CVE-2016-1019: Adobe Flash Player Arbitrary Code Execution Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2022-03-03. EPSS: 22.3% chance of exploitation in the next 30 days.

Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as exploited in the wild in April 2016.

Affected products

  • Adobe Air Desktop Runtime: up to and including 21.0.0.176
  • Adobe Air SDK: up to and including 21.0.0.176
  • Adobe Air SDK & Compiler: up to and including 21.0.0.176
  • Adobe Flash Player: up to and including 18.0.0.333; up to and including 21.0.0.197; up to and including 11.2.202.577
  • Adobe Flash Player Desktop Runtime: up to and including 21.0.0.197

Published 2016-04-07. Last modified 2026-10-01.