Adobe
Top 100 siteProgram Details
- Handle
- adobe
- Managed
- Yes
- Confidentiality
- public
Scope (41 targets)
web: 17 other: 24 In Scope
- Acrobat PDF Spaces other bounty-eligible
- Acrobat Create Presentations other bounty-eligible
- Acrobat Create Podcast other bounty-eligible
- Acrobat AI Assistant other bounty-eligible
- Adobe Express AI Assistant other bounty-eligible
- Lightroom AI Features other bounty-eligible
- Adobe Firefly AI Features other bounty-eligible
- Photoshop AI Assistant other bounty-eligible
- Adobe Stock AI Studio other bounty-eligible
- Frame.io iOS Application other bounty-eligible
- Adobe Fresco (iOS) other bounty-eligible
- Adobe Photoshop Express Mobile App (iOS) other bounty-eligible
- Lightroom Video & Photo Editor (IOS) other bounty-eligible
- Lightroom Video & Photo Editor (Android) other bounty-eligible
- Adobe Scan Mobile App (iOS) other bounty-eligible
- Adobe Scan Mobile App (Android) other bounty-eligible
- Acrobat Reader Mobile App (iOS) other bounty-eligible
- Acrobat Reader Mobile App (Android) other bounty-eligible
- *.acrobat.adobe.com other bounty-eligible
- stock.adobe.com web bounty-eligible
- and 21 more targets
Known Exploited Vulnerabilities 81CVEs
11 linked to ransomware campaigns
Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code.
Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.
Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption.
Adobe Acrobat contains a use-after-free vulnerability that allows for code execution
Adobe Acrobat and Reader contain a prototype pollution vulnerability that allows for arbitrary code execution.
Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API.
Adobe Experience Manager Forms in JEE contains an unspecified vulnerability that allows for arbitrary code execution.
Adobe ColdFusion contains a deserialization vulnerability in the Apache BlazeDS library that allows for arbitrary code execution.
Adobe ColdFusion contains an improper access control vulnerability that could allow an attacker to access or modify restricted files via an internet-exposed admin panel.
Adobe Flash Player contains a double free vulnerability that allows a remote attacker to execute arbitrary code.
security.txt
- Contact
- https://app.intigriti.com/programs/adobe/adobepublic/detail, [email protected]
- Encryption
- https://helpx.adobe.com/security/key.html
- Policy
- https://helpx.adobe.com/security.html/security/policy.ug.html
- Hiring
- https://www.adobe.com/careers.html
- Acknowledgments
- https://helpx.adobe.com/security.html
- Languages
- en, ro, hi
- Expires
- Jul 30, 2027