CVE-2017-3099: Adobe Flash Player

High severity, CVSS 8.8. EPSS: 8.6% chance of exploitation in the next 30 days.

Adobe Flash Player versions 26.0.0.131 and earlier have an exploitable memory corruption vulnerability in the Action Script 3 raster data model. Successful exploitation could lead to arbitrary code execution.

Affected products

  • Adobe Flash Player: up to and including 26.0.0.120; up to and including 26.0.0.131
  • Adobe Flash Player Desktop Runtime: up to and including 26.0.0.131

Published 2017-07-17. Last modified 2026-06-17.