basicsecurity.net
Proof, not just disclosure.
Threats / Contributors / Adobe
Vendor security team contributor

Adobe

cited as evidence in 25 · CNA assigner on 76 of 76 known-exploited records. Every aggregate on this page is recomputed from the records listed below — each one already cited to its public source.

adobe.com ↗ · home of the cited advisories

76
records cited in
deterministic count
0
finder / reporter credits
CVE.org credits
76
CVE records catalogued (CNA)
assigner
62%
avg modeled exploit prob.
FIRST EPSS, 76/76
13%
ransomware-associated
10 of 76 · CISA flag
R

Roles across the work

— find / fix / exploit / catalog, computed per record from credit type, the vendor-self-CNA gate, and the linked public exploit catalog
0
Find
record(s)
76
Fix
record(s)
0
Exploit
record(s)
0
Catalog
record(s)

Each dimension is a count of the listed records where this contributor did that job. A CNA row is fix only when the affected product is the assigner’s own; registries, coordinators, platforms, intel and research houses read as catalog, never fix. Exploit counts records where this contributor is credited as author of a public exploit / detection template in a linked catalog — we link the catalog, never host a payload.

01

Known for

— recomputed from this contributor’s own records
SurfacesApplication / other (76)
WeaknessMemory safety (33), Authorization / access control (11), Injection (8), Resource / availability (3), Path traversal / file (3)
PortfolioAdobe (76)
02

Narrative reach

— how far this contributor’s records carry an attacker, front door → lights out
1Front door
73reach this stage
→
2Keys to the kingdom
73reach this stage
→
3Lateral reach
70reach this stage
→
4Data at risk
6reach this stage
→
5Lights out
1reach this stage

Furthest any of these records carries an attacker: 5 · Lights out. 6 of 73 narrative-framed records reach data-at-risk or lights-out. (furthest-position idiom, reused from the landing map; the stage mapping is a model output over cited evidence.)

03

Recent highlights

— this contributor’s newest known-exploited records
04

Every record they’re cited in

— all 76, each linked to its cited source

This is the evidence behind every number above. Sorted ransomware-first, then by modeled exploit probability.

CVE-2023-29300Adobe100%RWKEVCVE-2010-2861Adobe100%RWKEVCVE-2023-38203Adobe97%RWKEVCVE-2016-4117Adobe94%RWKEVCVE-2009-3960Adobe90%RWKEVCVE-2018-15982Adobe90%RWKEVCVE-2018-4878Adobe90%RWKEVCVE-2010-0188Adobe88%RWKEVCVE-2015-7645Adobe65%RWKEVCVE-2016-1019Adobe22%RWKEVCVE-2024-34102Adobe100%KEVCVE-2018-15961Adobe100%KEVCVE-2015-3113Adobe100%KEVCVE-2014-0497Adobe100%KEVCVE-2023-29298Adobe100%KEVCVE-2023-38205Adobe100%KEVCVE-2011-0611Adobe99%KEVCVE-2015-5119Adobe99%KEVCVE-2022-24086Adobe99%KEVCVE-2024-20767Adobe99%KEVCVE-2023-26360Adobe97%KEVCVE-2015-0313Adobe95%KEVCVE-2025-54236Adobe95%KEVCVE-2015-5122Adobe94%KEVCVE-2013-0625Adobe94%KEVCVE-2013-0632Adobe94%KEVCVE-2012-0754Adobe91%KEVCVE-2017-3066Adobe91%KEVCVE-2011-2462Adobe89%KEVCVE-2025-54253Adobe88%KEVCVE-2013-0640Adobe87%KEVCVE-2009-3459Adobe87%KEVCVE-2021-21017Adobe86%KEVCVE-2015-0311Adobe86%KEVCVE-2009-3953Adobe83%KEVCVE-2010-1297Adobe82%KEVCVE-2009-4324Adobe82%KEVCVE-2010-2883Adobe81%KEVCVE-2013-3346Adobe79%KEVCVE-2015-3043Adobe74%KEVCVE-2015-8651Adobe68%KEVCVE-2013-2729Adobe67%KEVCVE-2013-0631Adobe66%KEVCVE-2013-0629Adobe66%KEVCVE-2011-0609Adobe64%KEVCVE-2018-4939Adobe62%KEVCVE-2023-21608Adobe61%KEVCVE-2016-0984Adobe55%KEVCVE-2021-28550Adobe52%KEVCVE-2020-9715Adobe49%KEVCVE-2026-48282Adobe42%KEVCVE-2014-0496Adobe40%KEVCVE-2018-4990Adobe36%KEVCVE-2013-0641Adobe32%KEVCVE-2016-7855Adobe25%KEVCVE-2018-5002Adobe25%KEVCVE-2014-0502Adobe25%KEVCVE-2014-0546Adobe22%KEVCVE-2012-5054Adobe21%KEVCVE-2014-9163Adobe21%KEVCVE-2014-8439Adobe20%KEVCVE-2016-4171Adobe20%KEVCVE-2016-1010Adobe19%KEVCVE-2015-5123Adobe19%KEVCVE-2016-7892Adobe19%KEVCVE-2023-26359Adobe17%KEVCVE-2015-0310Adobe15%KEVCVE-2017-11292Adobe12%KEVCVE-2013-0648Adobe11%KEVCVE-2013-0643Adobe11%KEVCVE-2012-2034Adobe8%KEVCVE-2023-26369Adobe7%KEVCVE-2012-0767Adobe6%KEVCVE-2026-75650Adobe4%KEVCVE-2026-71362Adobe2%KEVCVE-2026-34621Adobe2%KEV
05

Coverage & confidence

— what this profile claims, and what it does not

Established (cited)

  • Cited in 76 known-exploited records — the list below; every one links to its public source.
  • Catalogued 76 CVE record(s) as the CNA assigner (from CVE.org).
  • Coverage gaps — stated, not hidden

  • This profile is an aggregation: it asserts only what the listed records already cite — no new external claim about the contributor is made.
  • The TYPE badge and the narrative-stage mapping are editorial (our call), labeled as such, not a sourced fact.