Vulnerabilities · 154 days ago

ColdFusion Flaws Take Priority Over Adobe’s Broad Patch Load

The real risk in Adobe’s Patch Tuesday is not the volume of fixes. It is that five critical ColdFusion flaws sit in the highest-priority bucket because ColdFusion has a long history of being targeted, and the patched issues can bypass security controls, read files, and execute arbitrary code.

Adobe fixed 55 vulnerabilities across 11 products. The critical set spans ColdFusion, Acrobat and Reader, InDesign, InCopy, FrameMaker, Connect, Bridge, Photoshop, and Illustrator, and Adobe also recently patched Acrobat and Reader zero-day CVE-2026-34621 after in-the-wild use; CISA has also warned about attacks on the older CVE-2020-9715.

The forward risk is uneven. Most of the Adobe backlog is lower priority, but unpatched ColdFusion instances remain the clearest intrusion path because the product keeps drawing attacker attention and the flaws affect both security boundaries and code execution.

CVE-2020-9715

NVD KEV

Known exploited · CISA KEV

CVSS 7.8 HIGH: adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an use-after-free vulnerability. EPSS 49% (99th percentile).

CISA federal remediation date Apr 27

CVE-2026-34621

NVD KEV

Known exploited · CISA KEV

CVSS 8.6 HIGH: acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification… EPSS 7% (93rd percentile).

CISA federal remediation date Apr 27

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-04-15

Editions

Related stories