CVE-2016-4117
Executive Summary
Adobe Flash Player 21.0.0.226 and earlier are vulnerable to remote code execution via unspecified vectors, actively exploited in the wild (CISA KEV). Attackers can run arbitrary code on affected systems, compromising confidentiality, integrity, and availability. Immediate patching or disabling Flash is required.
Authoritative CVE Metadata - CVSS Base Score: 9.8 (CRITICAL) - Published: 2016-05-11T01:59:46.137 - Last Modified: 2026-09-10T04:17:30.760
[!CAUTION] Known Exploited Vulnerability: YES (CISA KEV Added: 2022-03-03)
Original Description: Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016.
"The beginning of knowledge is the discovery of something we do not understand."
— Frank Herbert