Adobe

Adobe

Top 100 site
Bounty RecognitionPartial Safe Harbor USD $75 - $15,000

Program Details

Handle
adobe
Managed
Yes
Confidentiality
public

Scope (39 targets)

web: 17 other: 22

In Scope

  • Acrobat PDF Spaces other bounty-eligible
  • Acrobat Create Presentations other bounty-eligible
  • Acrobat Create Podcast other bounty-eligible
  • Acrobat AI Assistant other bounty-eligible
  • Adobe Express AI Assistant other bounty-eligible
  • Lightroom AI Features other bounty-eligible
  • Adobe Firefly AI Features other bounty-eligible
  • Photoshop AI Assistant other bounty-eligible
  • Adobe Stock AI Studio other bounty-eligible
  • Frame.io iOS Application other bounty-eligible
  • Adobe Fresco (iOS) other bounty-eligible
  • Adobe Photoshop Express Mobile App (iOS) other bounty-eligible
  • Lightroom Video & Photo Editor (IOS) other bounty-eligible
  • Lightroom Video & Photo Editor (Android) other bounty-eligible
  • Adobe Scan Mobile App (iOS) other bounty-eligible
  • Adobe Scan Mobile App (Android) other bounty-eligible
  • Acrobat Reader Mobile App (iOS) other bounty-eligible
  • Acrobat Reader Mobile App (Android) other bounty-eligible
  • *.acrobat.adobe.com other bounty-eligible
  • stock.adobe.com web bounty-eligible
  • and 19 more targets

Out of Scope

Adobe ColdFusion without ColdFusion Administrator, ColdFusion Administrator

Known Exploited Vulnerabilities 81CVEs

11 linked to ransomware campaigns

  • CVE-2026-75650Commerce and MagentoSep 8, 20260.7% EPSS

    Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code.

  • CVE-2026-48282ColdFusionJul 7, 202642.4% EPSS

    Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.

  • CVE-2009-3459Acrobat and ReaderMay 20, 202686.6% EPSS

    Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption.

  • CVE-2020-9715AcrobatApr 13, 202648.4% EPSS

    Adobe Acrobat contains a use-after-free vulnerability that allows for code execution

  • CVE-2026-34621Acrobat and ReaderApr 13, 20267.1% EPSS

    Adobe Acrobat and Reader contain a prototype pollution vulnerability that allows for arbitrary code execution.

  • CVE-2025-54236Commerce and MagentoOct 24, 202594.5% EPSS

    Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API.

  • CVE-2025-54253Experience Manager (AEM) FormsOct 15, 202587.5% EPSS

    Adobe Experience Manager Forms in JEE contains an unspecified vulnerability that allows for arbitrary code execution.

  • CVE-2017-3066ColdFusionFeb 24, 202590.6% EPSS

    Adobe ColdFusion contains a deserialization vulnerability in the Apache BlazeDS library that allows for arbitrary code execution.

  • CVE-2024-20767ColdFusionDec 16, 202498.5% EPSS

    Adobe ColdFusion contains an improper access control vulnerability that could allow an attacker to access or modify restricted files via an internet-exposed admin panel.

  • CVE-2014-0502Flash PlayerSep 17, 202424.2% EPSS

    Adobe Flash Player contains a double free vulnerability that allows a remote attacker to execute arbitrary code.

and 71 more - view full CISA catalog →

security.txt

Contact
https://hackerone.com/adobe, [email protected]
Encryption
https://helpx.adobe.com/security/key.html
Policy
https://helpx.adobe.com/security.html/security/policy.ug.html
Hiring
https://www.adobe.com/careers.html
Acknowledgments
https://helpx.adobe.com/security.html
Languages
en, ro, hi
Expires
Jul 30, 2027
View raw security.txt →