Description
Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-07-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A heap‑based buffer overflow exists in Adobe Acrobat Reader that can allow an attacker to execute arbitrary code with the same privileges as the user who opens a specially crafted file. The flaw occurs during the processing of certain PDF objects and requires the victim to interactively open the malicious document to trigger the overflow.

Affected Systems

Adobe Acrobat Reader, the widely used PDF viewer from Adobe, is the target of this vulnerability. No explicit version range is provided by the vendor, so any installation that has not yet applied the latest Adobe Acrobat Reader Security Update may be vulnerable. All systems that rely on Acrobat Reader for PDF viewing, including end‑user desktops and servers, could be affected.

Risk and Exploitability

The vulnerability scores high on the CVSS scale with a 7.8 rating. The EPSS score is reported to be less than 1%, indicating a very low likelihood of widespread exploitation, and the issue is not listed in the CISA KEV catalog. However, because exploitation requires the victim to open a malicious PDF, it is a user‑interaction attack. If an attacker succeeds, they can run code with the victim’s privileges, potentially leading to data exposure, further lateral movement, or compromise of the user’s system.

Generated by OpenCVE AI on July 30, 2026 at 23:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Adobe Acrobat Reader Security Update (APSb26‑63) as soon as it becomes available.
  • Upgrade to the latest supported version of Acrobat Reader to ensure the fix is in place.
  • Restrict the opening of PDF files from untrusted or unknown sources and enforce user awareness training to reduce the chance of a user launching a malicious document.

Generated by OpenCVE AI on July 30, 2026 at 23:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe acrobat Reader
Vendors & Products Adobe
Adobe acrobat Reader

Fri, 17 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Acrobat Reader | Heap-based Buffer Overflow (CWE-122)
Weaknesses CWE-122
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Adobe Acrobat Reader
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-23T03:56:11.342Z

Reserved: 2026-05-21T15:28:38.141Z

Link: CVE-2026-48373

cve-icon Vulnrichment

Updated: 2026-07-21T02:04:43.802Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T23:45:05Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow