Skip to content

Every change, newest first

What a record said when it was published, what it says now, and the commit that changed it.

276 changes · newest first · grouped by dayCSVJSONRSS

SinceClear the filter
ChangedSourceRows
Counted changes from adobe, newest first, one line per change to a CVE record, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.KindRecord, Which record was edited, by its CVE id, or how many records one collapsed line stands on.Vendor · product, The vendor and product a CVE record names, with the organisation that publishes the record under them; or the package an advisory names and its registry.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Wed 26 Aug 2026· 12 record changes
2026-08-26Product addedCVE-2026-47959not named as affected at publication, now names acrobat 2024Days to revision 78
2026-08-26Product addedCVE-2026-47959not named as affected at publication, now names acrobat dcDays to revision 78
2026-08-26Product addedCVE-2026-47961not named as affected at publication, now names acrobat 2024Days to revision 78
2026-08-26Product addedCVE-2026-47961not named as affected at publication, now names acrobat dcDays to revision 78
2026-08-26Product addedCVE-2026-47963not named as affected at publication, now names adobe dng software development kit (sdk)Days to revision 71
2026-08-26Product addedCVE-2026-47964not named as affected at publication, now names adobe dng software development kit (sdk)Days to revision 71
2026-08-26Product addedCVE-2026-47965not named as affected at publication, now names acrobat 2024Days to revision 75
2026-08-26Product addedCVE-2026-47965not named as affected at publication, now names acrobat dcDays to revision 75
2026-08-26Product addedCVE-2026-48267not named as affected at publication, now names adobe dng software development kit (sdk)Days to revision 51
2026-08-26Product addedCVE-2026-48373not named as affected at publication, now names acrobat 2024Days to revision 40
2026-08-26Product addedCVE-2026-48373not named as affected at publication, now names acrobat dcDays to revision 40
2026-08-26Product addedCVE-2026-48389not named as affected at publication, now names adobe dng software development kit (sdk)Days to revision 37
Wed 15 Jul 2026· 13 record changes
2026-07-15Affected range extendedCVE-2026-48254
adobeadobe experience manager 6.5
stated at publication 6.5.24, now states 6.5.25Release branch starts at 0.Days to revision 1
2026-07-15Affected range extendedCVE-2026-48257
adobeadobe experience manager 6.5
stated at publication 6.5.24, now states 6.5.25Release branch starts at 0.Days to revision 1
2026-07-15Affected range extendedCVE-2026-48255
adobeadobe experience manager 6.5
stated at publication 6.5.24, now states 6.5.25Release branch starts at 0.Days to revision 1
2026-07-15Affected range extendedCVE-2026-48252
adobeadobe experience manager 6.5
stated at publication 6.5.24, now states 6.5.25Release branch starts at 0.Days to revision 1
2026-07-15Affected range extendedCVE-2026-48262
adobeadobe experience manager 6.5
stated at publication 6.5.24, now states 6.5.25Release branch starts at 0.Days to revision 1
2026-07-15Affected range extendedCVE-2026-48253
adobeadobe experience manager 6.5
stated at publication 6.5.24, now states 6.5.25Release branch starts at 0.Days to revision 1
2026-07-15Affected range extendedCVE-2026-48261
adobeadobe experience manager 6.5
stated at publication 6.5.24, now states 6.5.25Release branch starts at 0.Days to revision 1
2026-07-15Affected range extendedCVE-2026-48355
adobeadobe experience manager 6.5
stated at publication 6.5.24, now states 6.5.25Release branch starts at 0.Days to revision 1
2026-07-15Affected range extendedCVE-2026-48260
adobeadobe experience manager 6.5
stated at publication 6.5.24, now states 6.5.25Release branch starts at 0.Days to revision 1
2026-07-15Affected range extendedCVE-2026-48263
adobeadobe experience manager 6.5
stated at publication 6.5.24, now states 6.5.25Release branch starts at 0.Days to revision 1
2026-07-15Affected range extendedCVE-2026-48359
adobeadobe experience manager 6.5
stated at publication 6.5.24, now states 6.5.25Release branch starts at 0.Days to revision 1
2026-07-15Affected range extendedCVE-2026-48259
adobeadobe experience manager 6.5
stated at publication 6.5.24, now states 6.5.25Release branch starts at 0.Days to revision 1
2026-07-15Affected range extendedCVE-2026-48310
adobeadobe experience manager 6.5
stated at publication 6.5.24, now states 6.5.25Release branch starts at 0.Days to revision 1
Tue 14 Jul 2026· 37 record changes
2026-07-14Affected range extendedCVE-2026-34690
adobeafter effects
stated at publication 25.6.4, now states 25.6.5Release branch starts at 0.Days to revision 63
2026-07-14Product addedCVE-2026-48287not named as affected at publication, now names content credentials command-line toolDays to revision 0
2026-07-14Product addedCVE-2026-48287not named as affected at publication, now names content credentials js sdkDays to revision 0
2026-07-14Product addedCVE-2026-48287not named as affected at publication, now names content credentials rust sdkDays to revision 0
2026-07-14Product addedCVE-2026-48290not named as affected at publication, now names content credentials command-line toolDays to revision 0
2026-07-14Product addedCVE-2026-48290not named as affected at publication, now names content credentials js sdkDays to revision 0
2026-07-14Product addedCVE-2026-48290not named as affected at publication, now names content credentials rust sdkDays to revision 0
2026-07-14Product addedCVE-2026-48295not named as affected at publication, now names content credentials command-line toolDays to revision 0
2026-07-14Product addedCVE-2026-48295not named as affected at publication, now names content credentials js sdkDays to revision 0
2026-07-14Product addedCVE-2026-48295not named as affected at publication, now names content credentials rust sdkDays to revision 0
2026-07-14Product addedCVE-2026-48296not named as affected at publication, now names content credentials command-line toolDays to revision 0
2026-07-14Product addedCVE-2026-48296not named as affected at publication, now names content credentials js sdkDays to revision 0
2026-07-14Product addedCVE-2026-48296not named as affected at publication, now names content credentials rust sdkDays to revision 0
2026-07-14Product addedCVE-2026-48298not named as affected at publication, now names content credentials command-line toolDays to revision 0
2026-07-14Product addedCVE-2026-48298not named as affected at publication, now names content credentials js sdkDays to revision 0
2026-07-14Product addedCVE-2026-48298not named as affected at publication, now names content credentials rust sdkDays to revision 0
2026-07-14Product addedCVE-2026-48302not named as affected at publication, now names content credentials command-line toolDays to revision 0
2026-07-14Product addedCVE-2026-48302not named as affected at publication, now names content credentials js sdkDays to revision 0
2026-07-14Product addedCVE-2026-48302not named as affected at publication, now names content credentials rust sdkDays to revision 0
2026-07-14Product addedCVE-2026-48312not named as affected at publication, now names content credentials command-line toolDays to revision 0
2026-07-14Product addedCVE-2026-48312not named as affected at publication, now names content credentials js sdkDays to revision 0
2026-07-14Product addedCVE-2026-48312not named as affected at publication, now names content credentials rust sdkDays to revision 0
2026-07-14Product addedCVE-2026-48351not named as affected at publication, now names content credentials command-line toolDays to revision 0
2026-07-14Product addedCVE-2026-48351not named as affected at publication, now names content credentials js sdkDays to revision 0
2026-07-14Product addedCVE-2026-48351not named as affected at publication, now names content credentials rust sdkDays to revision 0
2026-07-14Product addedCVE-2026-48352not named as affected at publication, now names content credentials command-line toolDays to revision 0
2026-07-14Product addedCVE-2026-48352not named as affected at publication, now names content credentials js sdkDays to revision 0
2026-07-14Product addedCVE-2026-48352not named as affected at publication, now names content credentials rust sdkDays to revision 0
2026-07-14Product addedCVE-2026-48353not named as affected at publication, now names content credentials command-line toolDays to revision 0
2026-07-14Product addedCVE-2026-48353not named as affected at publication, now names content credentials js sdkDays to revision 0
2026-07-14Product addedCVE-2026-48353not named as affected at publication, now names content credentials rust sdkDays to revision 0
2026-07-14Product addedCVE-2026-48354not named as affected at publication, now names content credentials command-line toolDays to revision 0
2026-07-14Product addedCVE-2026-48354not named as affected at publication, now names content credentials js sdkDays to revision 0
2026-07-14Product addedCVE-2026-48354not named as affected at publication, now names content credentials rust sdkDays to revision 0
2026-07-14Product addedCVE-2026-48357not named as affected at publication, now names content credentials command-line toolDays to revision 0
2026-07-14Product addedCVE-2026-48357not named as affected at publication, now names content credentials js sdkDays to revision 0
2026-07-14Product addedCVE-2026-48357not named as affected at publication, now names content credentials rust sdkDays to revision 0
Tue 7 Jul 2026· 1 record change
2026-07-07Added to CISA KEVCVE-2026-48282
AdobeColdFusion
CISA KEV
fix due 2026-07-10Not applicable: Added to CISA KEV has no earlier value
Wed 20 May 2026· 1 record change
2026-05-20Added to CISA KEVCVE-2009-3459
AdobeAcrobat and Reader
CISA KEV
fix due 2026-06-03Not applicable: Added to CISA KEV has no earlier value
Mon 13 Apr 2026· 2 record changes
2026-04-13Added to CISA KEVCVE-2020-9715
AdobeAcrobat
CISA KEV
fix due 2026-04-27Not applicable: Added to CISA KEV has no earlier value
2026-04-13Added to CISA KEVCVE-2026-34621
AdobeAcrobat and Reader
CISA KEV
fix due 2026-04-27Not applicable: Added to CISA KEV has no earlier value
Fri 24 Oct 2025· 1 record change
2025-10-24Added to CISA KEVCVE-2025-54236
AdobeCommerce and Magento
CISA KEV
fix due 2025-11-14Not applicable: Added to CISA KEV has no earlier value
Wed 15 Oct 2025· 1 record change
2025-10-15Added to CISA KEVCVE-2025-54253
AdobeExperience Manager (AEM) Forms
CISA KEV
fix due 2025-11-06 · listed 2025-10-16Not applicable: Added to CISA KEV has no earlier value
Mon 12 May 2025· 2 record changes
2025-05-12Ransomware use confirmedCVE-2015-7645
AdobeFlash Player
CISA KEV
stated at publication Unknown, now states KnownDays to revision at least 76
2025-05-12Ransomware use confirmedCVE-2008-2992
AdobeAcrobat and Reader
CISA KEV
stated at publication Unknown, now states KnownDays to revision at least 76
Mon 24 Feb 2025· 1 record change
2025-02-24Added to CISA KEVCVE-2017-3066
AdobeColdFusion
CISA KEV
fix due 2025-03-17Not applicable: Added to CISA KEV has no earlier value
Tue 17 Sep 2024· 2 record changes
2024-09-17Product addedCVE-2023-29288not named as affected at publication, now names adobe commerceDays to revision 461
2024-09-17Product addedCVE-2023-29293not named as affected at publication, now names adobe commerceDays to revision 461
Fri 13 Sep 2024· 2 record changes
2024-09-13Affected range extendedCVE-2024-39420
adobeacrobat reader
stated at publication 24.001.30123, now states 24.003.20054Release branch starts at 0.Days to revision 30
2024-09-13Affected range extendedCVE-2024-41856
adobeillustrator
stated at publication 27.9.4, now states 27.9.5Release branch starts at 0.Days to revision 30
Thu 14 Sep 2023· 1 record change
2023-09-14Product addedCVE-2023-38207not named as affected at publication, now names adobe commerceDays to revision 36

Rows, not records: a moved fix version or an extended range counts once per record, product and release branch; an added product once per record and product; every other kind once per record or advisory. Days to revision is how long the value first stated stood: from the record's or advisory's publication, or from the day a KEV field value was first seen, to the first commit that replaced it. An addition to KEV has no earlier value and shows none.

Data sources and quality

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Check my CVEs against these changes →