← Vulnerability feed

Vulnerability record · CVE-2016-4126 · published 16 June 2016

CVE-2016-4126: Adobe air desktop runtime vulnerability

Adobe · Air Desktop Runtime

Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.

8.8 CVSS 3.1 High EPSS 4.7% · top 8.4%
8.8CVSS 3.1 base score, v2 9.3
4.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-4126 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-1019Adobe Flash Player memory corruption allows code executionAdobe Flash Player 21.0.0.197 and earlier contains an unspecified memory corruption flaw that can crash the application or allow arbitrary code execu…KEVEPSS 22%analysed8.8CVE-2016-1010Adobe Flash Player and AIR integer overflow allows code executionAdobe Flash Player, AIR, AIR SDK and AIR SDK & Compiler contain an integer overflow (CWE-190) that permits arbitrary code execution via unspecified v…KEVEPSS 19%analysed8.8CVE-2016-0984Adobe Flash Player and AIR use-after-free allows code executionCVE-2016-0984 is a use-after-free (CWE-416) in Adobe Flash Player, Adobe AIR, AIR SDK and AIR SDK & Compiler that lets an attacker execute arbitrary …KEVEPSS 55%analysed10.0CVE-2014-0564Adobe flash player vulnerabilityAdobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.…EPSS 6.2%9.8CVE-2016-4163Adobe flash player memory buffer overflow vulnerabilityAdobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and before 11.2.202.621 on Linux allows attackers to…EPSS 6.3%9.8CVE-2016-4162Adobe flash player memory buffer overflow vulnerabilityAdobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and before 11.2.202.621 on Linux allows attackers to…EPSS 6.3%9.8CVE-2016-4160Adobe flash player memory buffer overflow vulnerabilityAdobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and before 11.2.202.621 on Linux allows attackers to…EPSS 6.3%9.8CVE-2016-4161Adobe flash player memory buffer overflow vulnerabilityAdobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and before 11.2.202.621 on Linux allows attackers to…EPSS 6.3%

Source: NIST National Vulnerability Database (record CVE-2016-4126), CISA KEV, FIRST EPSS (scores of 2026-10-02). This page is refreshed as NVD updates the record.