Description
Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-09-08
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Information Disclosure
Action: Assess Impact
AI Analysis

Impact

A flaw in Adobe Acrobat and Acrobat Reader allows an attacker to read data beyond the bounds of a buffer. The vulnerability is an out‑of‑bounds read (CWE-125), which can expose portions of memory that may contain confidential information. The exposure is limited to the data accessible to the application at the time of the read and does not grant direct code execution or administrative privileges.

Affected Systems

The affected products are Adobe Acrobat 2024, Adobe Acrobat Reader and other Adobe Acrobat releases. Vulnerability impacts all operating systems where these products are installed unless mitigated by a subsequent update or patch.

Risk and Exploitability

The vulnerability carries a moderate CVSS score of 5.5. The EPSS score is unavailable, and it is not listed in the CISA KEV catalog, suggesting that widespread exploitation is not yet documented. Exploitation requires user interaction: the victim must open a crafted PDF file. No remote code execution is possible, but once the file is opened the application may leak parts of memory to the attacker. The risk to an asset depends on the sensitivity of the data in memory at the time of the read and the likelihood that an attacker can create or deliver a malicious file to the target.

Generated by OpenCVE AI on September 9, 2026 at 08:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Adobe Acrobat or Acrobat Reader update that addresses the out‑of‑bounds read flaw.
  • Configure Acrobat to block or sandbox unknown PDF content, or disable JavaScript execution when opening PDFs from untrusted sources.
  • Avoid opening PDF files from unfamiliar or suspicious senders, and scan files with up‑to‑date antivirus or sandbox tools before opening them.

Generated by OpenCVE AI on September 9, 2026 at 08:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Adobe acrobat 2024
Adobe acrobat Reader
Vendors & Products Adobe acrobat 2024
Adobe acrobat Reader

Thu, 10 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe acrobat
Adobe acrobat Dc
Adobe acrobat Reader Dc
Apple
Apple macos
Microsoft
Microsoft windows
CPEs cpe:2.3:a:adobe:acrobat:*:*:*:*:classic:*:*:*
cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:*
cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Adobe
Adobe acrobat
Adobe acrobat Dc
Adobe acrobat Reader Dc
Apple
Apple macos
Microsoft
Microsoft windows

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Acrobat Reader | Out-of-bounds Read (CWE-125)
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}


Subscriptions

Adobe Acrobat Acrobat 2024 Acrobat Dc Acrobat Reader Acrobat Reader Dc
Apple Macos
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-10T14:59:06.305Z

Reserved: 2026-08-25T14:55:21.140Z

Link: CVE-2026-79910

cve-icon Vulnrichment

Updated: 2026-09-09T16:41:22.907Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T21:18:42.777

Modified: 2026-09-10T15:57:51.263

Link: CVE-2026-79910

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:06:19Z

Weaknesses