VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
18,947 CVE recordsPage 304 of 1264 · EPSS data 2026.08.02
ReviewHigh
CVE-2026-48370

Adobe Adobe Media Encoder, media encoder

Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-48369

Adobe Premiere, premiere pro

Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-48367

Adobe After Effects, after effects

After Effects is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-48366

Adobe Adobe Media Encoder, media encoder

Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-48344

Adobe Creative Cloud Desktop, creative cloud desktop application, windows

Creative Cloud Desktop is affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-48343

Adobe Adobe Bridge, bridge, macos

Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-48342

Adobe Adobe Bridge, bridge, macos

Bridge is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-48341

Adobe Adobe Bridge, bridge, macos

Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-48340

Adobe Adobe Bridge, bridge, macos

Bridge is affected by an Untrusted Pointer Dereference vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-48339

Adobe Adobe Bridge, bridge, macos

Bridge is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

The CVSS severity warrants an early asset and exposure review.
PriorityHigh
CVE-2026-48332

Adobe ColdFusion 2025, ColdFusion 2023, coldfusion

ColdFusion is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed.

FIRST EPSS indicates an elevated probability of exploitation.
ReviewHigh
CVE-2026-48328

Adobe ColdFusion 2025, ColdFusion 2023, coldfusion

ColdFusion is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-48327

Adobe ColdFusion 2025, ColdFusion 2023, coldfusion

ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-48325

Adobe ColdFusion 2025, ColdFusion 2023, coldfusion

ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-48324

Adobe ColdFusion 2025, ColdFusion 2023, coldfusion

ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

The CVSS severity warrants an early asset and exposure review.