Adobe Reader
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Adobe Reader.
Recent Adobe Reader Security Advisories
| Advisory | Title | Published |
|---|---|---|
| APSB26-141 | Security Bulletin for Adobe Acrobat and Reader | APSB26-141 | September 8, 2026 |
| APSB26-63 | Security Bulletin for Adobe Acrobat and Reader | APSB26-63 | June 9, 2026 |
| APSB26-44 | Prenotification Security Advisory for Adobe Acrobat and Reader | APSB26-44 | April 14, 2026 |
| APSB26-43 | Prenotification Security Advisory for Adobe Acrobat and Reader | APSB26-43 | April 11, 2026 |
| APSB26-26 | Prenotification Security Advisory for Adobe Acrobat and Reader | APSB26-26 | March 10, 2026 |
| APSB25-119 | Prenotification Security Advisory for Adobe Acrobat and Reader | APSB25-119 | December 9, 2025 |
| APSB25-85 | Prenotification Security Advisory for Adobe Acrobat and Reader | APSB25-85 | September 9, 2025 |
| APSB25-57 | Prenotification Security Advisory for Adobe Acrobat and Reader | APSB25-57 | June 10, 2025 |
| APSB25-14 | Prenotification Security Advisory for Adobe Acrobat and Reader | APSB25-14 | March 11, 2025 |
| APSB24-92 | Prenotification Security Advisory for Adobe Acrobat and Reader | APSB24-92 | December 10, 2024 |
Known Exploited Adobe Reader Vulnerabilities
The following Adobe Reader vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| Adobe Reader Buffer Overflow Vulnerability |
A buffer overflow vulnerability exists in Adobe Reader which allows an attacker to perform remote code execution. CVE-2013-0641 Exploit Probability: 32.4% |
March 3, 2022 |
The vulnerability CVE-2013-0641: Adobe Reader Buffer Overflow Vulnerability is in the top 5% of the currently known exploitable vulnerabilities.
By the Year
In 2026 there have been 60 vulnerabilities in Adobe Reader with an average score of 7.1 out of ten. Last year, in 2025 Reader had 4 security vulnerabilities published. That is, 56 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 1.57.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 60 | 7.12 |
| 2025 | 4 | 5.55 |
| 2024 | 0 | 0.00 |
| 2023 | 0 | 0.00 |
| 2022 | 0 | 0.00 |
| 2021 | 0 | 0.00 |
| 2020 | 1 | 0.00 |
It may take a day or so for new Reader vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Adobe Reader Security Vulnerabilities
Adobe Acrobat Reader UAF Disclosure Vulnerability (CVE-2026-81984)
CVE-2026-81984
5.5 - Medium
- September 08, 2026
Acrobat Reader is affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Dangling pointer
Acrobat Reader Use-After-Free CVE-2026-81989 Enables Arbitrary Code Execution
CVE-2026-81989
7.8 - High
- September 08, 2026
Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Dangling pointer
Acrobat Reader OOB Read for Sensitive Memory Disclosure (Adobe)
CVE-2026-81991
5.5 - Medium
- September 08, 2026
Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Out-of-bounds Read
Acrobat Reader OOB Write Enables A.C.E. (user interaction)
CVE-2026-81980
7.8 - High
- September 08, 2026
Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Memory Corruption
Acrobat Reader UAF Arbitrary Code Exec w/ Malicious File
CVE-2026-81990
7.8 - High
- September 08, 2026
Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Dangling pointer
Adobe Acrobat Reader Integer Overflow Arbitrary Code Exec (CVE-2026-81987)
CVE-2026-81987
7.8 - High
- September 08, 2026
Acrobat Reader is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Integer Overflow or Wraparound
Adobe Acrobat Reader OOB Read Sensitive Memory Disclosure
CVE-2026-79910
5.5 - Medium
- September 08, 2026
Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Out-of-bounds Read
Acrobat Reader Heap Buffer Overflow (CVE-2026-81993)
CVE-2026-81993
5.5 - Medium
- September 08, 2026
Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Heap-based Buffer Overflow
Adobe Acrobat Reader Double Free CVE-2026-79907
CVE-2026-79907
7.8 - High
- September 08, 2026
Acrobat Reader is affected by a Double Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Double-free
Adobe Acrobat Reader Untrusted Search Path Priv Escalation
CVE-2026-80159
4 - Medium
- September 08, 2026
Acrobat Reader is affected by an Untrusted Search Path vulnerability that could result in privilege escalation. An attacker with high privileges could leverage this vulnerability to gain elevated access. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Untrusted Path
Adobe Acrobat Reader UAF Leads to Arbitrary Code Exec
CVE-2026-79909
7.8 - High
- September 08, 2026
Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Dangling pointer
Acrobat Reader UAF CVE-2026-81973
CVE-2026-81973
7.8 - High
- September 08, 2026
Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Dangling pointer
Adobe Acrobat Reader Use-After-Free in PDF Parsing
CVE-2026-81988
7.8 - High
- September 08, 2026
Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Dangling pointer
Acrobat Reader UAF memory disclosure (CVE-2026-80162)
CVE-2026-80162
5.5 - Medium
- September 08, 2026
Acrobat Reader is affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Dangling pointer
Acrobat Reader Integer Underflow Vulnerability (CVE-2026-81977)
CVE-2026-81977
5.5 - Medium
- September 08, 2026
Acrobat Reader is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Integer underflow
Acrobat Reader Use-After-Free CVE-2026-81986
CVE-2026-81986
7.8 - High
- September 08, 2026
Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Dangling pointer
Acrobat Reader OOB Write -> Arbitrary Code Exec
CVE-2026-81981
7.8 - High
- September 08, 2026
Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Memory Corruption
Acrobat Reader Type Confusion Leads to Arbitrary Code Execution (CVE-2026-80161)
CVE-2026-80161
7.8 - High
- September 08, 2026
Acrobat Reader is affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Object Type Confusion
Adobe Acrobat Reader: Authorization Bypass via Malicious File
CVE-2026-81997
6.3 - Medium
- September 08, 2026
Acrobat Reader is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
AuthZ
Adobe Acrobat Reader UAF Arbitrary Code Exec
CVE-2026-81976
7.8 - High
- September 08, 2026
Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Dangling pointer
Acrobat Reader Prototype Pollution Allows Arbitrary FS Read
CVE-2026-81994
8.2 - High
- September 08, 2026
Acrobat Reader is affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Prototype Pollution
Acrobat Reader Use-After-Free Allows Arbitrary Code Exec
CVE-2026-81985
7.8 - High
- September 08, 2026
Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Dangling pointer
Acrobat Reader OOB Read CVE-2026-80160: Sensitive Data Disclosure
CVE-2026-80160
5.5 - Medium
- September 08, 2026
Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Out-of-bounds Read
Acrobat Reader OOB Write CVE-2026-81979 - Arbitrary Code Exec via User Interaction
CVE-2026-81979
7.8 - High
- September 08, 2026
Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Memory Corruption
Adobe Acrobat Reader Incorrect Authorization Privilege Escalation
CVE-2026-81996
8.8 - High
- September 08, 2026
Acrobat Reader is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access. Exploitation of this issue does not require user interaction. Scope is changed.
AuthZ
Acrobat Reader Heap Buffer Overflow (CVE-2026-81992)
CVE-2026-81992
7.8 - High
- September 08, 2026
Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Heap-based Buffer Overflow
Acrobat Reader Uncontrolled Resource Consumption Causing DoS
CVE-2026-82001
5.5 - Medium
- September 08, 2026
Acrobat Reader is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Resource Exhaustion
Acrobat Reader OOB Read Info Disclosure (CVE-2026-81982)
CVE-2026-81982
5.5 - Medium
- September 08, 2026
Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Out-of-bounds Read
Out-of-Bounds Read in Acrobat Reader Enables Sensitive Memory Disclosure
CVE-2026-81978
5.5 - Medium
- September 08, 2026
Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Out-of-bounds Read
Adobe Acrobat Reader UAF Arbitrary Code Execution
CVE-2026-81975
7.8 - High
- September 08, 2026
Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Dangling pointer
Acrobat Reader OOB Write for Arbitrary Code Execution
CVE-2026-81983
7.8 - High
- September 08, 2026
Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Memory Corruption
Acrobat Reader OOB Write Arbitrary Code Exec (CVE-2026-79908)
CVE-2026-79908
7.8 - High
- September 08, 2026
Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Memory Corruption
Adobe Acrobat Reader: Heap Buffer Overflow -> Arbitrary Code Execution
CVE-2026-48373
7.8 - High
- July 17, 2026
Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Heap-based Buffer Overflow
Adobe Acrobat Reader OOB Write in 24.001.30365 Arbitrary code exec
CVE-2026-47965
7.8 - High
- June 12, 2026
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Memory Corruption
U.S.P.E. in Adobe Acrobat Reader 24.001.30365/26.001.21651 & prior
CVE-2026-47937
7.7 - High
- June 09, 2026
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
DLL preloading
Acrobat Reader UAF before 26.001.21651: AAExec via malicious file
CVE-2026-47916
7.8 - High
- June 09, 2026
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Dangling pointer
Use-After-Free (UAF) in Adobe Acrobat Reader <=26.001.21651
CVE-2026-47918
7.8 - High
- June 09, 2026
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Dangling pointer
Acrobat Reader <24.001.30365/26.001.21651: UAF Arbitrary Exec
CVE-2026-47915
7.8 - High
- June 09, 2026
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Dangling pointer
Acrobat Reader OOB Read v24-26 Disclosed
CVE-2026-47923
5.5 - Medium
- June 09, 2026
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Out-of-bounds Read
Heap-based Buffer Overflow in Acrobat Reader before 26.001.21652
CVE-2026-47952
7.8 - High
- June 09, 2026
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Heap-based Buffer Overflow
Adobe Acrobat Reader UAF 24/26, Arbitrary Code Execution
CVE-2026-47917
7.8 - High
- June 09, 2026
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Dangling pointer
Acrobat Reader 24.001.30365 & 26.001.21651 Use After Free RCE
CVE-2026-47955
7.8 - High
- June 09, 2026
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Dangling pointer
Acrobat Reader UEFAF Vulnerability <26.001.21651
CVE-2026-47924
5.5 - Medium
- June 09, 2026
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Dangling pointer
Adobe Acrobat Reader Use-After-Free in PDF Parser 24.x/26.x
CVE-2026-47919
7.8 - High
- June 09, 2026
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Dangling pointer
Acrobat Reader 24.001.x-26.001.x OOBR memory disclosure
CVE-2026-47926
5.5 - Medium
- June 09, 2026
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Out-of-bounds Read
Acrobat Reader UAF in 24.001.30365/26.001.21651 Arbitrary Code Exec
CVE-2026-47921
7.8 - High
- June 09, 2026
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Dangling pointer
Acrobat Reader < 26 UAF in PDF Parser (exploit requires user interaction)
CVE-2026-47920
7.8 - High
- June 09, 2026
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Dangling pointer
Acrobat Reader OOB Read (v <24.001.30365)
CVE-2026-47961
5.5 - Medium
- June 09, 2026
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Out-of-bounds Read
Adobe Acrobat Reader UAF Before 26.001.21651
CVE-2026-47913
7.8 - High
- June 09, 2026
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Dangling pointer
Use-After-Free in Adobe Acrobat Reader <26.001.21651
CVE-2026-47914
7.8 - High
- June 09, 2026
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Dangling pointer
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Adobe Reader or by Adobe? Click the Watch button to subscribe.