.

Adobe Security Bulletins and Advisories

This page contains important information regarding security vulnerabilities that could affect specific versions of Adobe products. Use this information to take the prescribed corrective actions.

Report a vulnerability Subscribe to security bulletins

Last Updated: September 22, 2026

Stay up to date by subscribing to receive notifications.

Looking for older bulletins? Adobe security bulletins and advisories published before January 2026 are available on HelpX.

Priority ratings

The Adobe Priority Rating System helps customers in managed environments prioritize the deployment of Adobe security updates based on Adobe's assessment of exploitability. Each priority rating signals how likely a vulnerability is to be exploited and how quickly customers should apply the update, taking into account historical attack patterns for the relevant product, the nature of the vulnerability, the platform(s) affected, and any mitigations already in place.

Priority 1

Act as soon as possible.

This update resolves vulnerabilities that are being actively exploited or are at higher risk of exploitation for the given product and platform.

Priority 2

Act within 30 days.

This update addresses vulnerabilities with a high likelihood of exploitation based on the nature of the vulnerability, the product's history, and the platform affected. There are currently no known active exploits.

Priority 3

Act at your admin’s discretion.

This update addresses vulnerabilities where active exploitation is unlikely based on the product’s history and nature of the vulnerability. There are currently no known active exploits.

Severity ratings

Adobe rates the severity of CVE's using the Common Vulnerability Scoring System version 3.1 (CVSS v3.1). Each CVE is assigned a CVSS score from 0.1 to 10.0, a corresponding severity rating, and a CVSS vector string. The CVSS scores and ratings are as follows:

Critical

CVSS Score: 9.0 – 10.0

High

CVSS Score: 7.0 – 8.9

Medium

CVSS Score: 4.0 – 6.9

Low

CVSS Score: 0.1 – 3.9

Legacy severity ratings

The following severity ratings applied to bulletins published before October 2026. Bulletins from October 2026 onward use the CVSS severity ratings above.

Critical

A vulnerability, which, if exploited would allow malicious native-code to execute, potentially without a user being aware.

Important

A vulnerability, which, if exploited would compromise data security, potentially allowing access to confidential data, or could compromise processing resources.

Moderate

A vulnerability that is limited to a significant degree by factors such as default configuration, auditing, or is difficult to exploit.

Need help with the Trust Center? Email fse@adobe.com.