Adobe recognizes that the global security research community plays a vital role in protecting our customers and maintaining trust in our brand. Our bug bounty program engages researchers worldwide to identify and report vulnerabilities. If you have discovered a security vulnerability in an Adobe product or service, we encourage you to report it as soon as possible.
Adobe offers monetary rewards for valid security vulnerabilities reported through our public bug bounty program. The reward amounts are determined based on the severity, impact, and exploitability of the reported issue, with higher payouts for vulnerabilities that have the greatest security impact.
To learn more about our reward structure and eligible vulnerabilities, visit our program page.
Note: the graph below outlines the payout ranges across both tier 1 and 2 products by severity level.
Security Researcher Hall of Fame
In addition to monetary rewards, we honor top contributors in our Security Researcher Hall of Fame, which celebrates those who have made exceptional contributions to enhancing the security of Adobe’s products and services.
tab
bugbounty, 1
style
m spacing
Program scope
We welcome reports of security vulnerabilities that may affect the security or privacy of Adobe customers. To be eligible for a bounty, you must report security vulnerabilities in one or more of the following Adobe products and services, including but not limited to:
For a full list of in-scope assets and specific guidelines, visit our program page. Additionally, our program scope provides a detailed list of in-scope and out-of-scope vulnerabilities.
tab
bugbounty, 2
style
m spacing
Reporting a vulnerability
All reports are reviewed and validated by HackerOne and Adobe’s product security teams. To help expedite our investigation and to speed payouts, please follow these guidelines:
Provide clear, reproducible steps when submitting a vulnerability report, including the following details:
Step-by-step instructions: Outline each step needed to reproduce the issue, from login (if applicable) to triggering the vulnerability.
Specific URLs & endpoints: Provide exact affected locations where the issue occurs, including API endpoints.
Expected vs. actual behavior: Clearly describe what should happen versus what actually happens due to the vulnerability.
Payloads & code snippets: If injecting input (e.g., XSS, SQLi), include the exact payload used.
Browser/environment details: Specify the OS, browser version, or tools used to reproduce the issue.
Required pre-conditions: Note any necessary account permissions, configurations, or settings needed to trigger the vulnerability.
Include a proof-of-concept (PoC) — preferably a video — with a dedicated “impact” section to help significantly speed up the review and validation process.
Consolidate all affected hosts into a single report when the same vulnerability impacts multiple hosts within the same asset or domain. Bounties are awarded per unique vulnerability, not per affected host. If duplicate reports are submitted, only the first valid submission will be considered, while later reports will be marked as duplicates.
Use PGP encryption for sensitive submissions.
Please review our terms and conditions on our program page.
For a full list of reporting requirements, please review the Rules of Engagement on the program page.
tab
bugbounty, 3
style
m spacing
Security Researcher Hall of Fame
Earn Hall of Fame points to climb the ranks and earn special recognition for your contributions.
What is the Security Researcher Hall of Fame? The Security Researcher Hall of Fame initiative provides an opportunity to recognize and celebrate the most impactful security researchers who have demonstrated tremendous dedication to their craft and helped strengthen protections for our products, services, and customers.
We welcome all security researchers, from hobbyists to full-time ethical hackers, to participate in the Security Researcher Hall of Fame by submitting a report to the Adobe Bug Bounty Program.
How do I earn points? Researcher points will be awarded for each valid submission to the Adobe Bug Bounty Program. Researcher points will accumulate for a final score calculated at the end of each testing period. To help ensure equal opportunity for all, researcher points will reset at the beginning of each testing period.
What is the scoring process? Any valid and unique submission reported to the Adobe Bug Bounty Program will be awarded Hall of Fame points based on the table below. Adobe's standard policy scope and exclusions apply.
What is the testing period? Each testing period lasts one year, starting every September and ending the next September. Announcements for Adobe's Top 10 researchers occur every October.
What are the rewards? At the end of each testing period, total researcher points will be tallied for all participating researchers and the top ten point earners will be announced. In addition to being commemorated in the Hall of Fame initiative, each top ten researcher will be eligible to choose one of the following rewards:
Note: The Hall of Fame recognizes winners for the testing period from September 1, 2024, through September 1, 2025.
tab
bugbounty, 4
style
m spacing
Email Submissions
To submit a vulnerability report via email: Please send your report to psirt@adobe.com, using the PGP key below to encrypt your message. This email should only be utilized to report security vulnerabilities in Adobe products.
You can control how Adobe websites use cookies and similar technologies by making choices below. But note that if you disable cookies and similar technologies entirely, Adobe websites may not function properly.
Cookies are small text files stored by your web browser when you use websites. There are also other technologies that can be used for similar purposes like HTML5 Local Storage and local shared objects, web beacons, and embedded scripts. These technologies help us do things like remembering you and your preferences when you return to our sites, measure how you use the website, conduct market research, and gather information about the ads you see and interact with.
You can make choices in the menu below about what cookies and other technologies you want us to use on Adobe sites when you visit them from this browser. You can always change those choices later by clicking on the Cookie Preferences link at the bottom of the page.
If enabled:
We can improve your experience by tailoring the site and the content to things we think might be of interest
We can better keep track of your preferences — like what language you prefer to use
We will better understand your likely interests so we can provide you more relevant Adobe ads and content on non-Adobe websites and in non-Adobe apps
It will help us improve the performance of our website and those of our partners who use the Adobe Experience Cloud
If disabled:
We won’t be able to remember you from session to session so the experience may not be tailored to your interests
You’ll still have access to the content of the site but certain features that depend on cookies may not function
You’ll still see ads, they just may not be as relevant to you
General information
You can control how Adobe websites use cookies and similar technologies by making choices below. But note that if you disable cookies and similar technologies entirely, Adobe websites may not function properly.
Cookies are small text files stored by your web browser when you use websites. There are also other technologies that can be used for similar purposes like HTML5 Local Storage, web beacons, and embedded scripts. These technologies help us do things like remembering you and your preferences when you return to our sites, measure how you use the website, conduct market research, and gather information about the ads you see and interact with.
You can make choices in the menu below about what cookies and other technologies you want us to use on Adobe sites when you visit them from this browser. You can always change those choices later by clicking on the Cookie Preferences link at the bottom of the page.
If enabled:
We can improve your experience by tailoring the site and the content to things we think might be of interest
We can better keep track of your preferences — like what language you prefer to use
We will better understand your likely interests so we can provide you more relevant Adobe ads and content on non-Adobe websites and in non-Adobe apps
It will help us improve the performance of our website and those of our partners who use the Adobe Experience Cloud
If disabled:
We won’t be able to remember you from session to session so the experience may not be tailored to your interests
We’ll still count your use of our site and services
You’ll still have access to the content of the site but certain features that depend on cookies may not function
You’ll still see ads, they just may not be as relevant to you
Operate the site and core servicesOperate site and measure engagement
Always active
These cookies are required, and they are used to enable the site and related services core functionality. Without them the site could not operate, so they cannot be disabled.
These cookies enable the site and related services’ core functionality and collect statistics about user engagement, such as counting active use to help us understand trends. These cookies cannot be disabled.
Measure performance
These cookies are used to analyze site usage to measure and improve performance. Without them Adobe cannot know what content is most valued and how often unique visitors return to the site, making it hard to improve information we offer to you.
These cookies are used to analyze site usage to measure and improve performance. Without them Adobe cannot know what content is most valued, making it hard to improve information we offer to you.
Extend functionality
These cookies are used to enhance the functionality of Adobe sites such as remembering your settings and preferences to deliver a personalized experience; for example, your username, your repeated visits, preferred language, your country, or any other saved preference.
Personalize advertising
These cookies are used to enable Adobe and our partners to serve ads more relevant to your interests. Without them you will still see ads, but they might not be as relevant to you.