CVE-2018-4991: Adobe Creative Cloud

Critical severity, CVSS 9.8. EPSS: 4% chance of exploitation in the next 30 days.

Adobe Creative Cloud Desktop Application versions 4.4.1.298 and earlier have an exploitable Improper certificate validation vulnerability. Successful exploitation could lead to a security bypass.

Affected products

  • Adobe Creative Cloud: up to and including 4.4.1.298

Published 2018-05-19. Last modified 2026-06-17.