#fff

Priority ratings

The Adobe Priority Rating System helps customers in managed environments prioritize the deployment of Adobe security updates by indicating the urgency with which an update should be applied. Priority rankings are based on historical attack patterns for the relevant product, the type of vulnerability being addressed, the platform(s) affected, and any potential mitigations that may already be in place.

#fafafa

Priority 1

Act as soon as possible (within 72 hours).

This update resolves vulnerabilities in a product being actively exploited or at higher risk of exploitation for the given product and platform.

#fafafa

Priority 2

Act within 30 days.
This update resolves vulnerabilities in a product that has historically been at elevated risk. There are currently no known active exploits, and based on previous experience, we do not anticipate exploits are imminent.

#fafafa

Priority 3

Act at your admin’s discretion.
This update resolves vulnerabilities in a product that has not historically been a common target.

#fff

Severity ratings

As of October 2026, Adobe rates the severity of vulnerabilities using the Common Vulnerability Scoring System version 3.1 (CVSS v3.1). Each vulnerability receives a CVSS score from 0.1 to 10.0, a corresponding rating, and a CVSS vector string. The CVSS scores and ratings are as follows:

#fafafa

Critical

CVSS Score: 9.0 – 10.0

#fafafa

High

CVSS Score: 7.0 – 8.9

#fafafa

Medium

CVSS Score: 4.0 – 6.9

#fafafa

Low

CVSS Score: 0.1 – 3.9

#fff

Legacy severity ratings

The following severity ratings applied to bulletins published before October 2026. Bulletins from October 2026 onward use the CVSS severity ratings above.

#fafafa

Critical

A vulnerability that, if exploited, would allow malicious native code to execute, potentially without a user being aware.

#fafafa

Important

A vulnerability that, if exploited, would compromise data security, potentially allowing access to confidential data or compromising processing resources.

#fafafa

Moderate

A vulnerability that is limited to a significant degree by factors such as default configuration, auditing, or the difficulty of exploitation.