CVE-2016-7867: Adobe Flash Player

High severity, CVSS 8.8. EPSS: 10.7% chance of exploitation in the next 30 days.

Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable buffer overflow / underflow vulnerability in the RegExp class related to bookmarking in searches. Successful exploitation could lead to arbitrary code execution.

Affected products

  • Adobe Flash Player: up to and including 23.0.0.207; up to and including 11.2.202.644
  • Adobe Flash Player Desktop Runtime: up to and including 23.0.0.207

Published 2016-12-15. Last modified 2026-06-17.