — 2026-08-31
- [Adobe and Nvidia Patch Dozens of Vulnerabilities Across Multiple Products, Including Two Critical Flaws in Nvidia's NemoClaw AI Agent Stack and a CVSS 10.0 Adobe Campaign Classic Chain](https://intel.threadlinqs.com/threat/TL-2026-2152) — CRITICAL — 2026-08-26
- [Adobe Patches Critical RCE Flaws in ColdFusion, Campaign Classic, and Commerce (CVE-2026-48362, CVSS 10.0)](https://intel.threadlinqs.com/threat/TL-2026-1985) — CRITICAL — 2026-08-11
- [Fake CCleaner Installer Delivers GhostDesk Chrome Spyware with Keylogging, Credential Theft, and Crypto Clipboard Hijacking](https://intel.threadlinqs.com/threat/TL-2026-1990) — HIGH — 2026-08-11
- [LogoKit Phishing-as-a-Service Evolves to Real-Time "Environment Impersonation"](https://intel.threadlinqs.com/threat/TL-2026-1818) — MEDIUM — 2026-08-02
- [Adobe Campaign Classic Critical Incorrect Authorization Flaw Enables Unauthenticated Remote Code Execution (CVE-2026-48449) Paired With SQL Injection Memory/File Disclosure (CVE-2026-48448)](https://intel.threadlinqs.com/threat/TL-2026-1790) — CRITICAL — 2026-07-31
- [German-US-Indonesian Law Enforcement Dismantle Kratos (aka SneakyLog / Sneaky 2FA) Phishing-as-a-Service Kit Targeting Microsoft 365 Sessions and MFA](https://intel.threadlinqs.com/threat/TL-2026-1612) — HIGH — 2026-07-22
- [Kratos Phishing-as-a-Service Platform Dismantled in Operation Olympus Blade — BKA/FBI/Indonesian Police Takedown of AiTM Microsoft 365 Credential Theft Kit](https://intel.threadlinqs.com/threat/TL-2026-1613) — MEDIUM — 2026-07-22
- [CVE-2026-48294 ("HermeticReader"): Adobe Acrobat Chrome Extension Flaw Chain Enables Silent WhatsApp Web Data Theft](https://intel.threadlinqs.com/threat/TL-2026-1637) — HIGH — 2026-07-22
- [Infostealer-Enabled ClickFix Campaign Compromises Artlist via EtherHiding C2 and DLL Side-Loaded RAT](https://intel.threadlinqs.com/threat/TL-2026-1552) — HIGH — 2026-07-19
- [Multi-Vendor Critical Patch Roundup: Firefox 152.0.6, Chrome 150, Adobe ColdFusion/Commerce/AEM (APSB26-68/73/74), and VMware Avi Load Balancer (VMSA-2026-0005)](https://intel.threadlinqs.com/threat/TL-2026-1403) — CRITICAL — 2026-07-16
- [Kratos Phishing-as-a-Service Platform Targeting Microsoft 365 Users Across US and Europe](https://intel.threadlinqs.com/threat/TL-2026-1408) — HIGH — 2026-07-16
- [Microsoft July 2026 Patch Tuesday: 570 Flaws Fixed, 3 Zero-Days Including AD FS and SharePoint Privilege Escalation](https://intel.threadlinqs.com/threat/TL-2026-1324) — CRITICAL — 2026-07-14
- [Adobe ColdFusion Critical Path Traversal in RDS FILEIO Handler Enables Unauthenticated RCE (CVE-2026-48282)](https://intel.threadlinqs.com/threat/TL-2026-1145) — CRITICAL — 2026-07-09
- [Multiple Critical Adobe ColdFusion Vulnerabilities (CVE-2026-48276 et al., APSB26-68) Enable Unauthenticated Remote Code Execution](https://intel.threadlinqs.com/threat/TL-2026-1057) — CRITICAL — 2026-07-02
- [Adobe ColdFusion & Campaign Classic Priority 1 Patches for 12 Vulnerabilities Including Six Maximum-Severity RCE Flaws (APSB26-68, APSB26-69)](https://intel.threadlinqs.com/threat/TL-2026-1091) — CRITICAL — 2026-07-02
- [Adobe Patches Seven Priority-1 ColdFusion and Campaign Classic Flaws (CVE-2026-48276, CVE-2026-48277, CVE-2026-48281, CVE-2026-48282, CVE-2026-48316, CVE-2026-48286)](https://intel.threadlinqs.com/threat/TL-2026-1034) — CRITICAL — 2026-07-01
- [Adobe Patches Nine CVSS 10.0/9.3 Flaws in ColdFusion and Campaign Classic Enabling Arbitrary Code Execution (APSB26-68, APSB26-69)](https://intel.threadlinqs.com/threat/TL-2026-1048) — CRITICAL — 2026-07-01
- [Cross-Platform Phishing Campaigns Auto-Adapt Payloads to Victim Device/OS via Fingerprinting](https://intel.threadlinqs.com/threat/TL-2026-1126) — HIGH — 2026-07-01

## Threat actors targeting Adobe

Named threat actors attributed to campaigns that involve Adobe products or CVEs, with the number of linked campaigns:

- [Magecart](https://intel.threadlinqs.com/actor/Magecart) — 2 campaigns
- [APT29](https://intel.threadlinqs.com/actor/APT29) — 1 campaign
- [EvilTokens PhaaS Operators](https://intel.threadlinqs.com/actor/EvilTokens%20PhaaS%20Operators) — 1 campaign
- [Midnight Blizzard](https://intel.threadlinqs.com/actor/Midnight%20Blizzard) — 1 campaign
- [Storm-2372](https://intel.threadlinqs.com/actor/Storm-2372) — 1 campaign
- [UNC2452](https://intel.threadlinqs.com/actor/UNC2452) — 1 campaign
- [UNK_AcademicFlare](https://intel.threadlinqs.com/actor/UNK_AcademicFlare) — 1 campaign
- [UTA0304](https://intel.threadlinqs.com/actor/UTA0304) — 1 campaign
- [UTA0307](https://intel.threadlinqs.com/actor/UTA0307) — 1 campaign

## How to prioritise Adobe patching

This order follows the data Threadlinqs holds for Adobe, not a generic severity checklist:

- 3 of 17 Adobe CVEs (18%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with [CVE-2009-3459](https://intel.threadlinqs.com/cve/CVE-2009-3459), [CVE-2026-48282](https://intel.threadlinqs.com/cve/CVE-2026-48282), [CVE-2026-34621](https://intel.threadlinqs.com/cve/CVE-2026-34621).
- 1 CVE is known to be used in ransomware campaigns; patch these ahead of other KEV entries on internet-facing systems.
- Outside KEV, the highest EPSS scores are [CVE-2026-48318](https://intel.threadlinqs.com/cve/CVE-2026-48318) (6.7%), [CVE-2026-48276](https://intel.threadlinqs.com/cve/CVE-2026-48276) (0.9%), [CVE-2026-48277](https://intel.threadlinqs.com/cve/CVE-2026-48277) (0.9%).
- 14 CVEs score Critical and 3 High on CVSS v3 (maximum 10, average 9.6); sequence these after KEV and high-EPSS items.
- 1 CVE has a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.

## About this data

Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.

Canonical: https://intel.threadlinqs.com/vendors/adobe
All vendors: https://intel.threadlinqs.com/vendors
Full detection coverage and IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
