CVE-2014-0502Active Exploitation(adobe / adobe_air)

HIGHCVSS 8.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (4 mentions)

Immediate actions

  • Patch adobe adobe_air systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR SDK before 4.0.0.1628, and Adobe AIR SDK & Compiler before 4.0.0.1628 allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2014.

6.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-10-08. The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.

Weakness type (CWE)
CWE-415

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • adobe_air
  • adobe_air_sdk
  • android
  • enterprise_linux_desktop

Threat summary

  • Active exploitation appears in 4 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 2 observed days

What's happening

  • Active exploitation reported across 4 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked at 4 mentions on most recent observed day (2026-05-01)
  • 5 total mentions across 2 days

Affected systems

Products
adobe_airadobe_air_sdkandroidenterprise_linux_desktopenterprise_linux_eusenterprise_linux_serverenterprise_linux_server_ausenterprise_linux_workstationflash_playerlinux_enterprise_desktop

8 versions affected across 14 products

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-04-30: 1Mentions · 2026-05-01: 4PoC Mentioned / Linked · 2026-05-01: 1Active Exploitation · 2026-04-30: 1Active Exploitation · 2026-05-01: 3Patch / Workaround · 2026-04-30: 1Technical Details · 2026-04-30: 1Technical Details · 2026-05-01: 204-3005-01
Signal classification2 categories
Active Exploitation
480.0%
Disclosure
120.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-04-301
Active Exploitation1
2026-05-014
Active Exploitation3Disclosure1
Full discourse5 posts
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    What happened CISA added CVE-2014-0502 (Adobe Flash Player) to the Known Exploited Vulnerabilities (KEV) catalog on 2024-09-17, flagging it as actively exploited and setting a remediation due date of 2024-10-08 CISA KEV catalog. CISA’s required action states the impacted…

    Post summary

    CISA identified CVE-2014-0502 as actively exploited, added it to the KEV catalog, and set a remediation due date.

    1000031
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    The vulnerability is a double free memory error in Adobe Flash Player that enables remote code execution via crafted content NVD: CVE-2014-0502. The MITRE CVE record corroborates the issue and impact scope for CVE-2014-0502 MITRE CVE record.

    Post summary

    The post discloses that CVE-2014-0502 is a double free memory error in Adobe Flash Player that permits remote code execution through crafted content, but it provides no exploits, patches, or real‑world attack evidence.

    1000042
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CVE-2014-0502: Adobe Flash Player contains a double free vulnerability that allows a remote attacker to execute arbitrary code. What happened CISA added CVE-2014-0502 (Adobe Flash Player) to the Known Exploited Vulnerabilities (KEV) catalog on 2024-09-17, flagging it as…

    Post summary

    CVE-2014-0502 is confirmed as actively exploited, with CISA noting it in the KEV catalog, though no PoC, exploit tool, or patch details are provided.

    1000046
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    https://research.lyrie.ai/research/active-exploit-cve-2014-0502-flash-player #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The tweet links to a research article that reports an actively exploited CVE‑2014‑0502 in Adobe Flash Player, suggesting the vulnerability is being used in real-world attacks.

    0000031
    152 followersView on X
  • DFIR Lab@DFIR_Lab
    Active Exploitation

    🚨 HIGH: CVE-2014-0502 (CVSS 8.8) - Double free vulnerability in Adobe Flash Player allows remote code execution. Exploited in wild Feb 2014. Update to 11[.]7[.]700[.]269+ (Win/Mac) or 11[.]2[.]202[.]341+ (Linux) immediately. #CVE #PatchNow #ThreatIntel https://t.co/atQ2bS1yt9

    Post summary

    The tweet reports that CVE-2014-0502 was exploited in the wild and urges users to apply the Adobe Flash Player patch immediately.

    0000037
    11 followersView on X
CPE platform detail19 entries

19 of 19 entries

PartVendorProductVersionTarget SWTarget HW
Appadobeadobe_air---
Appadobeadobe_air_sdk---
Appadobeflash_player---
OSapplemac_os_x---
OSgoogleandroid---
OSlinuxlinux_kernel---
OSmicrosoftwindows---
OSopensuseopensuse11.4--
OSopensuseopensuse12.3--
OSopensuseopensuse13.1--
OSredhatenterprise_linux_desktop5.0--
OSredhatenterprise_linux_desktop6.0--
OSredhatenterprise_linux_eus6.5--
OSredhatenterprise_linux_server5.0--
OSredhatenterprise_linux_server6.0--
OSredhatenterprise_linux_server_aus6.5--
OSredhatenterprise_linux_workstation5.0--
OSredhatenterprise_linux_workstation6.0--
OSsuselinux_enterprise_desktop11--

Explore more