Vulnerabilities
6,098 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-81996 | Local Privilege Escalation via Incorrect Authorization in Adobe Acrobat Reader CVE-2026-81996 is an incorrect authorization flaw (CWE-863) in Adobe Acrobat Reader that fails to properly enforce privilege boundaries, allowing a local attacker to escalate privileges. A low-privileged attacker with local access can trigger the flaw without any user interaction, per the CVSS vector (AV:L/AC:L/PR:L/UI:N) and the vendor description. Successful exploitation grants elevated access beyond the attacker's normal privileges, with high impact on confidentiality, integrity, and availability; the changed-scope rating indicates the escalation crosses a security boundary, meaning the attacker gains authority beyond the application's own context. Any user running the affected Acrobat Reader versions is exposed, although the attacker must first be able to execute code locally on the host. No public proof-of-concept, CISA KEV listing, or known in-the-wild exploitation is documented, and EPSS estimates only a 0.1% probability of exploitation in the next 30 days. Do: Patch by upgrading Acrobat Reader to the fixed release identified in Adobe's security bulletin (exact fixed version numbers are not included in this dataset, so verify against the advisory). Until patched, limit untrusted low-privileged users' ability to execute code on sensitive hosts where Acrobat Reader is installed, and monitor for public PoC disclosures. Given no known exploitation, no KEV entry, and very low EPSS (0.1% over 30 days), standard patching cadence is likely sufficient unless local untrusted execution is common in your environment. | 8.8 group max | <1% |
| mass≈ hundreds of millions of desktop installations (Acrobat Reader is the dominant PDF viewer on Windows and macOS) | ||
| CVE-2026-76199 | Search-Path Hijack in Adobe Photoshop Desktop Allows Code Execution via Malicious File CVE-2026-76199 is an uncontrolled search path element flaw (CWE-427) in Adobe Photoshop Desktop, a class of issue similar to DLL search-order hijacking where the application loads code from an attacker-influenced location. To trigger it, a victim must open a malicious file while the vulnerable desktop application is installed, allowing the attacker to have arbitrary code executed in the context of the current user; the 'scope changed' flag indicates the impact can extend beyond the vulnerable component's own security scope, which drives the elevated 8.6 High CVSS score. Successful exploitation gives the attacker code execution with the victim's privileges, enabling follow-on actions such as deploying malware or accessing data available to that user. All users running Adobe Photoshop Desktop are potentially affected, though the provided data does not specify exact version ranges. There is no evidence of active exploitation: EPSS is low (0.2% probability within 30 days), the flaw is not in CISA's KEV catalog, and no public proof-of-concept is known. Do: Update Photoshop Desktop to the fixed release listed in Adobe's security bulletin for this CVE, as the provided data does not include version numbers. Until patching, avoid opening image or project files from untrusted sources, since exploitation requires a victim to open a malicious file. Because exploitation is local and user-triggered, organizations should also review endpoint controls that limit execution of downloaded files in user-writable directories. | 8.6 group max | <1% |
| masstens of millions of desktop installations (Photoshop's Creative Cloud subscriber base) | ||
| CVE-2026-79905 | Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed. NVD description · AI analysis pending | 5.4 | <1% |
| — |