I'm still having this issue on my system. As a summary, the security update to version 11.2.202.621 published by Adobe on May 12 [0] fixes the following 31 CVEs:
CVE-2016-1096, CVE-2016-1097, CVE-2016-1098, CVE-2016-1099, CVE-2016-1100, CVE-2016-1101, CVE-2016-1102, CVE-2016-1103, CVE-2016-1104, CVE-2016-1105, CVE-2016-1106, CVE-2016-1107, CVE-2016-1108, CVE-2016-1109, CVE-2016-1110, CVE-2016-4108, CVE-2016-4109, CVE-2016-4110, CVE-2016-4111, CVE-2016-4112, CVE-2016-4113, CVE-2016-4114, CVE-2016-4115, CVE-2016-4116, CVE-2016-4117, CVE-2016-4120, CVE-2016-4121, CVE-2016-4160, CVE-2016-4161, CVE-2016-4162, CVE-2016-4163 Each of the 31 vulnerabilities is reported to possibly lead to code execution, including via buffer overflow, use-after-free, and memory corruption bugs. The update is given the highest severity by Adobe: Critical - A vulnerability, which, if exploited would allow malicious native-code to execute, potentially without a user being aware. [1] If anyone knows a functional workaround, please let me know! (My understanding is that Debian 7 should have security support until May 2018 [2].) Cheers, - Chris [0] https://helpx.adobe.com/security/products/flash-player/apsb16-15.html [1] https://helpx.adobe.com/security/severity-ratings.html [2] https://wiki.debian.org/LTS/