SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Vendor Security Posture Report Card: Adobe - Q2 2026

Vendor Security Posture Report Card: Adobe - Q2 2026

Explore Adobe's security posture in Q2 2026, including disclosed vulnerabilities, critical security risks, patch management, exploitation trends, and key recommendations for enterprise security teams.

Oct 9, 2026By Aditya Jha8 min read

Vendor Security Posture Report Card: Adobe - Q2 2026

Reporting period: Q2 2026 (April 1 to June 30, 2026), covering Acrobat and Reader, the Creative Cloud applications, Experience Manager, ColdFusion, Commerce, Connect, and Campaign Classic.

Vendor Summary

FieldNotes
Vendor NameAdobe
Product Lines CoveredAcrobat and Reader, Creative Cloud applications (such as Photoshop, Illustrator, InDesign, and Premiere Pro), Experience Manager, ColdFusion, Commerce, Connect, and Campaign Classic
Reporting PeriodQ2 2026 (April 1 to June 30, 2026)
Overall Posture RatingConcerning
Prior Period RatingUnavailable (first report card for this vendor)
Total CVEs Disclosed (Period)237 unique CVEs across 34 security bulletins (61 in April, 52 in May, 124 in June), including the June 30 Campaign Classic bulletin APSB26-69
Critical and High Severity CountUnavailable at CVE level for the full quarter. In the previously counted June releases, 47 of 123 CVEs were Adobe-rated Critical; the June 30 Campaign Classic bulletin adds one further Critical CVE (CVE-2026-48286). In April and May, 19 of 22 bulletins carried Critical as their highest severity.
CVEs With Confirmed In-the-Wild Exploitation1 CVE published in the period is listed in the KEV catalog (CVE-2026-34621, Acrobat and Reader); at least 2 Adobe CVEs were added to the catalog during the quarter

Rating Scale Reference

The rating scale applied consistently across every report card in this series, so that ratings remain comparable from one vendor and one period to the next:

RatingCriteria
StrongDisclosure volume and severity trend stable or improving, advisories timely and complete, no unpatched critical exposure at time of writing.
AdequatePosture broadly sound with isolated gaps, such as a delayed patch cycle or an incomplete advisory, that do not indicate a systemic pattern.
Needs ImprovementRecurring gaps across the period: repeated delayed patches, incomplete disclosures, or a rising severity trend.
ConcerningEvidence of a systemic issue: sustained critical exposure, exploitation preceding a patch, or a pattern of incomplete or delayed disclosure.

This section is included in full on every post, unchanged, so the scale is never assumed to be self-evident.

Introduction

This report card assesses Adobe's security posture for the second quarter of 2026 across its document, creative, and enterprise product lines. Adobe receives an overall rating of Concerning. The decisive factor is the confirmed exploitation of the Acrobat and Reader zero-day CVE-2026-34621 before a fix was available, despite a steady release schedule and detailed bulletins.

Scope and Methodology

This assessment covers the monthly security bulletins Adobe published on its regular release days of April 14, May 12, and June 9, 2026, plus the out-of-cycle Acrobat and Reader bulletin published April 11 and updated April 12 (APSB26-43), and the June 30 Campaign Classic bulletin APSB26-69. It also draws on KEV catalog listings dated between April 1 and June 30, 2026.

  • Included: all CVEs listed in those bulletins, which span Acrobat and Reader, Photoshop, Illustrator, InDesign, InCopy, Premiere Pro, After Effects, Media Encoder, Bridge, the Substance 3D applications, FrameMaker, Experience Manager and Experience Manager Forms, ColdFusion, Commerce, Connect, Campaign Classic, Dreamweaver, and several SDKs.
  • Excluded: any other out-of-cycle releases not reviewed here, and third-party components bundled in Adobe products. The CVE and bulletin totals cover only the stated release inventory.
  • Data sources: Adobe's published security bulletins, CVE and NVD records, and KEV catalog listings.

Data limitations. Adobe publishes CVSS scores and severity labels for individual CVEs, but a full CVE-level CVSS severity tally was not compiled for April and May. Bulletin-level highest-severity ratings for those months are not equivalent to CVE-level counts. The required complete CVSS Critical, High, Medium, and Low distribution is therefore unavailable for this cohort. Counts are unique CVEs per release as tallied from the bulletins and can shift slightly when bulletins are revised. The KEV figures were compiled from catalog notices for the period and should be read as a minimum. The comparison to the prior period uses the same counting convention.

Vulnerability Disclosure Volume and Trend

The reviewed Adobe bulletins disclosed 237 unique CVEs across 34 bulletins in Q2:

  • April: 61 CVEs across 12 bulletins, including the out-of-cycle Acrobat and Reader fix.
  • May: 52 CVEs across 10 bulletins.
  • June: 124 CVEs across 12 bulletins, including the June 30 Campaign Classic bulletin APSB26-69 (CVE-2026-48286); more than twice May's total and the largest month of the first half of 2026.

For the prior period, Q1 2026 added up to 149 CVEs across 28 bulletins (25 in January, 44 in February, and 80 in March). Q2 disclosure volume is therefore up by 88 CVEs, roughly 59 percent. June alone accounts for about 52 percent of the quarter's total. The June spike was driven largely by Experience Manager, which accounted for 57 CVEs, most of them cross-site scripting issues. The source material does not otherwise explain the increase.

Severity Distribution Analysis

Adobe's bulletins carry a CVSS score and a vendor severity label for each CVE. A complete CVSS-based Critical, High, Medium, and Low breakdown was not compiled for this quarter; using the highest rating per bulletin for April and May would not be comparable with CVE-level June counts. The following are limited vendor-rating and individual CVSS observations, not a quarter-wide CVSS distribution:

  • April: 10 of 12 bulletins rated Critical as their highest severity and 2 rated Important. The exploited Acrobat and Reader flaw scored CVSS 8.6 (High by CVSS band), despite its Adobe Critical rating.
  • May: 9 of 10 bulletins rated Critical and 1 Important. The highest scores were in Connect, with two CVEs at CVSS 9.6, and Commerce, whose 15 CVEs reached 8.7.
  • June: 47 of the 123 CVEs in the previously counted June bulletins were Adobe-rated Critical; the June 30 bulletin adds one Adobe-rated Critical CVE, CVE-2026-48286 (CVSS 10.0). The other two Campaign Classic flaws cited here, CVE-2026-48303 and CVE-2026-47938, also carried CVSS 10.0, and Acrobat and Reader accounted for 15 Adobe-rated Critical remote code execution CVEs.

Critical-rated code execution flaws in desktop applications such as Acrobat and the Creative Cloud tools make up much of the Critical total, while the large Experience Manager and Commerce batches skew toward cross-site scripting and authorization bugs. These Adobe ratings must not be treated as CVSS Critical counts. A comparison with Q1's severity distribution was not compiled, so whether the period is weighted more heavily toward high severity than the prior one cannot be determined from vendor data alone.

Patch and Remediation Timeliness

Adobe's release rhythm held throughout the quarter. Regular bulletins arrived on the second Tuesday of each month, April 14, May 12, and June 9, and Adobe disclosed vulnerabilities together with their fixes.

  • Cadence: Adobe follows a monthly Patch Tuesday schedule, and all three regular releases met it.
  • Time to patch: because bulletins ship with fixes and a priority rating from 1 to 3, patches were available when the bulletins were published, but comparable discovery-to-patch intervals for the period's CVEs are unavailable.
  • Out-of-cycle response: Adobe issued an emergency Acrobat and Reader update within days of technical details of the exploited flaw becoming public, rather than waiting for the April 14 release.
  • Lag cases: the exploited Acrobat flaw was reportedly used in attacks from as early as December 2025, roughly four months before the fix. This is the only case in which a fix significantly trailed real-world activity.
  • Priority 1 items: ColdFusion carried Adobe's highest deployment priority in both April and June, with no known exploitation at release.

Exploitation and Real-World Impact

One CVE published in Q2, CVE-2026-34621 in Acrobat and Reader, is listed in the KEV catalog. It is a prototype pollution flaw that allows arbitrary code execution when a user opens a malicious PDF. It was added to the catalog on April 13 with a remediation deadline of April 27. A second Adobe entry added the same day, CVE-2020-9715, is an older Acrobat use-after-free flaw, which brings the total to at least two Adobe CVEs added during the quarter.

Among 237 advisory-listed CVEs, one has confirmed exploitation in this assessment (about 0.42 percent); this is an observed proportion, not an estimate of actual exploitation prevalence. Q1 had none flagged as exploited at release across 149 CVEs, so the rate rose from zero, though a single event is a small sample. The confirmed case involved the widely deployed Acrobat and Reader product line; undetected exploitation and later catalog additions could change the observed proportion.

Advisory and Communication Quality

Adobe's bulletins are consistently structured. Each lists affected versions and platforms, updated versions, a priority rating, the CVE-ID, CWE, impact, a severity label, a CVSS score and vector, and acknowledgments, and each states whether Adobe is aware of exploitation. The quarter showed Adobe correcting and clarifying its records in the open:

  • For the exploited Acrobat flaw, Adobe published a bulletin that states plainly that it is aware of exploitation in the wild.
  • On April 12 Adobe revised that advisory to change the CVSS attack vector from network to local, which is a visible and dated correction.
  • For every other bulletin in the period, Adobe stated that it was not aware of exploits in the wild at release.

The main weakness is volume rather than clarity. A 124-CVE month spread across 12 bulletins, with a single product accounting for nearly half, places a heavy triage load on administrators.

Notable Incidents This Period

The exploited Acrobat and Reader zero-day, CVE-2026-34621, shaped this period's rating. It was reportedly exploited for months before a fix, was fixed out of cycle after public disclosure of details, and was added to the KEV catalog two days later. A full technical analysis belongs in a dedicated post.

Historical Trend Comparison

Unavailable, as this is the first report card for Adobe. The Q1 2026 figures in the volume and exploitation sections serve as the baseline for the next edition.

Risk Context for Organizations

For organizations that rely on Adobe products, the Concerning rating warrants accelerated prioritization of exploited vulnerabilities alongside the normal monthly patch rhythm, with closer monitoring of the PDF and web-platform lines. Acrobat and Reader remain the product line most likely to be targeted, and the April event shows that exploitation can precede a fix by months, so out-of-cycle Adobe updates for Acrobat deserve faster handling than the regular monthly cycle.

Organizations running Experience Manager, Commerce, or ColdFusion face a different pattern: large, frequent batches that are dominated by web-application flaws and carry little exploitation at release, but concentrate in internet-facing systems. Adobe has also moved to releasing patches on the second and fourth Tuesdays of the month from July, which will change how monthly counts compare in future report cards.

Overall Posture Rating and Rationale

Adobe's Q2 2026 rating is Concerning. Three factors most influenced it:

  • Reliable cadence and fixes at disclosure: all three monthly releases landed on schedule, and an emergency update followed the exploited Acrobat flaw within days of public details (see Patch and Remediation Timeliness).
  • One exploited zero-day: CVE-2026-34621 was reportedly exploited for months before a fix, which is the main gap in the period (see Exploitation and Real-World Impact).
  • Rising volume: disclosures rose about 59 percent over Q1, with June at 124 CVEs, although the severity trend could not be shown to be worsening (see Vulnerability Disclosure Volume and Trend).

Although Adobe maintained its scheduled patch cadence and detailed bulletins, the confirmed Acrobat exploitation before patch availability directly meets the template's Concerning criterion. Those operational strengths do not negate that criterion.

Key Takeaways

  • The reviewed Adobe bulletins disclosed 237 unique CVEs across 34 bulletins in Q2 2026, up about 59 percent from Q1, and the overall rating is Concerning.
  • June's 124 CVEs were the largest month of the first half of the year, with Experience Manager accounting for 57 of them.
  • One Acrobat and Reader flaw was exploited before a fix, reportedly since December 2025, and was patched out of cycle in April.
  • Adobe met its Patch Tuesday schedule in April, May, and June and stated its exploitation status in every bulletin.
  • Three Campaign Classic flaws cited in June, including CVE-2026-48286 in the June 30 bulletin, reached CVSS 10.0; Adobe reported no known exploitation for APSB26-69 at publication.

Conclusion

Adobe's Concerning second-quarter rating reflects exploitation before patch availability, despite a dependable release schedule and clear bulletins, alongside one serious exploited flaw and a growing volume of fixes, particularly in its web platforms. These findings feed the ongoing vendor and compliance monitoring work behind this series. The Q3 2026 report card for Adobe is expected after the third-quarter reporting window closes.

Instantly Fix Risks with Saner Patch Management

Saner patch management is a continuous, automated, and integrated software that instantly fixes risks exploited in the wild. The software supports major operating systems like Windows, Linux, and macOS, as well as 550+ third-party applications.

It also allows you to set up a safe testing area to test patches before deploying them in a primary production environment. Saner patch management additionally supports a patch rollback feature in case of patch failure or a system malfunction.

Experience the fastest and most accurate patching software here.

Featured Posts

Open Vendor Security Posture Report Card: Oracle - Q2 2026
Vendor Security Posture Report Card: Oracle - Q2 2026

CVE Research

Vendor Security Posture Report Card: Oracle - Q2 2026

Explore Oracle's Q2 2026 security posture, including disclosed vulnerabilities, critical CVEs, security updates, patch management trends, exploitation risks, and key recommendations for enterprise security teams.

Oct 9, 2026

Open Vendor Security Posture Report Card: Cisco - Q2 2026
Vendor Security Posture Report Card: Cisco - Q2 2026

CVE Research

Vendor Security Posture Report Card: Cisco - Q2 2026

Explore Cisco's security posture in Q2 2026, covering disclosed vulnerabilities, critical security risks, patch management, exploitation trends, and key recommendations for enterprise security teams.

Oct 9, 2026

Open Critical Atlassian Flaw Exploited Within Hours of Disclosure, Affects Multiple Products
vulnerability researchCritical Atlassian Flaw Exploited Within Hours of Disclosure, Affects Multiple Products

CVE Research

Critical Atlassian Flaw Exploited Within Hours of Disclosure, Affects Multiple Products

Atlassian has disclosed CVE-2026-21589, a critical unauthenticated arbitrary file access flaw affecting Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible, and Fisheye Data Center products. Attackers need the exact file path; directory listing is not possible. Cloud is already patched. This article covers impact, fixed versions, and temporary mitigations.

Oct 8, 2026

Open Critical SonicWall SMA 1000 Flaw Lets Unauthenticated Attackers Reach Internal Functionality
vulnerability researchCritical SonicWall SMA 1000 Flaw Lets Unauthenticated Attackers Reach Internal Functionality

CVE Research

Critical SonicWall SMA 1000 Flaw Lets Unauthenticated Attackers Reach Internal Functionality

SonicWall has disclosed CVE-2026-102255, a critical pre-authentication SSRF vulnerability in SMA 1000 Work Place that can let unauthenticated attackers reach internal functionality and perform unauthorized operations. The advisory also covers three additional SMA 1000 issues. Fixed platform-hotfixes are available; SonicWall reports no evidence of in-the-wild exploitation at publication.

Oct 8, 2026