« Back to list

Adobe

Adobe C2pa: vulnerabilities and CVEs

Adobe C2pa has 55 published vulnerabilities, 55 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs55
Last 12 months55
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-76198Medium (5.5)0.26%—Aug 25, 2026
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories…
CVE-2026-76189Medium (6.2)0.26%—Aug 25, 2026
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the…
CVE-2026-71444Medium (6.2)0.26%—Aug 25, 2026
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the…
CVE-2026-71443High (7.5)0.93%—Aug 25, 2026
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to…
CVE-2026-71442High (7.5)0.90%—Aug 25, 2026
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the…
CVE-2026-71360High (7.5)0.90%—Aug 25, 2026
CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources,…
CVE-2026-71390Medium (4)0.27%—Aug 11, 2026
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain…
CVE-2026-71389Medium (6.2)0.26%—Aug 11, 2026
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the…
CVE-2026-48446Medium (5.5)0.29%—Aug 11, 2026
CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this…
CVE-2026-48445Medium (6.2)0.29%—Aug 11, 2026
CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application,…
CVE-2026-48444Medium (6.2)0.30%—Aug 11, 2026
CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application,…
CVE-2026-48443Medium (6.2)0.26%—Aug 11, 2026
CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources,…
CVE-2026-48442High (7.1)0.30%—Aug 11, 2026
CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Arbitrary file system read. An attacker could leverage this…
CVE-2026-48439High (7.5)0.90%—Aug 11, 2026
CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources,…
CVE-2026-48438High (7.5)0.90%—Aug 11, 2026
CAI Content Credentials is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a…
CVE-2026-48437Medium (5.5)0.15%—Aug 11, 2026
CAI Content Credentials is affected by an Improper Certificate Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain…
CVE-2026-48436Medium (6.5)0.72%—Aug 11, 2026
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain…
CVE-2026-48435Medium (6.2)0.26%—Aug 11, 2026
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the…
CVE-2026-48434Medium (6.2)0.26%—Aug 11, 2026
CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources,…
CVE-2026-48387Medium (6.2)0.29%—Aug 11, 2026
CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application,…
CVE-2026-47922Medium (4.7)0.56%—Aug 11, 2026
CAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue requires user interaction in that a victim must visit a…
CVE-2026-48357Medium (6.2)0.26%—Jul 14, 2026
CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources,…
CVE-2026-48354Medium (6.2)0.29%—Jul 14, 2026
CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application,…
CVE-2026-48353Medium (5.5)0.26%—Jul 14, 2026
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories…
CVE-2026-48352High (7.5)0.93%—Jul 14, 2026
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to…
CVE-2026-48351High (7.5)0.93%—Jul 14, 2026
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to…
CVE-2026-48312Medium (6.8)0.28%—Jul 14, 2026
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain…
CVE-2026-48302Medium (6.2)0.27%—Jul 14, 2026
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to…
CVE-2026-48298Medium (6.2)0.26%—Jul 14, 2026
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the…
CVE-2026-48296Medium (6.2)0.26%—Jul 14, 2026
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1190 Exploit Public-Facing Application12
  2. T1499.004 Application or System Exploitation9
  3. T1203 Exploitation for Client Execution2
  4. T1499 Endpoint Denial of Service2
  5. T1005 Data from Local System1
  6. T1068 Exploitation for Privilege Escalation1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Adobe