Last Updated: 2016-10-26 17:24:26 UTC
by Johannes Ullrich (Version: 1)
Adobe today released a critical update for Flash Player. The update was released outside of Adobe's regular patch cycle. 
The singled vulnerability fixed by this update, CVE-2016-7855, has already been exploited in targeted attacks against Windows.
Windows, Linux and Mac versions are affected, including versions embedded in Chrome and Edge/Internet Explorer 11.
Please expedite this update, and review that Flash does not start automatically in your browser but only if enabled by the user for a specific site. Consider removing Flash whenever possible.
If you have more information or corrections regarding our diary, please share.