CVE-2018-4920: Adobe Flash Player

High severity, CVSS 8.8. EPSS: 7.6% chance of exploitation in the next 30 days.

Adobe Flash Player versions 28.0.0.161 and earlier have an exploitable type confusion vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

Affected products

  • Adobe Flash Player: up to and including 28.0.0.161
  • Adobe Flash Player Desktop Runtime: up to and including 28.0.0.161

Published 2018-05-19. Last modified 2026-06-17.