Subscribe to the Security@Adobe newsletter
Don’t miss out! Get the latest Adobe security news and exclusive content delivered straight to your inbox.
This blog was updated on 11-24-2025.
At Adobe, we believe creativity and security go hand in hand. Our commitment is to empower creative expression while upholding high standards of software safety. With over 80 million monthly active users across our desktop products, we recognize our responsibility to innovate in secure software development. Adobe is announcing our adoption of a roadmap to help eliminate memory safety vulnerabilities across our desktop product portfolio. We are proud to share this roadmap and further demonstrate our dedication to building a safer digital future.
Some popular computer programming languages have greater exposure to vulnerabilities involving improper access or manipulation of program memory. Memory safety vulnerabilities, such as buffer overflows and use-after-free errors, remain one of the most exploited classes of software flaws. Industry data shows that up to 70 percent of critical vulnerabilities in C and C++ programming language-based systems stem from memory safety issues. Adobe’s own vulnerability assessments indicate that memory safety issues represent the most significant category of security concerns that we are addressing in our desktop products.
Left unresolved, these flaws can have real-world impact on our customers. That’s why we recognize the seriousness of these threats and are taking decisive action to remediate them.
As part of our long-standing commitment to product security, Adobe is adopting a roadmap to help eliminate memory safety vulnerabilities across our desktop product portfolio. This multi-pronged, risk-based approach is designed to align with guidance from the Cybersecurity and Infrastructure Security Agency (CISA) and global cybersecurity agencies. Our roadmap includes:
With these three strategies in place, we can effectively secure first- and third-party legacy code as well as put foundations in place for safe future development.
Our goal is to iteratively harden our desktop products against memory safety exploits in file parsing and decoding logic. This will enhance protection for our customers from file-based, one-click attacks, such as those that occur when opening unknown attachments or files from the Internet. We’re exploring ways to reduce the use of new C and C++ code in safety critical parts of our products to a fraction of current levels.
Trust drives Adobe’s adoption of this roadmap. Trust empowers creativity, and it starts with secure software that protects our users every day. From government agencies to enterprises and creative professionals worldwide, our customers depend on Adobe to help safeguard their work and respect privacy. Adobe is committed to continually earning and upholding that trust through our ongoing innovation and commitment to security.
Don’t miss out! Get the latest Adobe security news and exclusive content delivered straight to your inbox.
In this blog, we share how Adobe’s security teams work diligently to uphold our customers’ trust by implementing both proactive and reactive security measures to tackle evolving phishing attacks.
07-09-2025
In this blog, I will share a tool we developed at Adobe Security to trace the source of any AWS Access Key ID.
10-06-2025
Strategic Remediation emphasizes a “big picture” approach, prioritizing proactive, long-term solutions to drive more resilience across the business and better protect Adobe’s customers.
01-27-2025