CVE-2016-4117: Adobe Flash Player Arbitrary Code Execution Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2022-03-03. EPSS: 94.4% chance of exploitation in the next 30 days.

Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016.

Affected products

  • Adobe Flash Player: up to and including 21.0.0.226
  • Opensuse Evergreen: version 11.4 only
  • Opensuse Opensuse: version 13.1 only; version 13.2 only
  • Red Hat Enterprise Linux Desktop: version 5.0 only; version 6.0 only
  • Red Hat Enterprise Linux Server: version 5.0 only; version 6.0 only
  • Red Hat Enterprise Linux Server From Rhui: version 5.0 only; version 6.0 only
  • Red Hat Enterprise Linux Workstation: version 5.0 only; version 6.0 only
  • Suse Linux Enterprise Desktop: version 12 only
  • Suse Linux Enterprise Workstation Extension: version 12 only

Published 2016-05-11. Last modified 2026-09-10.